Click to jump to signature section
Source: R.D. Bitzer Co., Inc.xlsm | Virustotal: Detection: 16% | Perma Link |
Source: R.D. Bitzer Co., Inc.xlsm | ReversingLabs: Detection: 21% |
Source: global traffic | TCP traffic: 192.168.2.11:49706 -> 52.123.128.14:443 |
Source: global traffic | TCP traffic: 192.168.2.11:49706 -> 52.123.128.14:443 |
Source: global traffic | TCP traffic: 192.168.2.11:49706 -> 52.123.128.14:443 |
Source: global traffic | TCP traffic: 192.168.2.11:49706 -> 52.123.128.14:443 |
Source: global traffic | TCP traffic: 192.168.2.11:49711 -> 13.107.246.60:443 |
Source: global traffic | TCP traffic: 192.168.2.11:49711 -> 13.107.246.60:443 |
Source: global traffic | TCP traffic: 192.168.2.11:49711 -> 13.107.246.60:443 |
Source: global traffic | TCP traffic: 192.168.2.11:49711 -> 13.107.246.60:443 |
Source: global traffic | TCP traffic: 192.168.2.11:49706 -> 52.123.128.14:443 |
Source: global traffic | TCP traffic: 52.123.128.14:443 -> 192.168.2.11:49706 |
Source: global traffic | TCP traffic: 192.168.2.11:49706 -> 52.123.128.14:443 |
Source: global traffic | TCP traffic: 192.168.2.11:49706 -> 52.123.128.14:443 |
Source: global traffic | TCP traffic: 52.123.128.14:443 -> 192.168.2.11:49706 |
Source: global traffic | TCP traffic: 192.168.2.11:49706 -> 52.123.128.14:443 |
Source: global traffic | TCP traffic: 192.168.2.11:49711 -> 13.107.246.60:443 |
Source: global traffic | TCP traffic: 13.107.246.60:443 -> 192.168.2.11:49711 |
Source: global traffic | TCP traffic: 192.168.2.11:49711 -> 13.107.246.60:443 |
Source: global traffic | TCP traffic: 192.168.2.11:49711 -> 13.107.246.60:443 |
Source: global traffic | TCP traffic: 13.107.246.60:443 -> 192.168.2.11:49711 |
Source: global traffic | TCP traffic: 192.168.2.11:49711 -> 13.107.246.60:443 |
Source: Joe Sandbox View | IP Address: 13.107.246.60 13.107.246.60 |
Source: Joe Sandbox View | IP Address: 52.123.128.14 52.123.128.14 |
Source: Network traffic | Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.11:49711 -> 13.107.246.60:443 |
Source: Network traffic | Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.11:49706 -> 52.123.128.14:443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49711 |
Source: unknown | Network traffic detected: HTTP traffic on port 49706 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49711 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49706 |
Source: screenshot | OCR: Enable Editing" button at the yellow bar and then rlit,k 'Enable content". Microsoft Excel Compatibi |
Source: screenshot | OCR: Enable content". Microsoft Excel Compatibility We're sorry, something went wrong. This spreadsheet i |
Source: screenshot | OCR: Enable Editing" button at the yellow bar and then rlit,k 'Enable content". Sheetl @ Ready u Accessib |
Source: screenshot | OCR: Enable content". Sheetl @ Ready u Accessibility: Good to go B JUJAOEO UYYOJDFVF BWDRWEE... IZMFBFKME |
Source: screenshot | OCR: Enable Editing" button at the yellow bar and then click 'Enable content". Sheetl &Accessibility: Goo |
Source: screenshot | OCR: Enable content". Sheetl &Accessibility: Good to go Ready 13:14 ENG p Type here to search 10/03/2025 |
Source: screenshot | OCR: Enable Editing" button at the yellow bar and then click 'Enable content". Sheetl &Accessibility: Goo |
Source: screenshot | OCR: Enable content". Sheetl &Accessibility: Good to go Ready 13:14 ENG p Type here to search 10/03/2025 |
Source: screenshot | OCR: Enable Editing" button at the yellow bar and then click 'Enable content". Sheetl &Accessibility: Goo |
Source: screenshot | OCR: Enable content". Sheetl &Accessibility: Good to go Ready 13:15 ENG p Type here to search 10/03/2025 |
Source: screenshot | OCR: Enable Editing" button at the yellow bar and then click 'Enable content". Sheetl &Accessibility: Goo |
Source: screenshot | OCR: Enable content". Sheetl &Accessibility: Good to go Ready 13:15 ENG p Type here to search 10/03/2025 |
Source: screenshot | OCR: Enable Editing" button at the yellow bar and then click 'Enable content". Sheetl &Accessibility: Goo |
Source: screenshot | OCR: Enable content". Sheetl &Accessibility: Good to go Ready 13:15 ENG p Type here to search 10/03/2025 |
Source: 04030000.0.dr | OLE, VBA macro line: Set MOFOFXRPSPFOWBELNZW = JJLCEKWKKOTCAWWFGRO.CreateTextFile(RIYTFQPORBNBYTVTK) | |
Source: 04030000.0.dr | Stream path 'VBA/Module1' : found possibly 'XMLHttpRequest' functions response, responsetext, open, send | |
Source: 04030000.0.dr | OLE, VBA macro line: Private Sub Workbook_Open() | |
Source: ~DF0EF688E3FF0C2541.TMP.0.dr | OLE stream indicators for Word, Excel, PowerPoint, and Visio: all false |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Window title found: microsoft excel compatibility okwe're sorry something went wrong. this spreedsheet is protected by information rights management or in a format not supported by excel services. |
Source: classification engine | Classification label: mal64.expl.winXLSM@3/7@0/2 |
Source: R.D. Bitzer Co., Inc.xlsm | Virustotal: Detection: 16% |
Source: R.D. Bitzer Co., Inc.xlsm | ReversingLabs: Detection: 21% |
Source: unknown | Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding | |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288 | |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288 | Jump to behavior |
Source: 04030000.0.dr | Initial sample: OLE zip file path = xl/media/image1.png |
Source: 04030000.0.dr | Initial sample: OLE zip file path = docProps/custom.xml |
Source: ~DF0EF688E3FF0C2541.TMP.0.dr | Initial sample: OLE indicators vbamacros = False |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\splwow64.exe | Last function: Thread delayed |
Source: C:\Windows\splwow64.exe | Last function: Thread delayed |