Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
File opened: C:\Windows\SysWOW64\MSVCR100.dll |
Jump to behavior |
Source: unknown |
HTTPS traffic detected: 192.185.48.167:443 -> 192.168.2.4:49725 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 192.185.113.120:443 -> 192.168.2.4:49727 version: TLS 1.2 |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Section loaded: \KnownDlls32\WININET.dll origin: URLDownloadToFileA |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process created: C:\Windows\SysWOW64\regsvr32.exe |
Source: global traffic |
DNS query: name: forfacks.com |
Source: global traffic |
TCP traffic: 192.168.2.4:49725 -> 192.185.48.167:443 |
Source: global traffic |
TCP traffic: 192.168.2.4:49725 -> 192.185.48.167:443 |
Source: Joe Sandbox View |
ASN Name: UNIFIEDLAYER-AS-1US UNIFIEDLAYER-AS-1US |
Source: Joe Sandbox View |
JA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19 |
Source: unknown |
DNS traffic detected: queries for: forfacks.com |
Source: unknown |
Network traffic detected: HTTP traffic on port 49727 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49725 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49727 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49725 |
Source: unknown |
HTTPS traffic detected: 192.185.48.167:443 -> 192.168.2.4:49725 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 192.185.113.120:443 -> 192.168.2.4:49727 version: TLS 1.2 |
Source: Screenshot number: 4 |
Screenshot OCR: Enable Content ' ' 14 15 / , 16 " 17 18 WHY I CANNOT OPEN THIS DOCUMENT ? 19 20 21 W You |
Source: audit-367497006.xlsb |
Initial sample: EXEC |
Source: audit-367497006.xlsb |
Initial sample: Sheet size: 8595 |
Source: audit-367497006.xlsb |
Initial sample: Sheet size: 7538 |
Source: classification engine |
Classification label: mal76.expl.evad.winXLSB@5/9@2/2 |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
File created: C:\Users\user\Desktop\~$audit-367497006.xlsb |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
File created: C:\Users\user\AppData\Local\Temp\{CA4A0570-2497-4229-BD1C-B788DE92E1D9} - OProcSessId.dat |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
File read: C:\Users\desktop.ini |
Jump to behavior |
Source: C:\Windows\SysWOW64\regsvr32.exe |
Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Jump to behavior |
Source: unknown |
Process created: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE 'C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE' /automation -Embedding |
|
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 -s ..\werty1.dll |
|
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 -s ..\werty2.dll |
|
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 -s ..\werty1.dll |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 -s ..\werty2.dll |
Jump to behavior |
Source: Window Recorder |
Window detected: More than 3 window changes detected |
Source: audit-367497006.xlsb |
Initial sample: OLE zip file path = xl/media/image1.png |
Source: audit-367497006.xlsb |
Initial sample: OLE zip file path = xl/media/image2.png |
Source: audit-367497006.xlsb |
Initial sample: OLE zip file path = xl/media/image3.png |
Source: audit-367497006.xlsb |
Initial sample: OLE zip file path = xl/media/image4.png |
Source: audit-367497006.xlsb |
Initial sample: OLE zip file path = xl/media/image5.png |
Source: audit-367497006.xlsb |
Initial sample: OLE zip file path = xl/media/image6.png |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
File opened: C:\Windows\SysWOW64\MSVCR100.dll |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 -s ..\werty1.dll |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: regsvr32.exe, 00000001.00000002.659802132.0000000003400000.00000002.00000001.sdmp, regsvr32.exe, 00000002.00000002.661248559.0000000004640000.00000002.00000001.sdmp |
Binary or memory string: A Virtual Machine could not be started because Hyper-V is not installed. |
Source: regsvr32.exe, 00000001.00000002.659802132.0000000003400000.00000002.00000001.sdmp, regsvr32.exe, 00000002.00000002.661248559.0000000004640000.00000002.00000001.sdmp |
Binary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service. |
Source: regsvr32.exe, 00000001.00000002.659802132.0000000003400000.00000002.00000001.sdmp, regsvr32.exe, 00000002.00000002.661248559.0000000004640000.00000002.00000001.sdmp |
Binary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported. |
Source: regsvr32.exe, 00000001.00000002.659802132.0000000003400000.00000002.00000001.sdmp, regsvr32.exe, 00000002.00000002.661248559.0000000004640000.00000002.00000001.sdmp |
Binary or memory string: An unknown internal message was received by the Hyper-V Compute Service. |
Source: Yara match |
File source: app.xml, type: SAMPLE |