Windows
Analysis Report
Odcinek wyp#U0142aty_0.2.3.4._795.xlsx.exe
Overview
General Information
Sample name: | Odcinek wyp#U0142aty_0.2.3.4._795.xlsx.exerenamed because original name is a hash value |
Original sample name: | Odcinek wypaty_0.2.3.4._795.xlsx.exe |
Analysis ID: | 1432082 |
MD5: | 15e68670447dd65b34ff7affab74fe70 |
SHA1: | 517979db65d2152552f65e9544c502a54c3031e3 |
SHA256: | cd64dff47ed47daec98a2083274c717139ce76776f3f8c6e33b969c6d145a6cb |
Errors
|
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary or memory string: |
Source: | Cryptographic APIs: |
Source: | Classification label: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Static PE information: |
Source: | Static PE information: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 Deobfuscate/Decode Files or Information | OS Credential Dumping | System Service Discovery | Remote Services | 1 Archive Collected Data | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
75% | ReversingLabs | ByteCode-MSIL.Trojan.Leonem | ||
49% | Virustotal | Browse | ||
100% | Joe Sandbox ML |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1432082 |
Start date and time: | 2024-04-26 12:17:19 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 35s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 0 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Sample name: | Odcinek wyp#U0142aty_0.2.3.4._795.xlsx.exerenamed because original name is a hash value |
Original Sample Name: | Odcinek wypaty_0.2.3.4._795.xlsx.exe |
Detection: | MAL |
Classification: | mal52.winEXE@0/0@0/0 |
- Unable to connect to analysis machine: w10x64, esxi07-W10x64_Office_01, timeout exceeded, no analysis of the sample was performed
- No process behavior to analyse as no analysis process or sample was found
File type: | |
Entropy (8bit): | 7.983764933523991 |
TrID: |
|
File name: | Odcinek wyp#U0142aty_0.2.3.4._795.xlsx.exe |
File size: | 627'984 bytes |
MD5: | 15e68670447dd65b34ff7affab74fe70 |
SHA1: | 517979db65d2152552f65e9544c502a54c3031e3 |
SHA256: | cd64dff47ed47daec98a2083274c717139ce76776f3f8c6e33b969c6d145a6cb |
SHA512: | d2a3d0ea093e9fb28102546f65b1281618a22f0f39e20e039241b4178dda57333e8f8ac1a8513648f35c66e23eecbac9bd04a3fceccdb9cd7055cdcdfefa98e2 |
SSDEEP: | 12288:OmfEA72h2BA6pPMkwVjhbzbnLG+DXkHwzCgFxdUM19XrT247+JptAX3AjTmLN:Om2266CkmbHL9DTzTBU69H76tHjTm |
TLSH: | C7D42329AB849F6EC77B67B1A422E70653B4FA16026FBB9CAD47D41C10D3B074153BB0 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...x.%f.........."...0..f............... ....@...... ....................................`................................ |
Entrypoint: | 0x400000 |
Entrypoint Section: | |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows cui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x66258778 [Sun Apr 21 21:39:04 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: |
Instruction |
---|
dec ebp |
pop edx |
nop |
add byte ptr [ebx], al |
add byte ptr [eax], al |
add byte ptr [eax+eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xa000 | 0xb24 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2000 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x66c2 | 0x6800 | 6903f2518101d8d8b2a8b3e432db122d | False | 0.5129957932692307 | data | 5.881175224516216 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xa000 | 0xb24 | 0xc00 | 1131569baa42bfaf2d79660c4e9decbd | False | 0.2864583333333333 | data | 4.2896434131708805 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0xa0b8 | 0x440 | data | 0.4834558823529412 | ||
RT_VERSION | 0xa4f8 | 0x440 | data | English | United States | 0.484375 |
RT_MANIFEST | 0xa938 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5489795918367347 |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |