Windows
Analysis Report
TAX INVOICE - NBO2506000632.xlam.xlsx
Overview
General Information
Detection
Score: | 64 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
EXCEL.EXE (PID: 7532 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \Root\Offi ce16\EXCEL .EXE" /aut omation -E mbedding MD5: 4A871771235598812032C822E6F68F19) splwow64.exe (PID: 5304 cmdline:
C:\Windows \splwow64. exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
INDICATOR_XML_LegacyDrawing_AutoLoad_Document | detects AutoLoad documents using LegacyDrawing | ditekSHen |
|
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | File opened: | Jump to behavior |
Source: | Memory has grown: |
System Summary |
---|
Source: | Matched rule: |
Source: | OLE stream indicators for Word, Excel, PowerPoint, and Visio: |
Source: | Matched rule: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Window / User API: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 2 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Extra Window Memory Injection | 1 Virtualization/Sandbox Evasion | LSASS Memory | 1 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Process Injection | Security Account Manager | 1 Application Window Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Extra Window Memory Injection | NTDS | 1 File and Directory Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | 1 System Information Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
51% | Virustotal | Browse | ||
68% | ReversingLabs | Document-Office.Exploit.CVE-2017-11882 | ||
100% | Avira | EXP/CVE-2017-11882.Gen |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
s-part-0035.t-0009.t-msedge.net | 13.107.246.63 | true | false | high |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1581207 |
Start date and time: | 2024-12-27 08:34:14 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 40s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsofficecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | TAX INVOICE - NBO2506000632.xlam.xlsx |
Detection: | MAL |
Classification: | mal64.winXLSX@3/4@0/0 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, d llhost.exe, WMIADAP.exe, SIHCl ient.exe, conhost.exe, svchost .exe - Excluded IPs from analysis (wh
itelisted): 52.109.32.97, 52.1 13.194.132, 52.109.28.47, 23.2 18.208.109, 52.168.117.175, 52 .182.141.63, 20.190.147.5, 52. 149.20.212, 13.107.246.63 - Excluded domains from analysis
(whitelisted): slscr.update.m icrosoft.com, otelrules.afd.az ureedge.net, eur.roaming1.live .com.akadns.net, fs-wildcard.m icrosoft.com.edgekey.net, fs-w ildcard.microsoft.com.edgekey. net.globalredir.akadns.net, ec s-office.s-0005.s-msedge.net, roaming.officeapps.live.com, l ogin.live.com, e16604.g.akamai edge.net, officeclient.microso ft.com, ukw-azsc-config.office apps.live.com, prod.fs.microso ft.com.akadns.net, ecs.office. com, self-events-data.trafficm anager.net, fs.microsoft.com, otelrules.azureedge.net, prod. configsvc1.live.com.akadns.net , self.events.data.microsoft.c om, onedscolprdeus19.eastus.cl oudapp.azure.com, prod.roaming 1.live.com.akadns.net, s-0005- office.config.skype.com, osipr od-uks-buff-azsc-000.uksouth.c loudapp.azure.com, fe3cr.deliv ery.mp.microsoft.com, uks-azsc -000.roaming.officeapps.live.c om, s-0005.s-msedge.net, confi g.officeapps.live.com, azureed ge-t-prod.trafficmanager.net, ecs.office.trafficmanager.net, europe.configsvc1.live.com.ak adns.net, onedscolprdcus01.cen tral - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtCreateKey calls foun d. - Report size getting too big, t
oo many NtQueryAttributesFile calls found. - Report size getting too big, t
oo many NtQueryValueKey calls found. - Report size getting too big, t
oo many NtReadVirtualMemory ca lls found.
Time | Type | Description |
---|---|---|
02:36:26 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
s-part-0035.t-0009.t-msedge.net | Get hash | malicious | Vidar | Browse |
| |
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | Gozi, Ursnif | Browse |
| ||
Get hash | malicious | Dynamer | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 118 |
Entropy (8bit): | 3.5700810731231707 |
Encrypted: | false |
SSDEEP: | 3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq |
MD5: | 573220372DA4ED487441611079B623CD |
SHA1: | 8F9D967AC6EF34640F1F0845214FBC6994C0CB80 |
SHA-256: | BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D |
SHA-512: | F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 8213 |
Entropy (8bit): | 7.846014496130794 |
Encrypted: | false |
SSDEEP: | 192:XM6gSJbO9TUYG+Fb7CK7EXLbe8RTZRk+OHkT19blQEJoRABky/8E:XMJIyiYG6b7CKgXLbe8kkvaY3t |
MD5: | 0AADEBFCF977109C6FD91C324285BEE8 |
SHA1: | 4C80DD68330905F123361915E3B6F5D822664CB4 |
SHA-256: | 6227127DF97E76623C99875BE5D5188BA3068DADF050B87C4CBD383B508B0A9C |
SHA-512: | 9C0E5B0FC8AF6BDD9ED18A58393355592F52CF5BB480640162D2C9B80844A3FC1CDA43F57328171E7F068B11944AA47C87FCC6D33B6FDD34670DA49EEBAA548A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 165 |
Entropy (8bit): | 1.3520167401771568 |
Encrypted: | false |
SSDEEP: | 3:qs/FFyGff:qsyWf |
MD5: | 5C22367453CA7CD5BD7CA96C4FD55742 |
SHA1: | FC7428D064740B4E331D57098AF028AA26FBC1AE |
SHA-256: | F5D3D989BFAC7CF7187B3665F8CB75AF84FD749DBE245E454E2F9F1AC562E543 |
SHA-512: | BE2C202040245F25CB24C7F7B44A69F0000A95984236C3AE671443C56A7E1AE05BD7ACED71979ADF1159490770A767D25F581E76540C9C653441558BAECC0C89 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 165 |
Entropy (8bit): | 1.3520167401771568 |
Encrypted: | false |
SSDEEP: | 3:qs/FFyGff:qsyWf |
MD5: | 5C22367453CA7CD5BD7CA96C4FD55742 |
SHA1: | FC7428D064740B4E331D57098AF028AA26FBC1AE |
SHA-256: | F5D3D989BFAC7CF7187B3665F8CB75AF84FD749DBE245E454E2F9F1AC562E543 |
SHA-512: | BE2C202040245F25CB24C7F7B44A69F0000A95984236C3AE671443C56A7E1AE05BD7ACED71979ADF1159490770A767D25F581E76540C9C653441558BAECC0C89 |
Malicious: | true |
Reputation: | moderate, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 7.998140424471837 |
TrID: |
|
File name: | TAX INVOICE - NBO2506000632.xlam.xlsx |
File size: | 621'005 bytes |
MD5: | a866e44919d15b19cb0bf0686c422fb9 |
SHA1: | 0525eef57577d546c234f603b4da4486259b3fa7 |
SHA256: | a2e94cb25566b2f893c2c5be8f52ef5188f685d85d55e2f87ac4317d081a280d |
SHA512: | 76ddcd8e20717b652176ce6dda289ab56c8200d5cef690d643d143a4bd3cddbfbaa83c723e25ed92f8454deab63c5057444424b2316f9e53eaba220e14a58682 |
SSDEEP: | 12288:6tnWhfJyC0fzzTdXvJ7Xp8OkgCSEVAJGFIeNk63kIvtNpZ6DsWSgRrmGUT:yCJyrzdXvJ7XKSDEOGF1kIvtXZ6PqGE |
TLSH: | 8AD42391C856BC6AC28BD27EBB25DD4EB8353B54E14C4BDC09A2915C02E7FAB37C01D9 |
File Content Preview: | PK...........Y................[Content_Types].xmlUT...x.mgx.mgx.mg.UMo.0.....0t-b.=.....6;...mgZbl%.......e7.P4q.../...'...nkt..........@+.T..............,Vl....~.2{.y...m.X....y.-....h).t.@...p.b.........&.i.2...=..^t*.[..WR+...>/KU...J@.0.X.Nd..K%P:.b.R |
Icon Hash: | 35e58a8c0c8a85b9 |
Document Type: | OpenXML |
Number of OLE Files: | 1 |
Has Summary Info: | |
Application Name: | |
Encrypted Document: | False |
Contains Word Document Stream: | False |
Contains Workbook/Book Stream: | False |
Contains PowerPoint Document Stream: | False |
Contains Visio Document Stream: | False |
Contains ObjectPool Stream: | False |
Flash Objects Count: | 0 |
Contains VBA Macros: | False |
Author: | |
Last Saved By: | |
Create Time: | 2010-06-04T08:55:28Z |
Last Saved Time: | 2023-07-30T22:56:25Z |
Creating Application: | |
Security: | 0 |
Thumbnail Scaling Desired: | false |
Company: | |
Contains Dirty Links: | false |
Shared Document: | false |
Changed Hyperlinks: | false |
Application Version: | 15.0300 |
General | |
Stream Path: | \x1OlE10natiVe |
CLSID: | |
File Type: | data |
Stream Size: | 858114 |
Entropy: | 5.916107375363978 |
Base64 Encoded: | False |
Data ASCII: | H _ . . . . . < . F S ^ U . 2 = . x - x . V . . k p . } ( + D . # h Q P V w F ! . 9 I j . . . U . . . I K . $ . v . 0 } . 3 p = 7 # " . y A h o . . . . ? q * F ^ Z n _ . * = i ' . + 8 p . s . . H M N _ ! \\ . | p 5 . . . . . P ' . c . e ( | C / m N . d i , . . Z H W 5 . J . ` s % 8 . 8 l . b k . . & X T u . 6 . 2 d J * . . f w F / [ j A . . y P - ) f W . M q . W ; 6 x _ 8 . 3 3 . U . c / n r f . j I . % 5 + ` . . x Z . < # 5 . . . ' . v 7 Q m $ L ! . ? t . R A d \\ I # , . . k Z I & ' : . 8 q Z ? P . s r |
Data Raw: | 48 eb 5f 04 03 02 cb ca c0 d7 01 08 89 3c bd d7 0b 46 53 81 c5 5e b1 ff ac 8b 55 07 8b 32 b8 3d 10 fc 78 2d 8d a8 b5 78 8b 10 56 ff d2 05 1b 83 6b 70 05 b5 7d 94 8f ff e0 28 2b c2 44 00 cd 23 f5 68 ec 51 50 97 c1 56 cc 77 82 d0 f5 a0 46 21 0f b4 a4 99 39 b5 49 6a cf bf 1a ec ac a5 ca 55 cb 9f c5 85 a2 cd 7f b2 d0 49 91 ca 4b ab 98 05 83 24 c1 8d 1f 76 02 81 ef 30 7d e6 91 bf da 33 |
General | |
Stream Path: | TXmi6mxgz3V8UBX6e |
CLSID: | |
File Type: | empty |
Stream Size: | 0 |
Entropy: | 0.0 |
Base64 Encoded: | False |
Data ASCII: | |
Data Raw: |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 27, 2024 08:36:28.224550009 CET | 1.1.1.1 | 192.168.2.9 | 0xd51f | No error (0) | s-part-0035.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 27, 2024 08:36:28.224550009 CET | 1.1.1.1 | 192.168.2.9 | 0xd51f | No error (0) | 13.107.246.63 | A (IP address) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 02:35:18 |
Start date: | 27/12/2024 |
Path: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x4c0000 |
File size: | 53'161'064 bytes |
MD5 hash: | 4A871771235598812032C822E6F68F19 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 02:36:26 |
Start date: | 27/12/2024 |
Path: | C:\Windows\splwow64.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff64ec00000 |
File size: | 163'840 bytes |
MD5 hash: | 77DE7761B037061C7C112FD3C5B91E73 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |