Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
File opened: C:\Windows\SysWOW64\MSVCR100.dll |
Jump to behavior |
Source: vbaProject.bin |
Binary string: http://www.oracle.com/bne> - obfuscation quality: 4 |
Source: vbaProject.bin |
String found in binary or memory: http://www.oracle.com/bne |
Source: vbaProject.bin |
String found in binary or memory: https://ebs-prd.eos.lkqeurope. |
Source: vbaProject.bin |
String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA |
Source: vbaProject.bin |
String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML/ |
Source: vbaProject.bin |
String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML// |
Source: vbaProject.bin |
String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML//BneUploaderService?bne:tickleSession=Truem:443/ |
Source: vbaProject.bin |
String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML/BneApplicationService |
Source: vbaProject.bin |
String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML/BneComponentServiceos.lk |
Source: vbaProject.bin |
String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML/BneDownloadServiceeos.lk( |
Source: vbaProject.bin |
String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML/BneDownloadServiceeos.lk(FM51SOK4ODFJXCML07W7O8HY1PLOC |
Source: vbaProject.bin |
String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML/BneUploaderServiceeos.lk |
Source: Initial sample |
OLE, VBA macro line: Ursnif specific tokens |
Source: bnerad4129F.xlsm |
Stream path 'VBA/BneVBAUploader' : found possibly 'ADODB.Stream' functions position, open, read |
|
Source: bnerad4129F.xlsm |
Stream path 'VBA/Sheet1' : found possibly 'ADODB.Stream' functions mode, open, read |
|
Source: bnerad4129F.xlsm |
OLE, VBA macro line: Public Function UnZip( ZipFile As String, Optional TargetFolderPath As String = vbNullString, Optional OverwriteFile As Boolean = False ) As Boolean |
|
Source: bnerad4129F.xlsm |
OLE, VBA macro line: If OverwriteFile Then |
|
Source: bnerad4129F.xlsm |
OLE, VBA macro line: Kill Environ("Temp") & "Temporary Directory*" |
|
Source: bnerad4129F.xlsm |
OLE, VBA macro line: CallByName objProperty, Me.StylePropertyVBA, VbLet, Me.StylePropertyValue |
|
Source: bnerad4129F.xlsm |
OLE, VBA macro line: Set objProperty = CallByName(objProperty, Me.StylePropertyVBA, VbGet) |
|
Source: bnerad4129F.xlsm |
OLE, VBA macro line: Set objProperty = CallByName(objProperty, Me.StylePropertyVBA, VbGet, Me.StylePropertyValue) |
|
Source: bnerad4129F.xlsm |
Stream path 'VBA/BneRibbon' : found possibly 'XMLHttpRequest' functions response, responsebody, status, open, send |
|
Source: bnerad4129F.xlsm |
Stream path 'VBA/BneVBAUploader' : found possibly 'XMLHttpRequest' functions readystate, response, responsexml, status, open, send, setrequestheader |
|
Source: bnerad4129F.xlsm |
Stream path 'VBA/Sheet1' : found possibly 'XMLHttpRequest' functions response, status, open, send |
|
Source: bnerad4129F.xlsm |
OLE, VBA macro line: Private m_layoutImage As String |
|
Source: bnerad4129F.xlsm |
OLE, VBA macro line: m_layoutImage = "" |
|
Source: bnerad4129F.xlsm |
OLE, VBA macro line: LayoutImage = m_layoutImage |
|
Source: bnerad4129F.xlsm |
OLE, VBA macro line: Public Sub Workbook_Open() |
|
Source: bnerad4129F.xlsm |
OLE, VBA macro line: AddBneMsg BNE_ERROR, "Workbook_Open", "Error: " & Err.Number & " " & Err.Description |
|
Source: bnerad4129F.xlsm |
OLE indicator, VBA macros: true |
Source: ~DF31B384211B18428B.TMP.0.dr |
OLE stream indicators for Word, Excel, PowerPoint, and Visio: all false |
Source: bnerad4129F.xlsm |
OLE indicator, Workbook stream: true |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
File created: C:\Users\user\Desktop\~$bnerad4129F.xlsm |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
File created: C:\Users\user\AppData\Local\Temp\{E656762D-7272-4DA5-AD90-1F1FBD4D22C4} - OProcSessId.dat |
Jump to behavior |
Source: classification engine |
Classification label: mal72.bank.expl.evad.winXLSM@1/4@0/0 |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
File read: C:\Users\desktop.ini |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Window found: window name: SysTabControl32 |
Jump to behavior |
Source: Window Recorder |
Window detected: More than 3 window changes detected |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Window detected: Number of UI elements: 71 |
Source: bnerad4129F.xlsm |
Initial sample: OLE zip file path = xl/worksheets/sheet4.xml |
Source: bnerad4129F.xlsm |
Initial sample: OLE zip file path = xl/worksheets/sheet5.xml |
Source: bnerad4129F.xlsm |
Initial sample: OLE zip file path = xl/worksheets/_rels/sheet5.xml.rels |
Source: bnerad4129F.xlsm |
Initial sample: OLE zip file path = docProps/custom.xml |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
File opened: C:\Windows\SysWOW64\MSVCR100.dll |
Jump to behavior |
Source: ~DF31B384211B18428B.TMP.0.dr |
Initial sample: OLE indicators vbamacros = False |
Source: bnerad4129F.xlsm |
Stream path 'BneBrowser' : High number of string operations |
|
Source: bnerad4129F.xlsm |
Stream path 'VBA/BneBrowser' : High number of string operations |
|
Source: bnerad4129F.xlsm |
Stream path 'VBA/BneRibbon' : High number of string operations |
|
Source: bnerad4129F.xlsm |
Stream path 'VBA/BneVBAUploader' : High number of string operations |
|
Source: bnerad4129F.xlsm |
Stream path 'VBA/Sheet1' : High number of string operations |
|
Source: bnerad4129F.xlsm |
Stream path 'VBA/__SRP_1' : xor key: 0x20, keywords: writefile |
Source: bnerad4129F.xlsm |
Stream path 'VBA/__SRP_1' : keywords: writefile |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: bnerad4129F.xlsm |
OLE indicator, VBA stomping: true |