Windows Analysis Report
xls.xls

Overview

General Information

Sample Name: xls.xls
Analysis ID: 736957
MD5: 109d15a7d33e671ded911d97bc4a15ab
SHA1: c6660d40673400505c70af85dfddc735fa50a39f
SHA256: 822d2e533e0537f92fa3ddcbd8cb2a0d7c33ba2ada626e1cae4ecf466ac61e9b
Tags: xls
Infos:

Detection

Score: 68
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for submitted file
Document contains an embedded VBA with functions possibly related to ADO stream file operations
Document contains an embedded VBA macro which may execute processes
Document contains an embedded VBA macro with suspicious strings
Machine Learning detection for sample
Document contains an embedded VBA with functions possibly related to HTTP operations
Document contains embedded VBA macros
Potential document exploit detected (unknown TCP traffic)
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)

Classification

AV Detection

barindex
Source: xls.xls ReversingLabs: Detection: 17%
Source: xls.xls Virustotal: Detection: 39% Perma Link
Source: xls.xls Joe Sandbox ML: detected
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE File opened: C:\Windows\SysWOW64\MSVCR100.dll Jump to behavior
Source: global traffic TCP traffic: 192.168.2.5:49684 -> 91.213.50.111:443
Source: global traffic TCP traffic: 91.213.50.111:443 -> 192.168.2.5:49684
Source: global traffic TCP traffic: 192.168.2.5:49684 -> 91.213.50.111:443
Source: global traffic TCP traffic: 192.168.2.5:49684 -> 91.213.50.111:443
Source: global traffic TCP traffic: 91.213.50.111:443 -> 192.168.2.5:49684
Source: global traffic TCP traffic: 91.213.50.111:443 -> 192.168.2.5:49684
Source: global traffic TCP traffic: 192.168.2.5:49685 -> 91.213.50.111:443
Source: global traffic TCP traffic: 91.213.50.111:443 -> 192.168.2.5:49685
Source: global traffic TCP traffic: 192.168.2.5:49685 -> 91.213.50.111:443
Source: global traffic TCP traffic: 192.168.2.5:49685 -> 91.213.50.111:443
Source: global traffic TCP traffic: 91.213.50.111:443 -> 192.168.2.5:49685
Source: global traffic TCP traffic: 91.213.50.111:443 -> 192.168.2.5:49685
Source: global traffic TCP traffic: 192.168.2.5:49689 -> 91.213.50.111:443
Source: global traffic TCP traffic: 91.213.50.111:443 -> 192.168.2.5:49689
Source: global traffic TCP traffic: 192.168.2.5:49689 -> 91.213.50.111:443
Source: global traffic TCP traffic: 192.168.2.5:49689 -> 91.213.50.111:443
Source: global traffic TCP traffic: 91.213.50.111:443 -> 192.168.2.5:49689
Source: global traffic TCP traffic: 192.168.2.5:49689 -> 91.213.50.111:443
Source: global traffic DNS query: name: dooxil.com
Source: global traffic TCP traffic: 192.168.2.5:49684 -> 91.213.50.111:443
Source: global traffic TCP traffic: 192.168.2.5:49684 -> 91.213.50.111:443
Source: global traffic TCP traffic: 192.168.2.5:49684 -> 91.213.50.111:443
Source: global traffic TCP traffic: 192.168.2.5:49685 -> 91.213.50.111:443
Source: global traffic TCP traffic: 192.168.2.5:49685 -> 91.213.50.111:443
Source: global traffic TCP traffic: 192.168.2.5:49685 -> 91.213.50.111:443
Source: global traffic TCP traffic: 192.168.2.5:49689 -> 91.213.50.111:443
Source: global traffic TCP traffic: 192.168.2.5:49689 -> 91.213.50.111:443
Source: global traffic TCP traffic: 192.168.2.5:49689 -> 91.213.50.111:443
Source: global traffic TCP traffic: 192.168.2.5:49689 -> 91.213.50.111:443
Source: unknown DNS traffic detected: queries for: dooxil.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49689
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49685
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49684
Source: unknown Network traffic detected: HTTP traffic on port 49685 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49689 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49684 -> 443

System Summary

barindex
Source: xls.xls Stream path '_VBA_PROJECT_CUR/VBA/Foglio1' : found possibly 'ADODB.Stream' functions open, read, write
Source: xls.xls OLE, VBA macro line: riporti = trattasse(scoperte, Shell(riporti))
Source: xls.xls OLE, VBA macro line: scoperte = aspetteremo(Left(Environ(ammiratrice("A7Uc6oP5mAs31p0Ee0c1", 3)), 20) & ammiratrice("S5r1Yu3n11dIIl7lM87", 1) & "32" & ammiratrice("K60.3EHeNN7x56eO", 4))
Source: VBA code instrumentation OLE, VBA macro: Module Foglio1, Function dimostrargli, String environ: scoperte = aspetteremo(Left(Environ(ammiratrice("A7Uc6oP5mAs31p0Ee0c1", 3)), 20) & ammiratrice("S5r1Yu3n11dIIl7lM87", 1) & "32" & ammiratrice("K60.3EHeNN7x56eO", 4)) Name: dimostrargli
Source: xls.xls Stream path '_VBA_PROJECT_CUR/VBA/Foglio1' : found possibly 'XMLHttpRequest' functions response, responsetext, open, send
Source: VBA code instrumentation OLE, VBA macro: Module Foglio1, Function stupidaggine, found possibly 'XMLHttpRequest' functions response, responsetext, open, send Name: stupidaggine
Source: xls.xls OLE indicator, VBA macros: true
Source: xls.xls ReversingLabs: Detection: 17%
Source: xls.xls Virustotal: Detection: 39%
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE File created: C:\Users\user\AppData\Local\Temp\{10F38723-79F0-4113-AD4D-B542D4D55D84} - OProcSessId.dat Jump to behavior
Source: xls.xls OLE indicator, Workbook stream: true
Source: classification engine Classification label: mal68.expl.winXLS@1/0@1/1
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE File read: C:\Users\desktop.ini Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE File opened: C:\Windows\SysWOW64\MSVCR100.dll Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs