Report - EDI IR.xls

VBA_macro MSOffice File
ScreenShot
Created 2025.02.23 23:37 Machine s1_win7_x6402
Filename EDI IR.xls
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, Code page: 1252, Author: Microsoft Corporation, Last Saved By: ABOUMOHAMMED, Name of Creating Application: Microsoft Excel, Create Time/Date: Mon Oct 21 11:03:58 1996, Last Save
AI Score Not founds Behavior Score
1.4
ZERO API file : clean
VT API (file) 1 detected ()
md5 cfcb25e1ddbb6ab5068d0b8d010826ff
sha256 acbddf19440a581f6c0e726726f4ea458f2346446b8d4c33eca63730517b9747
ssdeep 1536:Dun6Zqg/+7j0gG1OxQzfDlaGGxlMPIr3NiFfc3hho6OLx9AlAan:Dun6Zqg/+7j0gG1OxQzfDlaGGxlMPIrX
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice An application raised an exception which may be indicative of an exploit crash
notice File has been identified by one AntiVirus engine on VirusTotal as malicious
info One or more processes crashed

Rules (2cnts)

Level Name Description Collection
warning Contains_VBA_macro_code Detect a MS Office document with embedded VBA macro code [binaries] binaries (upload)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure