Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
54861 Proforma Invoice AMC2273745.xlam.xlsx

Overview

General Information

Sample name:54861 Proforma Invoice AMC2273745.xlam.xlsx
Analysis ID:1581205
MD5:2e09dd3b63476290fadb7da20b5beed9
SHA1:c32f53f312efb6d0dd99165cef588362f01b51ee
SHA256:dc6e207de8d2a4ff2feca507ed1ee1179004d1cf526d5563cf735e40df9518bd
Tags:AgentTeslaxlamxlsxuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Document contains OLE streams with names of living off the land binaries
Document misses a certain OLE stream usually present in this Microsoft Office document type
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Sample execution stops while process was sleeping (likely an evasion)
Yara signature match

Classification

  • System is w10x64
  • EXCEL.EXE (PID: 7516 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: 4A871771235598812032C822E6F68F19)
    • splwow64.exe (PID: 3428 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
sheet1.xmlINDICATOR_XML_LegacyDrawing_AutoLoad_Documentdetects AutoLoad documents using LegacyDrawingditekSHen
  • 0x24c3:$s1: <legacyDrawing r:id="
  • 0x24eb:$s2: <oleObject progId="
  • 0x253b:$s3: autoLoad="true"
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: 54861 Proforma Invoice AMC2273745.xlam.xlsxAvira: detected
Source: 54861 Proforma Invoice AMC2273745.xlam.xlsxVirustotal: Detection: 50%Perma Link
Source: 54861 Proforma Invoice AMC2273745.xlam.xlsxReversingLabs: Detection: 68%
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: excel.exeMemory has grown: Private usage: 2MB later: 88MB
Source: 57C8EDB95DF3F0AD4EE2DC2B8CFD4157.0.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab

System Summary

barindex
Source: sheet1.xml, type: SAMPLEMatched rule: detects AutoLoad documents using LegacyDrawing Author: ditekSHen
Source: 54861 Proforma Invoice AMC2273745.xlam.xlsxStream path '\x1oLE10NaTIvE' : o.....E..n.B.u ..n.Wd.P.!~Bq.x.R_A.1V|MX.R!V.~.3*x.R\ws.GE{;N.<*.'.qIv_.yv..~ny\d.:?..W.:...&.M.I2Vb<hg[A)`X.Jb.s0.6W..w5g..1f2..9}...W_.&/..B..+Rd5SKm.)0}XOB./m....V+j>u/C..!Q.g..P=mo.-#,n..q..BB:Xy..YIV([R%00O~8.vNHq...--I<'7'.1jYn.#...4.8PN^.{e. %}<..9.8Z........G#PS[M..l'..V^[XO...O...f......&......y.......5......W_VSk..I..[^...iC.&}...a..........}{...9...?.zF.~~.l...PXRY\..1....E..ZW1....A...........Fv.]c.s..._....w\......S[........pB...O...*...m.M8V%P'.I...6..C.uWmu=PP_..1b..-~A........*A..XXFcWk.L.o.Bpa=@9.?t\...1&1U&M..QI!9.|{@%a.L13F+K.g:.Y{U..`Q;31..8AAcjl te019N]J'(.<:p,YO((. <D..(0.._^HL..HJ.(x.A.'.3}.mX...r>.{w%p.2.ZnCN@[=.mO|.i2..\U.^%8.@#D2?.m>Ya{(.Uf<...^c`X.\KZg+eQ6,,i.faO..N..k.-%Z.x.E1A>.`mRTZ#oj%.0l...|Yw_O.7.=...-WN/E0Em.#/u.g.oU..=lQq.g{.j.s.q.aVe..4 ..a.jfM.]O.(.N.jq=cG.Cv.1.6..J..X[.X!L{s;xd....+6..|U]fnR../*.6$b...L)8R@tR@W`.~..Jyp.Q.,d:y..j.YG.(qw}NY.F.h_F&.PC'2%XF:wm!.{4:FE{.v*dLC[DJ*[Vikbb.j%`..>H.".A.N{@NM.x5.s!+I+#l.[y!V.p@,ld-8*1hbY!=)`+K.I.-u_\..#..7..+...Nb7.,2xS.,eTQ!IIH:o.foE..)1+)-Ym.Eh.kJ7+....d_)`Fw`s5%..w.yFvCI...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Source: 54861 Proforma Invoice AMC2273745.xlam.xlsxOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
Source: sheet1.xml, type: SAMPLEMatched rule: INDICATOR_XML_LegacyDrawing_AutoLoad_Document author = ditekSHen, description = detects AutoLoad documents using LegacyDrawing
Source: classification engineClassification label: mal68.winXLSX@3/5@0/0
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\~$54861 Proforma Invoice AMC2273745.xlam.xlsxJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{234A3DC7-8974-4CE5-81DE-E9D570DF85AC} - OProcSessId.datJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: 54861 Proforma Invoice AMC2273745.xlam.xlsxVirustotal: Detection: 50%
Source: 54861 Proforma Invoice AMC2273745.xlam.xlsxReversingLabs: Detection: 68%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3EE60F5C-9BAD-4CD8-8E21-AD2D001D06EB}\InprocServer32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: 54861 Proforma Invoice AMC2273745.xlam.xlsxInitial sample: OLE zip file path = xl/media/image1.jpg
Source: 54861 Proforma Invoice AMC2273745.xlam.xlsxInitial sample: OLE zip file path = xl/calcChain.xml
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: 54861 Proforma Invoice AMC2273745.xlam.xlsxInitial sample: OLE indicators vbamacros = False
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 903Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Extra Window Memory Injection
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Extra Window Memory Injection
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
54861 Proforma Invoice AMC2273745.xlam.xlsx51%VirustotalBrowse
54861 Proforma Invoice AMC2273745.xlam.xlsx68%ReversingLabsDocument-Office.Exploit.CVE-2017-11882
54861 Proforma Invoice AMC2273745.xlam.xlsx100%AviraEXP/CVE-2017-11882.Gen
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    high
    s-part-0035.t-0009.t-msedge.net
    13.107.246.63
    truefalse
      high
      No contacted IP infos
      Joe Sandbox version:41.0.0 Charoite
      Analysis ID:1581205
      Start date and time:2024-12-27 08:34:12 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 4m 54s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:defaultwindowsofficecookbook.jbs
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:10
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Sample name:54861 Proforma Invoice AMC2273745.xlam.xlsx
      Detection:MAL
      Classification:mal68.winXLSX@3/5@0/0
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      Cookbook Comments:
      • Found application associated with file extension: .xlsx
      • Found Word or Excel or PowerPoint or XPS Viewer
      • Attach to Office via COM
      • Active ActiveX Object
      • Scroll down
      • Close Viewer
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, sppsvc.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 52.109.32.97, 23.218.208.109, 52.113.194.132, 52.109.28.47, 199.232.214.172, 13.89.179.13, 20.190.147.5, 52.149.20.212, 13.107.246.63
      • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, otelrules.afd.azureedge.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, eur.roaming1.live.com.akadns.net, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, onedscolprdcus21.centralus.cloudapp.azure.com, ocsp.digicert.com, login.live.com, e16604.g.akamaiedge.net, officeclient.microsoft.com, ukw-azsc-config.officeapps.live.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, otelrules.azureedge.net, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, osiprod-uks-buff-azsc-000.uksouth.cloudapp.azure.com, fe3cr.delivery.mp.microsoft.com, uks-azsc-000.roaming.officeapps.live.com, s-0005.s-msedge.net, config.officeapps.live.com, azureed
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtCreateKey calls found.
      • Report size getting too big, too many NtQueryAttributesFile calls found.
      • Report size getting too big, too many NtQueryValueKey calls found.
      • Report size getting too big, too many NtReadVirtualMemory calls found.
      TimeTypeDescription
      02:36:25API Interceptor932x Sleep call for process: splwow64.exe modified
      No context
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      s-part-0035.t-0009.t-msedge.netinstaller.batGet hashmaliciousVidarBrowse
      • 13.107.246.63
      din.exeGet hashmaliciousVidarBrowse
      • 13.107.246.63
      lem.exeGet hashmaliciousVidarBrowse
      • 13.107.246.63
      atw3.dllGet hashmaliciousGozi, UrsnifBrowse
      • 13.107.246.63
      WRD1792.docx.docGet hashmaliciousDynamerBrowse
      • 13.107.246.63
      0zBsv1tnt4.exeGet hashmaliciousLummaCBrowse
      • 13.107.246.63
      pVbAZEFIpI.exeGet hashmaliciousLummaCBrowse
      • 13.107.246.63
      GxX48twWHA.exeGet hashmaliciousLummaCBrowse
      • 13.107.246.63
      ERTL09tA59.exeGet hashmaliciousLummaCBrowse
      • 13.107.246.63
      90m2xwxCOf.exeGet hashmaliciousUnknownBrowse
      • 13.107.246.63
      bg.microsoft.map.fastly.net6ee7HCp9cD.exeGet hashmaliciousQuasarBrowse
      • 199.232.214.172
      C8QT9HkXEb.exeGet hashmaliciousLummaCBrowse
      • 199.232.210.172
      P9UXlizXVS.exeGet hashmaliciousAsyncRATBrowse
      • 199.232.214.172
      Setup64v4.1.9.exeGet hashmaliciousUnknownBrowse
      • 199.232.214.172
      0Ty.png.exeGet hashmaliciousXmrigBrowse
      • 199.232.214.172
      0442.pdf.exeGet hashmaliciousUnknownBrowse
      • 199.232.210.172
      0442.pdf.exeGet hashmaliciousUnknownBrowse
      • 199.232.214.172
      yvaKqhmD4L.exeGet hashmaliciousUnknownBrowse
      • 199.232.210.172
      #U5b89#U88c5#U7a0b#U5e8f_1.1.1.exeGet hashmaliciousUnknownBrowse
      • 199.232.210.172
      IoIB9gQ6OQ.exeGet hashmaliciousAsyncRAT, PureLog StealerBrowse
      • 199.232.210.172
      No context
      No context
      No context
      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
      Category:dropped
      Size (bytes):118
      Entropy (8bit):3.5700810731231707
      Encrypted:false
      SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
      MD5:573220372DA4ED487441611079B623CD
      SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
      SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
      SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
      Malicious:false
      Reputation:high, very likely benign file
      Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      File Type:data
      Category:dropped
      Size (bytes):340
      Entropy (8bit):3.4313708529617903
      Encrypted:false
      SSDEEP:6:kKdNK8yG7DYUN+SkQlPlEGYRMY9z+s3Ql2DUeXJlOW1:ulLkPlE99SCQl2DUeXJlOA
      MD5:6E7663137A1D09BB832154967EB84C0E
      SHA1:C4196C4DECAD373EA8CDF1F682E34B099E9457FD
      SHA-256:74AB10F0ACF0A7BCDC980848BA9A602E6330F39E5223D6053A2C9BC11A312A4F
      SHA-512:6D9693742F7299F5CC44F86EA4FE4750A7EAA299E619C8C2A1ECDEA5ED0D23EAE60731E56292D68A2A55E1722772068359E1296519594006D83DC3644FDFE3A1
      Malicious:false
      Reputation:low
      Preview:p...... ........(?9.1X..(.................................................o.@... ........~..MG......&...............h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.d.i.s.a.l.l.o.w.e.d.c.e.r.t.s.t.l...c.a.b...".0.6.c.f.c.c.5.4.d.4.7.d.b.1.:.0."...
      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 139x76, components 3
      Category:dropped
      Size (bytes):8213
      Entropy (8bit):7.846014496130794
      Encrypted:false
      SSDEEP:192:XM6gSJbO9TUYG+Fb7CK7EXLbe8RTZRk+OHkT19blQEJoRABky/8E:XMJIyiYG6b7CKgXLbe8kkvaY3t
      MD5:0AADEBFCF977109C6FD91C324285BEE8
      SHA1:4C80DD68330905F123361915E3B6F5D822664CB4
      SHA-256:6227127DF97E76623C99875BE5D5188BA3068DADF050B87C4CBD383B508B0A9C
      SHA-512:9C0E5B0FC8AF6BDD9ED18A58393355592F52CF5BB480640162D2C9B80844A3FC1CDA43F57328171E7F068B11944AA47C87FCC6D33B6FDD34670DA49EEBAA548A
      Malicious:false
      Reputation:low
      Preview:......JFIF.............C....................................................................C.......................................................................L...."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?...(...(...)23.O.-g.r..dtHa..pW.c.A%....U..._9.R.#)...)7.I]..&RQNRiE].M.........x?..K_.~4...........?....#.:7........wM.uO..W.s...-..kvZ..G....n ..K.aK.3.....9.....j=.._.K...j.......tK...V.5}_I..oncc.km?R.....m&.?'.......*.0..n.u)...nU).R.j.)u.>.>G&.......Nu..b..j.B...Jt......I...vvg.Nv3..t.9.}...pk............+..G..uo..?.|.y.k/.v..x{.Wv.!m.,.Q.Y...g.\.;.
      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      File Type:data
      Category:dropped
      Size (bytes):165
      Entropy (8bit):1.4377382811115937
      Encrypted:false
      SSDEEP:3:KVC+cAmltV:KVC+cR
      MD5:9C7132B2A8CABF27097749F4D8447635
      SHA1:71D7F78718A7AFC3EAB22ED395321F6CBE2F9899
      SHA-256:7029AE5479F0CD98D892F570A22B2AE8302747DCFF3465B2DE64D974AE815A83
      SHA-512:333AC8A4987CC7DF5981AE81238A77D123996DB2C4C97053E8BD2048A64FDCF33E1245DEE6839358161F6B5EEA6BFD8D2358BC4A9188D786295C22F79E2D635E
      Malicious:false
      Reputation:moderate, very likely benign file
      Preview:.user ..j.o.n.e.s. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      File Type:data
      Category:dropped
      Size (bytes):165
      Entropy (8bit):1.4377382811115937
      Encrypted:false
      SSDEEP:3:KVC+cAmltV:KVC+cR
      MD5:9C7132B2A8CABF27097749F4D8447635
      SHA1:71D7F78718A7AFC3EAB22ED395321F6CBE2F9899
      SHA-256:7029AE5479F0CD98D892F570A22B2AE8302747DCFF3465B2DE64D974AE815A83
      SHA-512:333AC8A4987CC7DF5981AE81238A77D123996DB2C4C97053E8BD2048A64FDCF33E1245DEE6839358161F6B5EEA6BFD8D2358BC4A9188D786295C22F79E2D635E
      Malicious:true
      Preview:.user ..j.o.n.e.s. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
      File type:Microsoft Excel 2007+
      Entropy (8bit):7.99827146202957
      TrID:
      • Excel Microsoft Office Open XML Format document (35004/1) 81.40%
      • ZIP compressed archive (8000/1) 18.60%
      File name:54861 Proforma Invoice AMC2273745.xlam.xlsx
      File size:728'772 bytes
      MD5:2e09dd3b63476290fadb7da20b5beed9
      SHA1:c32f53f312efb6d0dd99165cef588362f01b51ee
      SHA256:dc6e207de8d2a4ff2feca507ed1ee1179004d1cf526d5563cf735e40df9518bd
      SHA512:6eb8d609db9f7ada31d0ec7e7bcc121b0a4b81e018e062525141e94ced434f1c7d1fba28b24c394c07a6cfe1994a958a9fbd63d9fc8428f405af50bcde4e52aa
      SSDEEP:12288:TGnWG/qUPBh6yIoyfiODX5TwyOX5F3elG2X93RFs7uYuE4P29kfTyyrxNsAO39fH:S8UPSjZ5TwtOGyG7uw9Cx3oH
      TLSH:A1F433CA61C282FD5AE95EF0DF8D2CB0C707AD77A4004457BE78DD8EA67D54B70A4A00
      File Content Preview:PK...........Y..b.............[Content_Types].xmlUT...|Elg|Elg|Elg.U.n.0....?..."...........I?."..m.B2...]J.Q...C...;3;..j~..]l!D.lE....`...6...t_~'EL.J..... ......O;..@...iS.?.....#u.,FV....54.s.......7&.M`S.2........T.u.y..V...!/KU.{.....lk.;...VJ.t.. .
      Icon Hash:35e58a8c0c8a85b9
      Document Type:OpenXML
      Number of OLE Files:1
      Has Summary Info:
      Application Name:
      Encrypted Document:False
      Contains Word Document Stream:False
      Contains Workbook/Book Stream:False
      Contains PowerPoint Document Stream:False
      Contains Visio Document Stream:False
      Contains ObjectPool Stream:False
      Flash Objects Count:0
      Contains VBA Macros:False
      Author:SHINY
      Last Saved By:X10LUXURY
      Create Time:2010-06-04T08:55:28Z
      Last Saved Time:2023-07-30T22:56:25Z
      Creating Application:Microsoft Excel
      Security:0
      Thumbnail Scaling Desired:false
      Company:Grizli777
      Contains Dirty Links:false
      Shared Document:false
      Changed Hyperlinks:false
      Application Version:15.0300
      General
      Stream Path:\x1oLE10NaTIvE
      CLSID:
      File Type:data
      Stream Size:981785
      Entropy:5.96885181692536
      Base64 Encoded:True
      Data ASCII:o . . . . . E . . n . B . u . . n . W d . P . ! ~ B q . x . R _ A . 1 V | M X . R ! V . ~ . 3 * x . R \\ w s . G E { ; N . < * . ' . q I v _ . y v . . ~ n y \\ d . : ? . . W . : . . . & . M . I 2 V b < h g [ A ) ` X . J b . s 0 . 6 W . . w 5 g . . 1 f 2 . . 9 } . . . W _ . & / . . B . . + R d 5 S K m . ) 0 } X O B . / m . . . . V + j > u / C . . ! Q . g . . P = m o . - # , n . . q . . B B : X y . . Y I V ( [ R % 0 0 O ~ 8 . v N H q . . . - - I < ' 7 ' . 1 j Y n . # . . . 4 . 8 P N ^ . { e . % } < . . 9 .
      Data Raw:6f 8a 1b 04 03 d9 b2 19 bd 45 01 08 6e 0f bd e3 42 ba ff f7 d5 8b 75 20 8b 06 bf bb 7f 6e 1a 81 e7 f4 e7 57 64 8b 1f 50 ff d3 05 21 7e 42 71 05 78 82 bd 8e ff e0 08 c1 ea 52 5f 9e 41 00 31 9e 56 7c 4d 58 ed 03 ef c1 84 c2 52 21 bd 56 8c d0 9c 7e 09 9a 9d 9e 33 2a 78 c8 e8 ff 1c 99 a8 52 a9 f2 87 5c 77 96 73 0a 47 45 c0 7b cc ea 88 3b 4e 02 e4 c4 3c 9e 84 a6 2a ce 10 d1 27 ea 08 71
      General
      Stream Path:xm4ePseOxAGUGiQqustmGbexc18
      CLSID:
      File Type:empty
      Stream Size:0
      Entropy:0.0
      Base64 Encoded:False
      Data ASCII:
      Data Raw:
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Dec 27, 2024 08:35:26.869601011 CET1.1.1.1192.168.2.40x17feNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
      Dec 27, 2024 08:35:26.869601011 CET1.1.1.1192.168.2.40x17feNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
      Dec 27, 2024 08:35:33.232431889 CET1.1.1.1192.168.2.40xd5afNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
      Dec 27, 2024 08:35:33.232431889 CET1.1.1.1192.168.2.40xd5afNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
      Dec 27, 2024 08:36:02.992393970 CET1.1.1.1192.168.2.40xe228No error (0)shed.dual-low.s-part-0035.t-0009.t-msedge.nets-part-0035.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
      Dec 27, 2024 08:36:02.992393970 CET1.1.1.1192.168.2.40xe228No error (0)s-part-0035.t-0009.t-msedge.net13.107.246.63A (IP address)IN (0x0001)false
      Dec 27, 2024 08:36:28.107099056 CET1.1.1.1192.168.2.40x428No error (0)shed.dual-low.s-part-0035.t-0009.t-msedge.nets-part-0035.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
      Dec 27, 2024 08:36:28.107099056 CET1.1.1.1192.168.2.40x428No error (0)s-part-0035.t-0009.t-msedge.net13.107.246.63A (IP address)IN (0x0001)false

      Click to jump to process

      Click to jump to process

      Click to dive into process behavior distribution

      Click to jump to process

      Target ID:0
      Start time:02:35:18
      Start date:27/12/2024
      Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
      Wow64 process (32bit):true
      Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
      Imagebase:0x320000
      File size:53'161'064 bytes
      MD5 hash:4A871771235598812032C822E6F68F19
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:high
      Has exited:false

      Target ID:7
      Start time:02:36:25
      Start date:27/12/2024
      Path:C:\Windows\splwow64.exe
      Wow64 process (32bit):false
      Commandline:C:\Windows\splwow64.exe 12288
      Imagebase:0x7ff6d1a70000
      File size:163'840 bytes
      MD5 hash:77DE7761B037061C7C112FD3C5B91E73
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:high
      Has exited:false

      No disassembly