Windows
Analysis Report
Companies House Trust Excel Document.xlsm
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w7x64
EXCEL.EXE (PID: 2768 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\Offic e14\EXCEL. EXE" /auto mation -Em bedding MD5: D53B85E21886D2AF9815C377537BCAC3)
- cleanup
Click to jump to signature section
Source: | File opened: | Jump to behavior |
System Summary |
---|
Source: | Stream path 'VBA/Module1' : |
Source: | OLE indicator, VBA macros: |
Source: | File created: | Jump to behavior |
Source: | OLE indicator, Workbook stream: |
Source: | Classification label: |
Source: | File read: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Stream path 'VBA/Module1' : |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | OLE indicator, VBA stomping: |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact | Resource Development | Reconnaissance |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | 21 Scripting | Path Interception | Path Interception | 1 Masquerading | OS Credential Dumping | 1 File and Directory Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | Data Obfuscation | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Abuse Accessibility Features | Acquire Infrastructure | Gather Victim Identity Information |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 21 Scripting | LSASS Memory | 1 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Junk Data | SIM Card Swap | Obtain Device Cloud Backups | Network Denial of Service | Domains | Credentials |
Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Steganography | Data Encrypted for Impact | DNS Server | Email Addresses | ||
Local Accounts | Cron | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Traffic Duplication | Protocol Impersonation | Data Destruction | Virtual Private Server | Employee Names |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Joe Sandbox Version: | 38.0.0 Ammolite |
Analysis ID: | 1350052 |
Start date and time: | 2023-11-29 19:01:16 +01:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 3m 48s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsofficecookbook.jbs |
Analysis system description: | Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2) |
Number of analysed new started processes analysed: | 3 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample file name: | Companies House Trust Excel Document.xlsm |
Detection: | MAL |
Classification: | mal52.evad.winXLSM@1/3@0/0 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis
(whitelisted): dllhost.exe, WM IADAP.exe - Excluded IPs from analysis (wh
itelisted): 184.87.173.89, 184 .87.173.58, 23.206.121.39, 23. 206.121.28 - Excluded domains from analysis
(whitelisted): ctldl.windowsu pdate.com, a767.dspw65.akamai. net, wu-bg-shim.trafficmanager .net, download.windowsupdate.c om.edgesuite.net - Report size getting too big, t
oo many NtQueryValueKey calls found. - Report size getting too big, t
oo many NtSetInformationFile c alls found. - VT rate limit hit for: Compan
ies House Trust Excel Document .xlsm
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 147284 |
Entropy (8bit): | 4.421670275438143 |
Encrypted: | false |
SSDEEP: | 1536:C8lL3FNSc8SetKB96vQVCBumVMOej6mXmYarrJQcd1FaLcmB:CeJNSc83tKBAvQVCgOtmXmLpLmB |
MD5: | 8E6E187ED4DA7BBBC75A1F2AC1C5CDA4 |
SHA1: | 42C99C555496C241B8F1677D0AABF95E5F4E256E |
SHA-256: | 5E9E69BD8CF8B92D81E5897BB3B8F781A4849EFA819569AD6059FA4DF4A0F04F |
SHA-512: | 0AE687D526F9F85A8198DC788DFF2DDC495F7BD5D0DCA2E5D7FAD0778612878E38D91A19B596A7814A08C8A2270376B7D14F265788287545A9308B02912467C4 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 98304 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:: |
MD5: | 0A9156C4E3C48EF827980639C4D1E263 |
SHA1: | 9F13A523321C66208E90D45F87FA0CD9B370E111 |
SHA-256: | 3A3ED164E42500A1C5B2D0093F0A813D27DC50D038F330CC100A7E70ECE2E6E4 |
SHA-512: | 8A46C1B44C0EA338AFF0D2E2D07C34430B67B68B6D27E1ADB8CF216B0F0994172CED106A90283F2F0469B5CAA40ACEDF101D45729B823E5179EA55AC507E04AD |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 165 |
Entropy (8bit): | 1.4377382811115937 |
Encrypted: | false |
SSDEEP: | 3:vZ/FFDJw2fV:vBFFGS |
MD5: | 797869BB881CFBCDAC2064F92B26E46F |
SHA1: | 61C1B8FBF505956A77E9A79CE74EF5E281B01F4B |
SHA-256: | D4E4008DD7DFB936F22D9EF3CC569C6F88804715EAB8101045BA1CD0B081F185 |
SHA-512: | 1B8350E1500F969107754045EB84EA9F72B53498B1DC05911D6C7E771316C632EA750FBCE8AD3A82D664E3C65CC5251D0E4A21F750911AE5DC2FC3653E49F58D |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 7.8748953501236025 |
TrID: |
|
File name: | Companies House Trust Excel Document.xlsm |
File size: | 57'842 bytes |
MD5: | 77b1b8d9244c48ed5a3ec4cabcac2201 |
SHA1: | f7a38dc3942c47da07f6cd4559beff4e10dca643 |
SHA256: | ccb6b1b4a79810defd516fb4cf5a3982437068858e001a34622890a1a22f7209 |
SHA512: | 27a9e8aa2ee7140ff3d70a3941b0a8295294fc7a3caccb3a092e056c7231fe69bab89c3b69089750d3ec1c869fc7f3e4983e9cef668e5893aa11b3d6df799cfa |
SSDEEP: | 1536:Y+vxTRBudd4ThvxbqJPwK/XXsvEzDjZW3Q1tI7KZJr1x:Y+vx1BudulpJK/XXu8xS7KZ5P |
TLSH: | F943F14C4680EE4DDFBBCC3E612D40D0258D096E92D3AD5621F5AFCE0342457E795FAA |
File Content Preview: | PK..........!...=.............[Content_Types].xml ...(......................................................................................................................................................................................................... |
Icon Hash: | 2562ab89afbfbfaf |
Document Type: | OpenXML |
Number of OLE Files: | 1 |
Has Summary Info: | |
Application Name: | |
Encrypted Document: | False |
Contains Word Document Stream: | False |
Contains Workbook/Book Stream: | True |
Contains PowerPoint Document Stream: | False |
Contains Visio Document Stream: | False |
Contains ObjectPool Stream: | False |
Flash Objects Count: | 0 |
Contains VBA Macros: | True |
Title: | |
Subject: | |
Author: | |
Keywords: | |
Last Saved By: | |
Revion Number: | |
Total Edit Time: | 0 |
Create Time: | 2022-04-07T19:40:59Z |
Last Saved Time: | 2022-11-15T17:35:20Z |
Creating Application: | |
Security: | 0 |
Thumbnail Scaling Desired: | false |
Company: | |
Contains Dirty Links: | false |
Shared Document: | false |
Changed Hyperlinks: | false |
Application Version: | 16.0300 |
General | |
Stream Path: | VBA/Module1 |
VBA File Name: | Module1 |
Stream Size: | 31370 |
Data ASCII: | . . . . . . . . & . . . . . . , . . . . . . _ . . B b . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . H . . . . . . . . 8 L : . . . . . . . . . . . > . . . . . . L . . . . . . . . . . . . . . . . . L . . . . . L . |
Data Raw: | 01 16 03 00 06 f4 00 00 00 26 1f 00 00 d8 00 00 00 2c 02 00 00 ff ff ff ff f4 1f 00 00 c0 5f 00 00 42 62 00 00 01 00 00 00 01 00 00 00 ff ff ff ff 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff 08 00 ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | VBA/Sheet1 |
VBA File Name: | Sheet1 |
Stream Size: | 1329 |
Data ASCII: | . . . . . . . . . ^ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . p . . . . E ) . M C . . . . . . . . . . . . . . . F . . . . . . . . . . . . . . . . . . . . : . u . : I . X e . . . . . . . . . . . . . . . . . . . . . . x . . . . : . u . : I . X e . E ) . M C . . . . . . M E . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . 6 " . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - . 0 . 0 . 0 . 0 . - . |
Data Raw: | 01 16 03 00 06 04 01 00 00 5e 03 00 00 e8 00 00 00 14 02 00 00 8c 03 00 00 9a 03 00 00 ee 03 00 00 80 04 00 00 00 00 00 00 01 00 00 00 ff ff ff ff 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff 70 00 ff ff 00 00 00 45 bd 29 05 4d 43 8d 93 bb d2 0a a8 0a a8 bb 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | VBA/Sheet2 |
VBA File Name: | Sheet2 |
Stream Size: | 1148 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . 9 . . . . . . . . . . . . . . \\ . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . |
Data Raw: | 01 16 03 00 01 f4 00 00 00 de 02 00 00 d8 00 00 00 04 02 00 00 ff ff ff ff e5 02 00 00 39 03 00 00 cb 03 00 00 00 00 00 00 01 00 00 00 ff ff 5c 96 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | VBA/Sheet3 |
VBA File Name: | Sheet3 |
Stream Size: | 1329 |
Data ASCII: | . . . . . . . . . ^ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . p . . . F . m J . k f . . . . . . . . . . . . . F . . . . . . . . . . . . . . . . . . . . 8 > 1 J : O r . . . . . . . . . . . . . . . . . . . . . . . x . . . . 8 > 1 J : O r . F . m J . k f . . . . M E . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . 6 " . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - . 0 . 0 . 0 . 0 . - . 0 . 0 . |
Data Raw: | 01 16 03 00 06 04 01 00 00 5e 03 00 00 e8 00 00 00 14 02 00 00 8c 03 00 00 9a 03 00 00 ee 03 00 00 80 04 00 00 00 00 00 00 01 00 00 00 ff ff ff ff 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff 70 00 ff ff 00 00 46 15 c5 d3 ee 6d 4a fd b6 11 b9 a2 87 6b 66 82 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | VBA/Sheet4 |
VBA File Name: | Sheet4 |
Stream Size: | 1329 |
Data ASCII: | . . . . . . . . . ^ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . p . . . . y " D $ r ] f . . . . . . . . . . . . . F . . . . . . . . . . . . . . . . . . . . . G B . . N . . . . . . . . . . . . . . . . . . . . . . x . . . . . G B . . N . y " D $ r ] f . . . . M E . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . 6 " . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . |
Data Raw: | 01 16 03 00 06 04 01 00 00 5e 03 00 00 e8 00 00 00 14 02 00 00 8c 03 00 00 9a 03 00 00 ee 03 00 00 80 04 00 00 00 00 00 00 01 00 00 00 ff ff ff ff 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff 70 00 ff ff 00 00 e4 14 e6 79 f2 22 44 8a a8 24 72 5d a3 66 df c7 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | VBA/Sheet5 |
VBA File Name: | Sheet5 |
Stream Size: | 1329 |
Data ASCII: | . . . . . . . . . ^ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . p . . . . . | C . y e c . . . . . . . . . . . . . F . . . . . . . . . . . . . . . . . . . . E . 2 I M z . c . . . . . . . . . . . . . . . . . . . . . . . x . . . . E . 2 I M z . c . . . | C . y e c . . . . M E . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . 6 " . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - . 0 . 0 . 0 . 0 . - . |
Data Raw: | 01 16 03 00 06 04 01 00 00 5e 03 00 00 e8 00 00 00 14 02 00 00 8c 03 00 00 9a 03 00 00 ee 03 00 00 80 04 00 00 00 00 00 00 01 00 00 00 ff ff ff ff 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff 70 00 ff ff 00 00 e6 b5 0e 02 d2 7c 43 03 93 9a 79 65 63 83 84 9f 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | VBA/Sheet7 |
VBA File Name: | Sheet7 |
Stream Size: | 1329 |
Data ASCII: | . . . . . . . . . ^ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . p . . . e P z E m / . . . . . . . . . . . . . F . . . . . . . . . . . . . . . . . . . . M W o F l ; * . . . . . . . . . . . . . . . . . . . . . . x . . . . M W o F l ; * e P z E m / . . . . M E . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . 6 " . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . |
Data Raw: | 01 16 03 00 06 04 01 00 00 5e 03 00 00 e8 00 00 00 14 02 00 00 8c 03 00 00 9a 03 00 00 ee 03 00 00 80 04 00 00 00 00 00 00 01 00 00 00 ff ff ff ff 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff 70 00 ff ff 00 00 b2 65 50 94 7a f6 45 9f aa fb ac e0 ae 6d 97 2f 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | VBA/ThisWorkbook |
VBA File Name: | ThisWorkbook |
Stream Size: | 1156 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . 9 . . . . . . . . . . . . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 1 . 9 . - |
Data Raw: | 01 16 03 00 01 f4 00 00 00 de 02 00 00 d8 00 00 00 04 02 00 00 ff ff ff ff e5 02 00 00 39 03 00 00 cb 03 00 00 00 00 00 00 01 00 00 00 ff ff ff ff 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | PROJECT |
CLSID: | |
File Type: | ASCII text, with CRLF line terminators |
Stream Size: | 711 |
Entropy: | 5.07704368192345 |
Base64 Encoded: | True |
Data ASCII: | I D = " { 0 B A 8 D D 0 2 - 0 E 0 3 - 3 4 4 2 - A 7 9 1 - 8 F C C 3 4 5 1 5 5 C 4 } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 3 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 4 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 5 / & H 0 0 0 0 0 0 0 0 . . M o d u l e = M o d u l e 1 . . D o c u m e n t = S h e e t 7 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 2 / & H 0 0 0 |
Data Raw: | 49 44 3d 22 7b 30 42 41 38 44 44 30 32 2d 30 45 30 33 2d 33 34 34 32 2d 41 37 39 31 2d 38 46 43 43 33 34 35 31 35 35 43 34 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 33 2f 26 48 30 30 30 |
General | |
Stream Path: | PROJECTwm |
CLSID: | |
File Type: | data |
Stream Size: | 191 |
Entropy: | 3.1529191325831984 |
Base64 Encoded: | False |
Data ASCII: | T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 1 . S . h . e . e . t . 1 . . . S h e e t 3 . S . h . e . e . t . 3 . . . S h e e t 4 . S . h . e . e . t . 4 . . . S h e e t 5 . S . h . e . e . t . 5 . . . M o d u l e 1 . M . o . d . u . l . e . 1 . . . S h e e t 7 . S . h . e . e . t . 7 . . . S h e e t 2 . S . h . e . e . t . 2 . . . . . |
Data Raw: | 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 53 68 65 65 74 33 00 53 00 68 00 65 00 65 00 74 00 33 00 00 00 53 68 65 65 74 34 00 53 00 68 00 65 00 65 00 74 00 34 00 00 00 53 68 65 65 74 35 00 53 00 68 00 65 00 65 00 74 00 35 00 00 00 4d 6f 64 75 6c |
General | |
Stream Path: | VBA/_VBA_PROJECT |
CLSID: | |
File Type: | data |
Stream Size: | 5230 |
Entropy: | 4.8463883780985775 |
Base64 Encoded: | False |
Data ASCII: | a . . . . . . . . . . . . . ' . . . . . . . . . . . . . . . . @ . * . \\ . H . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 6 . . . 0 . # . 9 . # . / . A . p . p . l . i . c . a . t . i . o . n . s . / . M . i . c . r . o . s . o . f . t . . E . x . c . e . l . . . a . p . p . / . C . o . n . t . e . n . t . s . / . S . h . a . r . e . d . S . u . p . p . o . r . t . / . T . y . p . e . . L . i |
Data Raw: | cc 61 df 00 00 03 00 ff 09 08 00 00 09 04 00 00 10 27 03 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 40 01 2a 00 5c 00 48 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 36 00 2e 00 30 00 23 00 |
General | |
Stream Path: | VBA/__SRP_0 |
CLSID: | |
File Type: | data |
Stream Size: | 11440 |
Entropy: | 3.473454736944786 |
Base64 Encoded: | False |
Data ASCII: | K * . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . r U . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . |
Data Raw: | 93 4b 2a df 03 00 10 00 00 00 ff ff 00 00 00 00 01 00 02 00 ff ff 00 00 00 00 01 00 00 00 05 00 00 00 00 00 01 00 02 00 05 00 00 00 00 00 01 00 00 00 01 00 00 00 00 00 01 00 02 00 01 00 00 00 00 00 01 00 00 00 03 00 00 00 00 00 01 00 02 00 03 00 00 00 00 00 01 00 00 00 07 00 00 00 00 00 01 00 02 00 07 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 01 00 02 00 02 00 00 00 00 00 01 00 |
General | |
Stream Path: | VBA/__SRP_1 |
CLSID: | |
File Type: | data |
Stream Size: | 541 |
Entropy: | 2.619396199691912 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . @ . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ . . . . . . . ~ v . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . t a r g e t . . . . . . . . . . . . . . . . S t o r e T e x t . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 02 00 00 00 00 00 00 7e 02 00 00 00 00 00 00 7e 76 00 00 00 00 00 00 7f 00 00 00 00 00 00 00 00 12 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff ff ff ff ff 11 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_2 |
CLSID: | |
File Type: | data |
Stream Size: | 12894 |
Entropy: | 4.2759294082066965 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . @ . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Q . . . . . . . . . . . A . . . . . . . . . . . . . . . . . . . . . . q . . . . . . . . . . . A . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . q . . . . . . . . . . . a . . . . . . . . . . . ! . . . . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 01 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 04 00 00 00 00 00 00 7e 78 00 00 00 00 00 00 7f 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 03 00 10 00 00 00 00 00 00 00 00 00 02 00 09 00 09 00 90 00 00 00 c1 0a 00 00 00 00 00 00 00 00 00 00 11 0c 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_3 |
CLSID: | |
File Type: | data |
Stream Size: | 772 |
Entropy: | 2.262130968771102 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . ` . . . . . . . . . . . . H . . . . . . . . . . . . . . . ` . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . @ . A . . . . . . . . . . . . . . ` . . . . . . . . . . . . . . . . . . . . . . . . P . P . . . . . . . . . . . . . . . ` . . . . . . A . . . . . . . . . . . . . . . . . . . . . . . . . . . . P . X . A . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 02 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 10 00 00 00 08 00 38 00 f1 00 00 00 00 00 00 00 00 00 02 00 00 00 00 60 00 00 fd ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_4 |
CLSID: | |
File Type: | data |
Stream Size: | 464 |
Entropy: | 1.6125343829533856 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . q . . . . . . . . . . . . . . . ` . . . 1 . . . . . . . . . . . . . . . . . . . . . . a . . . . . . . . . . . . . . . . D . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 05 00 80 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 00 00 00 01 00 a1 12 00 00 00 00 00 00 00 00 00 00 d1 12 00 00 00 00 00 00 00 00 00 00 01 13 |
General | |
Stream Path: | VBA/__SRP_5 |
CLSID: | |
File Type: | data |
Stream Size: | 106 |
Entropy: | 1.3591119461716878 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . b . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 04 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 78 00 00 00 08 00 00 00 00 00 00 00 62 00 00 00 00 00 00 7f 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_6 |
CLSID: | |
File Type: | data |
Stream Size: | 464 |
Entropy: | 1.6217254659415115 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A . . . . . . . . . . . . . . . . . . . . . . q . . . . . . . . . . . q . . . . . . . . . . . . . . . ` . . . 1 . . . . . . . . . . . . . . . . . . . . . . a . . . . . . . . . . . . . . . . D . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 07 00 20 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 00 00 00 01 00 41 1c 00 00 00 00 00 00 00 00 00 00 d1 12 00 00 00 00 00 00 00 00 00 00 71 1c |
General | |
Stream Path: | VBA/__SRP_7 |
CLSID: | |
File Type: | data |
Stream Size: | 106 |
Entropy: | 1.3591119461716878 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . b . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 06 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 78 00 00 00 08 00 00 00 00 00 00 00 62 00 00 00 00 00 00 7f 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_8 |
CLSID: | |
File Type: | data |
Stream Size: | 464 |
Entropy: | 1.6319730683168638 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . q . . . . . . . . . . . . . . . ` . . . 1 . . . . . . . . . . . . . . . . . . . . . . a . . . . . . . . . . . . . . . . D . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 09 00 c0 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 00 00 00 01 00 b1 1e 00 00 00 00 00 00 00 00 00 00 d1 12 00 00 00 00 00 00 00 00 00 00 e1 1e |
General | |
Stream Path: | VBA/__SRP_9 |
CLSID: | |
File Type: | data |
Stream Size: | 106 |
Entropy: | 1.3402440216433862 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . b . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 08 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 78 00 00 00 08 00 00 00 00 00 00 00 62 00 00 00 00 00 00 7f 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_a |
CLSID: | |
File Type: | data |
Stream Size: | 464 |
Entropy: | 1.630346155596684 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A . . . . . . . . . . . q . . . . . . . . . . . . . . . ` . . . 1 . . . . . . . . . . . . . . . . . . . . . . a . . . . . . . . . . . . . . . . D . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 0b 00 20 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 00 00 00 01 00 11 1f 00 00 00 00 00 00 00 00 00 00 d1 12 00 00 00 00 00 00 00 00 00 00 41 1f |
General | |
Stream Path: | VBA/__SRP_b |
CLSID: | |
File Type: | data |
Stream Size: | 106 |
Entropy: | 1.3591119461716878 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . b . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 0a 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 78 00 00 00 08 00 00 00 00 00 00 00 62 00 00 00 00 00 00 7f 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_c |
CLSID: | |
File Type: | data |
Stream Size: | 464 |
Entropy: | 1.6319730683168638 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . q . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . q . . . . . . . . . . . . . . . ` . . . 1 . . . . . . . . . . . . . . . . . . . . . . a . . . . . . . . . . . . . . . . D . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 0d 00 80 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 00 00 00 01 00 71 1f 00 00 00 00 00 00 00 00 00 00 d1 12 00 00 00 00 00 00 00 00 00 00 a1 1f |
General | |
Stream Path: | VBA/__SRP_d |
CLSID: | |
File Type: | data |
Stream Size: | 106 |
Entropy: | 1.3591119461716878 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . b . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 0c 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 78 00 00 00 08 00 00 00 00 00 00 00 62 00 00 00 00 00 00 7f 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | VBA/dir |
CLSID: | |
File Type: | data |
Stream Size: | 831 |
Entropy: | 6.5369046286896095 |
Base64 Encoded: | True |
Data ASCII: | . ; . . . . . . . . 0 J . . . . . . . H * . . . . H . . T . . . ' . . . . V B . A P r o j e c t . . . . . @ . . . . . Z = . . . . r . . . . . . . . . B H d . . . E . J < . . . . . . . M . S F o r m s > . . . . . . S . F . o . . r . m . s . 3 . . . . * \\ H { 0 . D 4 5 2 E E 1 - . E 0 8 F - 1 0 1 . A - 8 . . - 0 2 6 . 0 8 C 4 D 0 B B . 4 } # 2 . 0 # 0 . # / A p p l i c . a t i o n s / M . i c r o s o f t . E x c e l . a . p p / C o n t e . n t s / S h a r . e d S u p p o r . t / T y p e L . i b r a r i |
Data Raw: | 01 3b b3 80 01 00 04 00 00 00 03 00 30 82 4a 02 90 00 00 01 00 02 02 48 2a 09 00 c0 14 06 48 03 00 54 00 00 20 10 27 04 00 0a 00 ac 56 42 00 41 50 72 6f 6a 65 63 74 a2 05 00 1a 00 00 40 02 0a 06 02 0a 5a 3d 02 0a 07 02 72 01 14 08 06 12 09 01 02 12 42 48 b9 64 04 00 0c 45 02 4a 3c 02 0a 16 00 07 00 07 4d 00 53 46 6f 72 6d 73 3e 00 02 0e 01 0c 00 53 00 46 00 6f 00 00 72 00 6d 00 73 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 0 |
Start time: | 19:02:05 |
Start date: | 29/11/2023 |
Path: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x13fdb0000 |
File size: | 28'253'536 bytes |
MD5 hash: | D53B85E21886D2AF9815C377537BCAC3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |