Windows Analysis Report
Serbia_Vendor_Creation_1.xlsx

Overview

General Information

Sample name: Serbia_Vendor_Creation_1.xlsx
Analysis ID: 1432059
MD5: c1cda6d17a11952fef58a1aa3a47c30f
SHA1: 1c51727af61fd17e8d437a736bf254cd470a54a2
SHA256: 7c3babffc38d4b977d7e8ecef338936e9a002655a6fbbbd4bc2feaecfdbbdcca
Infos:

Detection

Score: 52
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Malicious sample detected (through community Yara rule)
Contains an external reference to another file
Yara signature match

Classification

Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6DB1906E.emf Jump to behavior

System Summary

barindex
Source: externalLink1.xml.rels, type: SAMPLE Matched rule: Detects XML relations where an OLE object is refrencing an external target in dropper OOXML documents Author: ditekSHen
Source: externalLink2.xml.rels, type: SAMPLE Matched rule: Detects XML relations where an OLE object is refrencing an external target in dropper OOXML documents Author: ditekSHen
Source: externalLink1.xml.rels, type: SAMPLE Matched rule: INDICATOR_OLE_RemoteTemplate author = ditekSHen, description = Detects XML relations where an OLE object is refrencing an external target in dropper OOXML documents
Source: externalLink2.xml.rels, type: SAMPLE Matched rule: INDICATOR_OLE_RemoteTemplate author = ditekSHen, description = Detects XML relations where an OLE object is refrencing an external target in dropper OOXML documents
Source: classification engine Classification label: mal52.evad.winXLSX@1/7@0/0
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\Desktop\~$Serbia_Vendor_Creation_1.xlsx Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Temp\CVR67D6.tmp Jump to behavior
Source: Serbia_Vendor_Creation_1.xlsx OLE indicator, Workbook stream: true
Source: 6B9E.tmp.0.dr OLE indicator, Workbook stream: true
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File read: C:\Users\desktop.ini Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: Serbia_Vendor_Creation_1.xlsx Initial sample: OLE zip file path = xl/media/image2.emf
Source: Serbia_Vendor_Creation_1.xlsx Initial sample: OLE zip file path = xl/media/image3.png
Source: Serbia_Vendor_Creation_1.xlsx Initial sample: OLE zip file path = xl/media/image4.png
Source: Serbia_Vendor_Creation_1.xlsx Initial sample: OLE zip file path = xl/externalLinks/externalLink1.xml
Source: Serbia_Vendor_Creation_1.xlsx Initial sample: OLE zip file path = xl/externalLinks/externalLink2.xml
Source: Serbia_Vendor_Creation_1.xlsx Initial sample: OLE zip file path = customXml/item3.xml
Source: Serbia_Vendor_Creation_1.xlsx Initial sample: OLE zip file path = customXml/itemProps3.xml
Source: Serbia_Vendor_Creation_1.xlsx Initial sample: OLE zip file path = docProps/custom.xml
Source: Serbia_Vendor_Creation_1.xlsx Initial sample: OLE zip file path = customXml/itemProps2.xml
Source: Serbia_Vendor_Creation_1.xlsx Initial sample: OLE zip file path = xl/externalLinks/_rels/externalLink1.xml.rels
Source: Serbia_Vendor_Creation_1.xlsx Initial sample: OLE zip file path = xl/externalLinks/_rels/externalLink2.xml.rels
Source: Serbia_Vendor_Creation_1.xlsx Initial sample: OLE zip file path = customXml/_rels/item2.xml.rels
Source: Serbia_Vendor_Creation_1.xlsx Initial sample: OLE zip file path = customXml/_rels/item3.xml.rels
Source: Serbia_Vendor_Creation_1.xlsx Initial sample: OLE zip file path = customXml/item2.xml
Source: 6B9E.tmp.0.dr Initial sample: OLE zip file path = xl/media/image2.emf
Source: 6B9E.tmp.0.dr Initial sample: OLE zip file path = xl/media/image3.png
Source: 6B9E.tmp.0.dr Initial sample: OLE zip file path = xl/media/image4.png
Source: 6B9E.tmp.0.dr Initial sample: OLE zip file path = xl/externalLinks/externalLink1.xml
Source: 6B9E.tmp.0.dr Initial sample: OLE zip file path = xl/externalLinks/externalLink2.xml
Source: 6B9E.tmp.0.dr Initial sample: OLE zip file path = customXml/item3.xml
Source: 6B9E.tmp.0.dr Initial sample: OLE zip file path = customXml/itemProps3.xml
Source: 6B9E.tmp.0.dr Initial sample: OLE zip file path = docProps/custom.xml
Source: 6B9E.tmp.0.dr Initial sample: OLE zip file path = customXml/itemProps2.xml
Source: 6B9E.tmp.0.dr Initial sample: OLE zip file path = xl/externalLinks/_rels/externalLink1.xml.rels
Source: 6B9E.tmp.0.dr Initial sample: OLE zip file path = xl/externalLinks/_rels/externalLink2.xml.rels
Source: 6B9E.tmp.0.dr Initial sample: OLE zip file path = customXml/_rels/item2.xml.rels
Source: 6B9E.tmp.0.dr Initial sample: OLE zip file path = customXml/_rels/item3.xml.rels
Source: 6B9E.tmp.0.dr Initial sample: OLE zip file path = customXml/item2.xml
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll Jump to behavior
Source: Serbia_Vendor_Creation_1.xlsx Initial sample: OLE indicators vbamacros = False

Persistence and Installation Behavior

barindex
Source: externalLink1.xml.rels Extracted files from sample: https://hyperoptic-my.sharepoint.com/personal/isidora_karapandzic_hyperoptic_com/documents/desktop/1.%20hyperoptic%20supplier%20code%20of%20conduct%20(1)%20srp.doc
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
No contacted IP infos