Report - = EDI IR.xls

VBA_macro Generic Malware MSOffice File
ScreenShot
Created 2025.02.23 23:17 Machine s1_win7_x6401
Filename = EDI IR.xls
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: Microsoft Corporation, Last Saved By: ASUS, Name of Creating Application: Microsoft Excel, Create Time/Date: Mon Oct 21 11:03:58 1996, Last Saved Time/
AI Score Not founds Behavior Score
0.8
ZERO API file : clean
VT API (file) 1 detected (OLE2)
md5 6505ed15b6710c610c2b82777e68a133
sha256 0a2298c0eb57e8df36928bf9bed27b63e0151473a6f94c2b473607dcbe49914f
ssdeep 1536:ron6Zqg/+7j0gG1OxQzfDlaGGxldg2VKkJX63X3fjz3+O8RCLxkAlAaneWacSF:ron6Zqg/+7j0gG1OxQzfDlaGGxldg2Vd
imphash
impfuzzy
  Network IP location

Signature (2cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by one AntiVirus engine on VirusTotal as malicious

Rules (3cnts)

Level Name Description Collection
warning Contains_VBA_macro_code Detect a MS Office document with embedded VBA macro code [binaries] binaries (upload)
warning Generic_Malware_Zero Generic Malware binaries (upload)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure