Click to jump to signature section
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | File opened: C:\Windows\SysWOW64\MSVCR100.dll | Jump to behavior |
Source: vbaProject.bin | Binary string: http://www.oracle.com/bne> - obfuscation quality: 4 |
Source: vbaProject.bin | String found in binary or memory: http://www.oracle.com/bne |
Source: vbaProject.bin | String found in binary or memory: https://ebs-prd.eos.lkqeurope. |
Source: vbaProject.bin | String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA |
Source: vbaProject.bin | String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML/ |
Source: vbaProject.bin | String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML// |
Source: vbaProject.bin | String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML//BneUploaderService?bne:tickleSession=Truem:443/ |
Source: vbaProject.bin | String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML/BneApplicationService |
Source: vbaProject.bin | String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML/BneComponentServiceos.lk |
Source: vbaProject.bin | String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML/BneDownloadServiceeos.lk( |
Source: vbaProject.bin | String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML/BneDownloadServiceeos.lk(FM51SOK4ODFJXCML07W7O8HY1PLOC |
Source: vbaProject.bin | String found in binary or memory: https://ebs-prd.eos.lkqeurope.com:443/OA_HTML/BneUploaderServiceeos.lk |
Source: Initial sample | OLE, VBA macro line: Ursnif specific tokens |
Source: bnerad4129F.xlsm | Stream path 'VBA/BneVBAUploader' : found possibly 'ADODB.Stream' functions position, open, read | |
Source: bnerad4129F.xlsm | Stream path 'VBA/Sheet1' : found possibly 'ADODB.Stream' functions mode, open, read | |
Source: bnerad4129F.xlsm | OLE, VBA macro line: Public Function UnZip( ZipFile As String, Optional TargetFolderPath As String = vbNullString, Optional OverwriteFile As Boolean = False ) As Boolean | |
Source: bnerad4129F.xlsm | OLE, VBA macro line: If OverwriteFile Then | |
Source: bnerad4129F.xlsm | OLE, VBA macro line: Kill Environ("Temp") & "Temporary Directory*" | |
Source: bnerad4129F.xlsm | OLE, VBA macro line: CallByName objProperty, Me.StylePropertyVBA, VbLet, Me.StylePropertyValue | |
Source: bnerad4129F.xlsm | OLE, VBA macro line: Set objProperty = CallByName(objProperty, Me.StylePropertyVBA, VbGet) | |
Source: bnerad4129F.xlsm | OLE, VBA macro line: Set objProperty = CallByName(objProperty, Me.StylePropertyVBA, VbGet, Me.StylePropertyValue) | |
Source: bnerad4129F.xlsm | Stream path 'VBA/BneRibbon' : found possibly 'XMLHttpRequest' functions response, responsebody, status, open, send | |
Source: bnerad4129F.xlsm | Stream path 'VBA/BneVBAUploader' : found possibly 'XMLHttpRequest' functions readystate, response, responsexml, status, open, send, setrequestheader | |
Source: bnerad4129F.xlsm | Stream path 'VBA/Sheet1' : found possibly 'XMLHttpRequest' functions response, status, open, send | |
Source: bnerad4129F.xlsm | OLE, VBA macro line: Private m_layoutImage As String | |
Source: bnerad4129F.xlsm | OLE, VBA macro line: m_layoutImage = "" | |
Source: bnerad4129F.xlsm | OLE, VBA macro line: LayoutImage = m_layoutImage | |
Source: bnerad4129F.xlsm | OLE, VBA macro line: Public Sub Workbook_Open() | |
Source: bnerad4129F.xlsm | OLE, VBA macro line: AddBneMsg BNE_ERROR, "Workbook_Open", "Error: " & Err.Number & " " & Err.Description | |
Source: bnerad4129F.xlsm | OLE indicator, VBA macros: true |
Source: ~DF31B384211B18428B.TMP.0.dr | OLE stream indicators for Word, Excel, PowerPoint, and Visio: all false |
Source: bnerad4129F.xlsm | OLE indicator, Workbook stream: true |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | File created: C:\Users\user\Desktop\~$bnerad4129F.xlsm | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | File created: C:\Users\user\AppData\Local\Temp\{E656762D-7272-4DA5-AD90-1F1FBD4D22C4} - OProcSessId.dat | Jump to behavior |
Source: classification engine | Classification label: mal72.bank.expl.evad.winXLSM@1/4@0/0 |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | File read: C:\Users\desktop.ini | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Window found: window name: SysTabControl32 | Jump to behavior |
Source: Window Recorder | Window detected: More than 3 window changes detected |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Window detected: Number of UI elements: 71 |
Source: bnerad4129F.xlsm | Initial sample: OLE zip file path = xl/worksheets/sheet4.xml |
Source: bnerad4129F.xlsm | Initial sample: OLE zip file path = xl/worksheets/sheet5.xml |
Source: bnerad4129F.xlsm | Initial sample: OLE zip file path = xl/worksheets/_rels/sheet5.xml.rels |
Source: bnerad4129F.xlsm | Initial sample: OLE zip file path = docProps/custom.xml |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | File opened: C:\Windows\SysWOW64\MSVCR100.dll | Jump to behavior |
Source: ~DF31B384211B18428B.TMP.0.dr | Initial sample: OLE indicators vbamacros = False |
Source: bnerad4129F.xlsm | Stream path 'BneBrowser' : High number of string operations | |
Source: bnerad4129F.xlsm | Stream path 'VBA/BneBrowser' : High number of string operations | |
Source: bnerad4129F.xlsm | Stream path 'VBA/BneRibbon' : High number of string operations | |
Source: bnerad4129F.xlsm | Stream path 'VBA/BneVBAUploader' : High number of string operations | |
Source: bnerad4129F.xlsm | Stream path 'VBA/Sheet1' : High number of string operations | |
Source: bnerad4129F.xlsm | Stream path 'VBA/__SRP_1' : xor key: 0x20, keywords: writefile |
Source: bnerad4129F.xlsm | Stream path 'VBA/__SRP_1' : keywords: writefile |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: bnerad4129F.xlsm | OLE indicator, VBA stomping: true |