Report - DRWG-347RB1.pd.xls

MSOffice File
ScreenShot
Created 2024.07.24 09:24 Machine s1_win7_x6401
Filename DRWG-347RB1.pd.xls
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 00:00:00 2006, Last Saved Time/Date: Tue Jul 23 07:02:54 2024, Security: 1
AI Score Not founds Behavior Score
3.0
ZERO API file : clean
VT API (file) 15 detected (CVE-2017-0199, Malcode, gen59, CLASSIC, Cve2017, ai score=88)
md5 c433eae598bb293ae5c2f28ad9a61c3b
sha256 f17bd7fd6d8a9e5fcbda5a90f2e7b6cd0835e52eda90c374290e896cd460745f
ssdeep 24576:4MwnuV9kaaGSUtaAfIZduMI5M5TIgZABgOqT6xZvYx:4uV9kaaRUAAfIZduMI5M5cAADqT6TY
imphash
impfuzzy
  Network IP location

Signature (5cnts)

Level Description
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
watch Communicates with host for which no DNS query was performed
watch File has been identified by 15 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Performs some HTTP requests

Rules (1cnts)

Level Name Description Collection
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (5cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://jx.ax/Ld3 US CLOUDFLARENET 104.21.74.75 clean
https://jx.ax/Ld3 US CLOUDFLARENET 172.67.200.114 clean
jx.ax US CLOUDFLARENET 172.67.200.114 clean
54.38.139.98 FR OVH SAS 54.38.139.98 clean
172.67.200.114 US CLOUDFLARENET 172.67.200.114 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure