Source: EXCEL.EXE, 00000000.00000002.2472147268.01290000.00000002.00000001.sdmp | String found in binary or memory: http://Myserver/Mydoc.htm |
Source: awnunJUC58.xls | OLE, VBA macro line: UNombre = Environ("username") | |
Source: awnunJUC58.xls | OLE, VBA macro line: UDominio = Environ("userdomain") | |
Source: awnunJUC58.xls | OLE, VBA macro line: Set myWS = CreateObject("WScript.Shell") | |
Source: awnunJUC58.xls | OLE, VBA macro line: UPerf = Environ("UserProfile") | |
Source: awnunJUC58.xls | OLE, VBA macro line: WDir = Environ("WinDir") | |
Source: awnunJUC58.xls | OLE, VBA macro line: UPerf = Environ("UserProfile") | |
Source: VBA code instrumentation | OLE, VBA macro: Module Hoja2, Function Worksheet_Activate, String environ: UNombre = Environ("username") | Name: Worksheet_Activate |
Source: VBA code instrumentation | OLE, VBA macro: Module Hoja2, Function Worksheet_Activate, String environ: UDominio = Environ("userdomain") | Name: Worksheet_Activate |
Source: VBA code instrumentation | OLE, VBA macro: Module Hoja2, Function Worksheet_Activate, String wscript: Set myWS = CreateObject("WScript.Shell") | Name: Worksheet_Activate |
Source: VBA code instrumentation | OLE, VBA macro: Module Hoja2, Function Worksheet_Activate, String environ: UPerf = Environ("UserProfile") | Name: Worksheet_Activate |
Source: VBA code instrumentation | OLE, VBA macro: Module Hoja2, Function Worksheet_Activate, String environ: WDir = Environ("WinDir") | Name: Worksheet_Activate |
Source: VBA code instrumentation | OLE, VBA macro: Module Hoja2, Function TestDecodeToFile, String environ: UPerf = Environ("UserProfile") | Name: TestDecodeToFile |
Source: awnunJUC58.xls | Stream path 'VBA/Hoja2' : found possibly 'WScript.Shell' functions exec, regwrite, environ | |
Source: awnunJUC58.xls | Stream path 'VBA/M\x243dulo1' : Found suspicious string scripting.filesystemobject in non macro stream |
Source: awnunJUC58.xls | OLE indicator, VBA macros: true |
Source: awnunJUC58.xls | OLE stream indicators for Word, Excel, PowerPoint, and Visio: all false |
Source: awnunJUC58.xls, type: SAMPLE | Matched rule: SUSP_VBA_FileSystem_Access date = 2019-06-21, author = Florian Roth, description = Detects suspicious VBA that writes to disk and is activated on document open, reference = Internal Research, score = 52262bb315fa55b7441a04966e176b0e26b7071376797e35c80aa60696b6d6fc |
Source: classification engine | Classification label: mal52.expl.evad.winXLS@1/0@0/0 |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | File created: C:\Users\user~1\AppData\Local\Temp\CVR9741.tmp | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | File read: C:\Users\desktop.ini | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | File opened: C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_50916076bcb9a742\MSVCR90.dll | Jump to behavior |
Source: | Binary string: D:\office\Target\XL\X86\ship\1033.pre\xlintl32.PDB source: EXCEL.EXE, 00000000.00000002.2472147268.01290000.00000002.00000001.sdmp |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: EXCEL.EXE, 00000000.00000002.2471734788.00510000.00000002.00000001.sdmp | Binary or memory string: Program Manager |
Source: EXCEL.EXE, 00000000.00000002.2471734788.00510000.00000002.00000001.sdmp | Binary or memory string: Progman |
Source: EXCEL.EXE, 00000000.00000002.2471734788.00510000.00000002.00000001.sdmp | Binary or memory string: Shell_TrayWnd |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.