top title background image
flash

audit-367497006.xlsb

Status: finished
Submission Time: 2021-06-09 13:16:14 +02:00
Malicious
Exploiter
Evader
Hidden Macro 4.0

Comments

Tags

  • xlsx

Details

  • Analysis ID:
    431855
  • API (Web) ID:
    799459
  • Analysis Started:
    2021-06-09 13:16:15 +02:00
  • Analysis Finished:
    2021-06-09 13:21:34 +02:00
  • MD5:
    6a44858ca2fe28f5e2c4eed2c5a360e4
  • SHA1:
    e793cbf64ad364c93e3a673a090977a3434cb6d9
  • SHA256:
    49558300c4315c8c53216a8c17e32ff87ca4be34547ab064de7d872d429bb3f3
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 76
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 5/88

IPs

IP Country Detection
192.185.48.167
United States
192.185.113.120
United States

Domains

Name IP Detection
forfacks.com
192.185.48.167
dreamhimalayan.com
192.185.113.120

Dropped files

Name File Type Hashes Detection
C:\Users\user\Desktop\~$audit-367497006.xlsb
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\2A108F49.png
PNG image data, 246 x 108, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\5C50E7CA.png
PNG image data, 521 x 246, 8-bit/color RGB, non-interlaced
#
Click to see the 6 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\8F304143.png
PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\9F7E393F.png
PNG image data, 490 x 30, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\BA0F5CB6.png
PNG image data, 934 x 29, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\DEFF0268.png
PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Temp\05A40000
data
#
C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
Little-endian UTF-16 Unicode text, with CR line terminators
#