Source: excel.exe |
Memory has grown: Private usage: 2MB later: 17MB |
Source: Initial sample |
OLE, VBA macro line: Ursnif specific tokens |
Source: 2021_0002565_DDT.xls |
OLE, VBA macro line: Excel4MacroSheets.Add(Before:=Worksheets((1))).Name = vgiom: ottoB |
|
Source: 2021_0002565_DDT.xls |
OLE, VBA macro line: ActiveSheet.Visible = 0 |
|
Source: 2021_0002565_DDT.xls |
OLE indicator, VBA macros: true |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
File created: C:\Users\alfredo\AppData\Local\Temp\{5831B89B-9FC5-4859-BBDB-4598E8DC4C22} - OProcSessId.dat |
Source: 2021_0002565_DDT.xls |
OLE indicator, Workbook stream: true |
Source: classification engine |
Classification label: mal52.bank.expl.winXLS@1/8@0/72 |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
File read: C:\Users\desktop.ini |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
File created: C:\Users\alfredo\AppData\Local\Microsoft\Office\16.0\WebServiceCache |
Source: Window Recorder |
Window detected: More than 3 window changes detected |
Source: 2021_0002565_DDT.xls |
Initial sample: OLE summary comments = ''BRT |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |