Click to jump to signature section
Source: R.D. Bitzer Co. Inc.xlsm | ReversingLabs: Detection: 18% |
Source: global traffic | TCP traffic: 192.168.2.6:49689 -> 52.123.129.14:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49689 -> 52.123.129.14:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49689 -> 52.123.129.14:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49689 -> 52.123.129.14:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49695 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49695 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49695 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49695 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49696 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49696 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49697 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49697 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49696 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49697 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49698 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49698 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49698 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49699 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49699 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49699 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49689 -> 52.123.129.14:443 |
Source: global traffic | TCP traffic: 52.123.129.14:443 -> 192.168.2.6:49689 |
Source: global traffic | TCP traffic: 192.168.2.6:49689 -> 52.123.129.14:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49689 -> 52.123.129.14:443 |
Source: global traffic | TCP traffic: 52.123.129.14:443 -> 192.168.2.6:49689 |
Source: global traffic | TCP traffic: 192.168.2.6:49689 -> 52.123.129.14:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49695 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 13.107.253.72:443 -> 192.168.2.6:49695 |
Source: global traffic | TCP traffic: 192.168.2.6:49695 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49695 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 13.107.253.72:443 -> 192.168.2.6:49695 |
Source: global traffic | TCP traffic: 192.168.2.6:49695 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49696 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 13.107.253.72:443 -> 192.168.2.6:49696 |
Source: global traffic | TCP traffic: 192.168.2.6:49696 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49697 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 13.107.253.72:443 -> 192.168.2.6:49697 |
Source: global traffic | TCP traffic: 192.168.2.6:49697 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49696 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 13.107.253.72:443 -> 192.168.2.6:49696 |
Source: global traffic | TCP traffic: 192.168.2.6:49697 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 13.107.253.72:443 -> 192.168.2.6:49697 |
Source: global traffic | TCP traffic: 192.168.2.6:49698 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 13.107.253.72:443 -> 192.168.2.6:49698 |
Source: global traffic | TCP traffic: 192.168.2.6:49698 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49698 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 13.107.253.72:443 -> 192.168.2.6:49698 |
Source: global traffic | TCP traffic: 192.168.2.6:49699 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 13.107.253.72:443 -> 192.168.2.6:49699 |
Source: global traffic | TCP traffic: 192.168.2.6:49699 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49699 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 13.107.253.72:443 -> 192.168.2.6:49699 |
Source: global traffic | TCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700 |
Source: global traffic | TCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 192.168.2.6:49700 -> 13.107.253.72:443 |
Source: global traffic | TCP traffic: 13.107.253.72:443 -> 192.168.2.6:49700 |
Source: Joe Sandbox View | IP Address: 13.107.253.72 13.107.253.72 |
Source: Joe Sandbox View | IP Address: 52.123.129.14 52.123.129.14 |
Source: Network traffic | Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49689 -> 52.123.129.14:443 |
Source: Network traffic | Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49695 -> 13.107.253.72:443 |
Source: Network traffic | Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49699 -> 13.107.253.72:443 |
Source: Network traffic | Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49700 -> 13.107.253.72:443 |
Source: Network traffic | Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49698 -> 13.107.253.72:443 |
Source: Network traffic | Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49696 -> 13.107.253.72:443 |
Source: Network traffic | Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49697 -> 13.107.253.72:443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49689 |
Source: unknown | Network traffic detected: HTTP traffic on port 49698 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49700 |
Source: unknown | Network traffic detected: HTTP traffic on port 49699 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49699 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49698 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49697 |
Source: unknown | Network traffic detected: HTTP traffic on port 49695 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49696 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49695 |
Source: unknown | Network traffic detected: HTTP traffic on port 49696 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49697 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49689 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49700 -> 443 |
Source: screenshot | OCR: Enable Editing" button at the yellow bar and then click 'Enable content". BJZFPPV./ PT G EO Sheetl @ |
Source: screenshot | OCR: Enable content". BJZFPPV./ PT G EO Sheetl @ &Accessibility: Good to go Ready L BIHQFD MXP SFP FIOL 1 |
Source: screenshot | OCR: Enable Editing" button at the yellow bar and then click 'Enable content". Sheetl &Accessibility: Goo |
Source: screenshot | OCR: Enable content". Sheetl &Accessibility: Good to go Ready 11:12 ENG p Type here to search 10/03/2025 |
Source: screenshot | OCR: Enable Editing" button at the yellow bar and then click 'Enable content". Sheetl &Accessibility: Goo |
Source: screenshot | OCR: Enable content". Sheetl &Accessibility: Good to go Ready 11:12 ENG p Type here to search 10/03/2025 |
Source: screenshot | OCR: Enable Editing" button at the yellow bar and then click 'Enable content". Sheetl &Accessibility: Goo |
Source: screenshot | OCR: Enable content". Sheetl &Accessibility: Good to go Ready 11:12 ENG p Type here to search 10/03/2025 |
Source: screenshot | OCR: Enable Editing" button at the yellow bar and then click 'Enable content". Sheetl &Accessibility: Goo |
Source: screenshot | OCR: Enable content". Sheetl &Accessibility: Good to go Ready 11:12 ENG p Type here to search 10/03/2025 |
Source: screenshot | OCR: Enable Editing" button at the yellow bar and then click 'Enable content". Sheetl &Accessibility: Goo |
Source: screenshot | OCR: Enable content". Sheetl &Accessibility: Good to go Ready 11:13 ENG p Type here to search 10/03/2025 |
Source: 18130000.0.dr | OLE, VBA macro line: Set TGVWEAHEHGCFQCOAD = LZECWFCMPLLYGFMXOHI.CreateTextFile(RDRFRJNCLCTNAEIJHIS) | |
Source: 18130000.0.dr | Stream path 'VBA/Module1' : found possibly 'XMLHttpRequest' functions response, responsetext, open, send | |
Source: 18130000.0.dr | OLE, VBA macro line: Private Sub Workbook_Open() | |
Source: 18130000.0.dr | OLE indicator, VBA macros: true |
Source: ~DF7F3A9F6B78AF0793.TMP.0.dr | OLE stream indicators for Word, Excel, PowerPoint, and Visio: all false |
Source: classification engine | Classification label: mal64.expl.winXLSM@3/7@0/2 |
Source: 18130000.0.dr | OLE indicator, Workbook stream: true |
Source: R.D. Bitzer Co. Inc.xlsm | ReversingLabs: Detection: 18% |
Source: unknown | Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding | |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288 | |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288 | Jump to behavior |
Source: Window Recorder | Window detected: More than 3 window changes detected |
Source: 18130000.0.dr | Initial sample: OLE zip file path = xl/media/image1.png |
Source: 18130000.0.dr | Initial sample: OLE zip file path = docProps/custom.xml |
Source: ~DF7F3A9F6B78AF0793.TMP.0.dr | Initial sample: OLE indicators vbamacros = False |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Last function: Thread delayed |
Source: C:\Windows\splwow64.exe | Last function: Thread delayed |