top title background image
flash

f9309eba_by_Libranalysis.xlsx

Status: finished
Submission Time: 2021-05-12 18:01:50 +02:00
Malicious
Trojan
Exploiter
Evader
Hidden Macro 4.0

Comments

Tags

Details

  • Analysis ID:
    412464
  • API (Web) ID:
    780075
  • Analysis Started:
    2021-05-12 18:01:52 +02:00
  • Analysis Finished:
    2021-05-12 18:12:49 +02:00
  • MD5:
    f9309ebadd3f4d1e665dfe567dbf9a25
  • SHA1:
    7cd5c8f8038217c20e09fd455fb5708185b151f9
  • SHA256:
    7d2fd957a301aeea8014fd95a0902a6c45a568d34f4a1ce9d7a9fd38b53b542c
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 72
System: Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
malicious
Score: 72
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run Condition: Potential for more IOCs and behavior

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B00DE8CB.bmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\Desktop\~$f9309eba_by_Libranalysis.xlsx
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5F799372.jpeg
[TIFF image data, big-endian, direntries=9, software=Adobe Photoshop 22.0 (Windows), datetime=2021:03:02 23:57:02], baseline, precision 8, 1600x1600, frames 3
#
Click to see the 7 hidden entries
C:\Users\user\AppData\Local\Temp\59EE0000
data
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Thu May 13 00:02:45 2021, atime=Thu May 13 00:02:45 2021, length=8192, window=hide
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\f9309eba_by_Libranalysis.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu May 13 00:02:30 2021, mtime=Thu May 13 00:02:45 2021, atime=Thu May 13 00:02:45 2021, length=609397, window=hide
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\Desktop\7AEE0000
data
#
C:\Users\user\Desktop\~$f9309eba_by_Libranalysis.xls
data
#
C:\Users\user\Nioka.meposv
data
#