Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Section loaded: \KnownDlls\api-ms-win-downlevel-shlwapi-l2-1-0.dll origin: URLDownloadToFileA | Jump to behavior |
Source: excel.exe | Memory has grown: Private usage: 4MB later: 32MB |
Source: global traffic | TCP traffic: 192.168.2.22:49167 -> 37.46.133.194:80 |
Source: global traffic | TCP traffic: 192.168.2.22:49167 -> 37.46.133.194:80 |
Source: global traffic | TCP traffic: 192.168.2.22:49169 -> 185.212.129.66:80 |
Source: unknown | TCP traffic detected without corresponding DNS query: 37.46.133.194 |
Source: unknown | TCP traffic detected without corresponding DNS query: 37.46.133.194 |
Source: unknown | TCP traffic detected without corresponding DNS query: 37.46.133.194 |
Source: unknown | TCP traffic detected without corresponding DNS query: 37.46.133.194 |
Source: unknown | TCP traffic detected without corresponding DNS query: 37.46.133.194 |
Source: unknown | TCP traffic detected without corresponding DNS query: 37.46.133.194 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.212.129.66 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.212.129.66 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.212.129.66 |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\62042346.gif | Jump to behavior |
Source: Complaint_1713723004_04122021.xlsm | Initial sample: urlmon |
Source: Screenshot number: 4 | Screenshot OCR: Enable editing button from the yellow bar above 15 0 Once you have enabled editing, please click En |
Source: Screenshot number: 4 | Screenshot OCR: Enable Content button from the yellow bar above 16 17 18 19 20 21 22 ' 23 24 25 26 27 2 |
Source: Document image extraction number: 0 | Screenshot OCR: Enable editing button from the yellow bar above Once you have enabled editing, please click Enabl |
Source: Document image extraction number: 0 | Screenshot OCR: Enable Content button from the yellow bar above |
Source: Document image extraction number: 1 | Screenshot OCR: Enable editing button from the yellow bar above Once you have enabled editing, please click Enabl |
Source: Document image extraction number: 1 | Screenshot OCR: Enable Content button from the yellow bar above |
Source: Complaint_1713723004_04122021.xlsm | Initial sample: EXEC |
Source: Complaint_1713723004_04122021.xlsm | Initial sample: EXEC |
Source: Complaint_1713723004_04122021.xlsm | Initial sample: EXEC |
Source: classification engine | Classification label: mal64.expl.evad.winXLSM@1/7@0/2 |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | File created: C:\Users\user\Desktop\~$Complaint_1713723004_04122021.xlsm | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | File created: C:\Users\user\AppData\Local\Temp\CVRD393.tmp | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | File read: C:\Users\desktop.ini | Jump to behavior |
Source: Window Recorder | Window detected: More than 3 window changes detected |
Source: Complaint_1713723004_04122021.xlsm | Initial sample: OLE zip file path = xl/media/image1.gif |
Source: Complaint_1713723004_04122021.xlsm | Initial sample: OLE zip file path = xl/printerSettings/printerSettings2.bin |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.