Windows
Analysis Report
SecuriteInfo.com.Script.SNH-gen.9465.5598.xls
Overview
General Information
Detection
Score: | 76 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w7x64
EXCEL.EXE (PID: 2996 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\Offic e14\EXCEL. EXE" /auto mation -Em bedding MD5: D53B85E21886D2AF9815C377537BCAC3)
- cleanup
- • AV Detection
- • Compliance
- • Networking
- • System Summary
- • Data Obfuscation
- • Hooking and other Techniques for Hiding and Protection
- • HIPS / PFW / Operating System Protection Evasion
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | File opened: | Jump to behavior |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
System Summary |
---|
Source: | Stream path 'VBA/PaczkiZwykle' : |
Source: | Stream path 'VBA/PaczkiZwykle' : |
Source: | OLE indicator, VBA macros: |
Source: | OLE stream indicators for Word, Excel, PowerPoint, and Visio: |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | OLE indicator, VBA stomping: |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | 62 Scripting | Path Interception | Path Interception | 62 Scripting | OS Credential Dumping | 1 File and Directory Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Application Layer Protocol | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Obfuscated Files or Information | LSASS Memory | 1 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Junk Data | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | 1 Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Steganography | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
22% | Virustotal | Browse | ||
12% | ReversingLabs | Script-Macro.Trojan.Logan |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false |
| unknown |
Joe Sandbox Version: | 36.0.0 Rainbow Opal |
Analysis ID: | 753390 |
Start date and time: | 2022-11-24 18:14:34 +01:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 4m 23s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | SecuriteInfo.com.Script.SNH-gen.9465.5598.xls |
Cookbook file name: | defaultwindowsofficecookbook.jbs |
Analysis system description: | Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2) |
Run name: | Without Instrumentation |
Number of analysed new started processes analysed: | 2 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal76.expl.evad.winXLS@1/1@0/0 |
EGA Information: | Failed |
HDC Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Corrupt sample or wrongly sele
cted analyzer.
- Exclude process from analysis
(whitelisted): dllhost.exe
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 512 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:: |
MD5: | BF619EAC0CDF3F68D496EA9344137E8B |
SHA1: | 5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5 |
SHA-256: | 076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 |
SHA-512: | DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 5.059565165780792 |
TrID: |
|
File name: | SecuriteInfo.com.Script.SNH-gen.9465.5598.xls |
File size: | 584704 |
MD5: | f12ff8c249bb5fa66bf7456dbd24d2f4 |
SHA1: | a95cb2684dc78798816008833da88f9e09031690 |
SHA256: | d89593a50b26663b82f9720ffaa24ba6c91216266c582333e469f9c48f6e2199 |
SHA512: | a3f17f4d82c520eca83f4c3f4c243e89d7eabf456fb1a653e60ec4d97b1ed87ff9117ba81ed0ad3f277a72da8142c46733663675f887ee86846e3f5e62e093ec |
SSDEEP: | 6144:1aR1CEqhx4eKc5bOSXAmx3BYebs7797Q1DmlhnTj9:1Lxhb5fxQ7BymTX9 |
TLSH: | 1AC4E6C1B145C62BD6885A374C97D7F933B87D12AE856243F08D732E3E7E3889A19781 |
File Content Preview: | ........................>.......................................................k.......h...................................................................................................................................................................... |
Icon Hash: | e4eea286a4b4bcb4 |
Document Type: | OLE |
Number of OLE Files: | 1 |
Has Summary Info: | |
Application Name: | None |
Encrypted Document: | False |
Contains Word Document Stream: | False |
Contains Workbook/Book Stream: | False |
Contains PowerPoint Document Stream: | False |
Contains Visio Document Stream: | False |
Contains ObjectPool Stream: | False |
Flash Objects Count: | 0 |
Contains VBA Macros: | True |
General | |
Stream Path: | VBA/Arkusz1 |
VBA File Name: | Arkusz1.cls |
Stream Size: | 11153 |
Data ASCII: | . . . . . . . . . . . . . . X . . . . . . O . . . # . . . . . . . . . . T V . . c . . . . . . . . . . . . . . . . . . . . . C H ' ~ M . . . . . . . . . . . . . F . . . . . . . . . . . . . . . . . . . . " I Y z N . . & r . . . . . . . . . . . . . . . . . . . . . . x . . . . . ; . C o m m a n d B u t t o n N o _ A u t o F i l t r , 1 1 2 0 1 , 0 , M S F o r m s , C o m m a n d B u t t o n 9 . C o m m a n d B u t t o n C l o n e _ L i n e , 1 1 1 9 9 , 1 , M S F o r m s , C o m m a n d B u t |
Data Raw: | 01 16 03 00 06 d0 02 00 00 fa 16 00 00 b4 02 00 00 58 04 00 00 e1 17 00 00 4f 18 00 00 df 23 00 00 0a 00 00 00 01 00 00 00 54 a3 56 a3 00 00 ff ff 63 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff f0 00 ff ff 00 00 b6 97 97 98 b9 e3 1f 43 b6 c3 48 27 7e b0 8d 4d 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | VBA/CalendarForm |
VBA File Name: | CalendarForm.frm |
Stream Size: | 180599 |
Data ASCII: | . . . . . \\ . . . . . . @ . . . 0 . . . . . . . . . 9 . . . . . . . . . T . . . . . . . . . . . . . . . . . . . . X . . . D e . . C . E 1 B 8 . G F * $ o & f < . K G J . ! Y . . . . ` F . | > f L J 2 . . . . . . . . . . . . . . . . . . . . . . x . . . . ` F . | > f L J 2 D e . . C . E 1 B . . . . R . . . . . R . . . . . . . . . . . . . . . . . . . R . . . . . R . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . ` . 8 . @ . H . . ( . 0 . . . . . . S P . . . . S . . . . . S |
Data Raw: | 01 16 03 00 06 5c 01 00 00 ca 03 01 00 40 01 00 00 30 03 00 00 a9 04 01 00 df 09 01 00 ab 39 02 00 bd 00 00 00 01 00 00 00 54 a3 d6 da 00 00 ff ff 01 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff 58 04 ff ff 00 00 bf e0 44 65 13 07 c1 43 b5 07 45 f5 f2 31 42 be e1 c9 38 93 99 ae 02 47 9a 46 2a 24 6f 26 ed 66 dd 3c bc dc 95 4b 9b 47 8d 4a 0d b8 21 |
|
General | |
Stream Path: | VBA/Module1 |
VBA File Name: | Module1.bas |
Stream Size: | 5108 |
Data ASCII: | . . . . . . . . . . . . . . x . . . . . . . J . . . . . . . . . . . T . . . . . . . . . . . . . l . . . . . v . . . . . . . . . . . . . . . . . . . . . . . . . . S H G e t P a t h F r o m I D L i s t A . . . . . . v . X . . . . . . . . . . . . . . . . . . . . . . . . . . . S H B r o w s e F o r F o l d e r A . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . |
Data Raw: | 01 16 03 00 03 b8 01 00 00 aa 08 00 00 9c 01 00 00 78 02 00 00 ff ff ff ff 2e 09 00 00 4a 10 00 00 00 00 00 00 01 00 00 00 54 a3 c8 ee 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 6c 00 00 00 00 00 76 04 20 00 00 00 ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 53 48 47 65 74 50 61 74 68 46 72 6f 6d 49 44 4c 69 73 74 41 00 00 00 00 00 00 76 04 58 |
|
General | |
Stream Path: | VBA/Module9 |
VBA File Name: | Module9.bas |
Stream Size: | 7739 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . T . s . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . 6 . . . . . . < . . . . . . . < . . . . . . . < . . . . . . . . . . . . . . . . @ . . . . . . . . |
Data Raw: | 01 16 03 00 03 f0 00 00 00 da 05 00 00 d4 00 00 00 b0 01 00 00 ff ff ff ff 08 06 00 00 1c 18 00 00 00 00 00 00 01 00 00 00 54 a3 2e 73 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff 08 00 ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | VBA/PaczkiPlacowe |
VBA File Name: | PaczkiPlacowe.bas |
Stream Size: | 23833 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . C . . . . . . . . . . T > . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . . < p . . . . . . < x . . . . . 6 . . . . . . . . . . . . . . . . . . . . . . . . . x . |
Data Raw: | 01 16 03 00 06 f6 00 00 00 c0 0e 00 00 da 00 00 00 b6 01 00 00 ff ff ff ff 03 0f 00 00 9b 43 00 00 08 00 00 00 01 00 00 00 54 a3 86 3e 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff 08 00 ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | VBA/PaczkiZwykle |
VBA File Name: | PaczkiZwykle.bas |
Stream Size: | 144947 |
Data ASCII: | . . . . . . . . > . . . . . . . . . A . . . . . . . . . . . . T . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . . . . @ . . . . . ( p . . . . . . x . . . . . > . . . . . . . . . . . L . . . . . L . . . . . P . . . . . L . . . |
Data Raw: | 01 16 03 00 06 f0 00 00 00 f2 3e 00 00 d4 00 00 00 c8 02 00 00 ff ff ff ff 12 41 00 00 f6 a9 01 00 13 00 00 00 01 00 00 00 54 a3 f9 0c 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff 08 00 ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | VBA/ThisWorkbook |
VBA File Name: | ThisWorkbook.cls |
Stream Size: | 4387 |
Data ASCII: | . . . . . . . . . . . . . . . 8 . . . . . . . - . . . . . . . . . . . . . . . T _ . . # . . . . . . . . . . . . . . . . . p . . . S < 8 ` > w I I . ! [ { u . . . . . . . . . . . . . . F . . . . . . . . . . . . . . . . . . . . m w . 3 M N Q s . h _ . . . . . . . . . . . . . . . . . . . . . . x . . . . m w . 3 M N Q s . h _ S < 8 ` > w I I . ! [ { u . . . . M E . . . . . . . . . . . . . . . . . . . . . 8 . P . . . . . S L . . . . S . . . . . S . . . . 6 " . . . . . . . . . . L . . . . . . . . . . . < . . . . |
Data Raw: | 01 16 03 00 06 00 01 00 00 b2 07 00 00 e4 00 00 00 38 02 00 00 1f 08 00 00 2d 08 00 00 09 0e 00 00 03 00 00 00 01 00 00 00 54 a3 5f a3 00 00 ff ff 23 00 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff 70 00 ff ff 00 00 53 3c b1 38 60 3e 77 49 9c 49 0a 21 5b b9 7b 75 19 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | CalendarForm/\x1CompObj |
File Type: | data |
Stream Size: | 97 |
Entropy: | 3.6106491830605214 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t F o r m s 2 . 0 F o r m . . . . . E m b e d d e d O b j e c t . . . . . 9 q . . . . . . . . . . . . |
Data Raw: | 01 00 fe ff 03 0a 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 19 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 46 6f 72 6d 73 20 32 2e 30 20 46 6f 72 6d 00 10 00 00 00 45 6d 62 65 64 64 65 64 20 4f 62 6a 65 63 74 00 00 00 00 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | CalendarForm/\x3VBFrame |
File Type: | ISO-8859 text, with CRLF line terminators |
Stream Size: | 302 |
Entropy: | 4.683356371143677 |
Base64 Encoded: | True |
Data ASCII: | V E R S I O N 5 . 0 0 . . B e g i n { C 6 2 A 6 9 F 0 - 1 6 D C - 1 1 C E - 9 E 9 8 - 0 0 A A 0 0 5 7 4 A 4 F } C a l e n d a r F o r m . . C a p t i o n = " W y b i e r z d a t . . . " . . C l i e n t H e i g h t = 4 3 2 0 . . C l i e n t L e f t = 4 5 . . C l i e n t T o p = 3 7 5 . . C l i e n t W i d t h = 3 2 7 0 . . S t a r t U p P o s i t i o n = 1 ' C |
Data Raw: | 56 45 52 53 49 4f 4e 20 35 2e 30 30 0d 0a 42 65 67 69 6e 20 7b 43 36 32 41 36 39 46 30 2d 31 36 44 43 2d 31 31 43 45 2d 39 45 39 38 2d 30 30 41 41 30 30 35 37 34 41 34 46 7d 20 43 61 6c 65 6e 64 61 72 46 6f 72 6d 20 0d 0a 20 20 20 43 61 70 74 69 6f 6e 20 20 20 20 20 20 20 20 20 3d 20 20 20 22 57 79 62 69 65 72 7a 20 64 61 74 ea 2e 2e 2e 22 0d 0a 20 20 20 43 6c 69 65 6e 74 48 65 69 |
General | |
Stream Path: | CalendarForm/f |
File Type: | TTComp archive data, binary, 1K dictionary |
Stream Size: | 5135 |
Entropy: | 3.9674859753005904 |
Base64 Encoded: | False |
Data ASCII: | . . , . J . . . . . . . . @ . . . . . . . . } . . . . . . . . . . . . . . . . . R . . . . K Q . . . . D B . . . T a h o m a . . n . . . . . . . . . . . ( . . . . . . . . . . . 2 . . . 0 . . . . . . . b g D a t e 1 1 . . . } . . . . . , . . . . . . . . . . . 2 . . . @ . . . . . . . l b l D a t e 1 1 . i . . . . . . . . . ( . . . . . . . . . . . 2 . . . 0 . . . . . . . b g D a t e 1 2 O . . . } . . . . . ( . . . . . . . . . . . 2 . . . 0 . . . . . . . b g D a t e 1 3 . . . } . . . . . ( . . . . . . . . . . . |
Data Raw: | 00 04 2c 00 4a 0c 10 0c ff ff ff 00 ba 00 00 00 04 40 00 00 ff ff 00 00 8d 01 00 00 00 7d 00 00 88 16 00 00 c4 1d 00 00 00 00 00 00 00 00 00 00 03 52 e3 0b 91 8f ce 11 9d e3 00 aa 00 4b b8 51 01 ee 00 00 90 01 44 42 01 00 06 54 61 68 6f 6d 61 00 00 6e 00 00 00 a4 13 00 00 00 ee 01 0c 00 00 28 00 f5 01 00 00 08 00 00 80 01 00 00 00 32 00 00 00 30 00 00 00 0d 00 15 00 62 67 44 61 74 |
General | |
Stream Path: | CalendarForm/o |
File Type: | Intel ia64 COFF object file, not stripped, 16 sections, symbol offset=0xffffff, 635 symbols, optional header size 635, created Thu Jan 1 00:00:34 1970 |
Stream Size: | 6164 |
Entropy: | 3.522871835497573 |
Base64 Encoded: | True |
Data ASCII: | . . . . " . . . . { . . . { . . . . . . . 5 . . . . . . . . . . . . . T a h o m a . . . . . / . . . . . . . . . . . . . . 9 9 1 . { . . . r . . . . . . . u . . . . . . . . . . . . . C a l i b r i . . . . . " . . . . { . . . { . . . . . . . 5 . . . . . . . . . . . . . T a h o m a i . . . . . " . . . . { . . . { . . . . . . . 5 . . . . . . . . . . . . . T a h o m a . . . . . " . . . . { . . . { . . . . . . . 5 . . . . . . . . . . . . . T a h o m a > . . . . . " . . . . { . . . { . . . . . . . 5 . . . . . . |
Data Raw: | 00 02 10 00 22 00 00 00 ff ff ff 00 7b 02 00 00 7b 02 00 00 00 02 18 00 35 00 00 00 06 00 00 80 a5 00 00 00 00 02 00 00 54 61 68 6f 6d 61 00 00 00 02 20 00 2f 00 00 00 00 00 00 00 ff ff ff 00 13 00 80 00 02 00 00 80 39 39 31 00 7b 02 00 00 72 01 00 00 00 02 18 00 75 00 00 00 07 00 00 80 b4 00 00 00 00 02 03 00 43 61 6c 69 62 72 69 00 00 02 10 00 22 00 00 00 ff ff ff 00 7b 02 00 00 |
General | |
Stream Path: | PROJECT |
File Type: | ASCII text, with CRLF line terminators |
Stream Size: | 856 |
Entropy: | 5.199637986783791 |
Base64 Encoded: | True |
Data ASCII: | I D = " { 0 0 0 0 0 0 0 0 - 0 0 0 0 - 0 0 0 0 - 0 0 0 0 - 0 0 0 0 0 0 0 0 0 0 0 0 } " . . D o c u m e n t = A r k u s z 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . P a c k a g e = { A C 9 F 2 F 9 0 - E 8 7 7 - 1 1 C E - 9 F 6 8 - 0 0 A A 0 0 5 7 4 A 4 F } . . M o d u l e = P a c z k i Z w y k l e . . M o d u l e = M o d u l e 9 . . M o d u l e = M o d u l e 1 . . M o d u l e = P a c z k i P l a c o w e . . B a s e C l a s s = C a l e n d a r F o r m . . H |
Data Raw: | 49 44 3d 22 7b 30 30 30 30 30 30 30 30 2d 30 30 30 30 2d 30 30 30 30 2d 30 30 30 30 2d 30 30 30 30 30 30 30 30 30 30 30 30 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 41 72 6b 75 73 7a 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 50 61 63 6b 61 67 65 3d 7b 41 43 39 46 32 46 39 30 2d 45 38 |
General | |
Stream Path: | PROJECTwm |
File Type: | data |
Stream Size: | 233 |
Entropy: | 3.670277212366342 |
Base64 Encoded: | False |
Data ASCII: | A r k u s z 1 . A . r . k . u . s . z . 1 . . . T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . P a c z k i Z w y k l e . P . a . c . z . k . i . Z . w . y . k . l . e . . . M o d u l e 9 . M . o . d . u . l . e . 9 . . . M o d u l e 1 . M . o . d . u . l . e . 1 . . . P a c z k i P l a c o w e . P . a . c . z . k . i . P . l . a . c . o . w . e . . . C a l e n d a r F o r m . C . a . l . e . n . d . a . r . F . o . r . m . . . . . |
Data Raw: | 41 72 6b 75 73 7a 31 00 41 00 72 00 6b 00 75 00 73 00 7a 00 31 00 00 00 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 50 61 63 7a 6b 69 5a 77 79 6b 6c 65 00 50 00 61 00 63 00 7a 00 6b 00 69 00 5a 00 77 00 79 00 6b 00 6c 00 65 00 00 00 4d 6f 64 75 6c 65 39 00 4d 00 6f 00 64 00 75 00 6c 00 65 00 39 00 00 00 4d 6f |
General | |
Stream Path: | VBA/_VBA_PROJECT |
File Type: | data |
Stream Size: | 18545 |
Entropy: | 5.910307618606032 |
Base64 Encoded: | False |
Data ASCII: | a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 1 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 1 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 7 . \\ . V . B . E . 7 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o . r . |
Data Raw: | cc 61 9a 00 00 03 00 ff 15 04 00 00 09 04 00 00 e2 04 03 00 00 00 00 00 00 00 00 00 01 00 06 00 02 00 fa 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 31 00 23 00 |
General | |
Stream Path: | VBA/__SRP_0 |
File Type: | data |
Stream Size: | 28431 |
Entropy: | 3.8232462422059292 |
Base64 Encoded: | False |
Data ASCII: | K * . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . r U ( . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . |
Data Raw: | 93 4b 2a 9a 03 00 10 00 00 00 ff ff 00 00 00 00 01 00 02 00 ff ff 00 00 00 00 01 00 00 00 01 00 00 00 00 00 01 00 02 00 01 00 00 00 00 00 01 00 00 00 04 00 00 00 00 00 01 00 02 00 04 00 00 00 00 00 01 00 00 00 05 00 00 00 00 00 01 00 02 00 05 00 00 00 00 00 01 00 00 00 03 00 00 00 00 00 01 00 02 00 03 00 00 00 00 00 01 00 02 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 01 00 |
General | |
Stream Path: | VBA/__SRP_1 |
File Type: | data |
Stream Size: | 2960 |
Entropy: | 3.421559447674446 |
Base64 Encoded: | True |
Data ASCII: | r U @ . . . . . . . @ . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ . . . . . . . ~ R . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 01 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 02 00 00 00 00 00 00 7e 02 00 00 00 00 00 00 7e 02 00 00 00 00 00 00 7e 02 00 00 00 00 00 00 7e 02 00 00 00 00 00 00 7e 02 00 00 00 00 00 00 7e 02 00 00 00 00 00 00 7e 02 00 00 00 00 00 00 7e 02 00 00 00 00 00 00 7e 02 00 00 00 00 00 00 7e 02 00 00 00 00 00 00 7e 52 00 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_2 |
File Type: | data |
Stream Size: | 1616 |
Entropy: | 2.3727324284045177 |
Base64 Encoded: | False |
Data ASCII: | r U . . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . P . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A . . . . . . . . . . . q . . . . . . . . . . . . . . . . . . . . . . . . + . ` . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ` . . . . . . . ` . . . |
Data Raw: | 72 55 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 03 00 50 00 00 00 00 00 00 00 00 00 00 00 05 00 05 00 04 00 00 00 d1 0e 00 00 00 00 00 00 00 00 00 00 41 10 00 00 00 00 00 00 00 00 00 00 81 0e 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_3 |
File Type: | data |
Stream Size: | 406 |
Entropy: | 2.3069470264937544 |
Base64 Encoded: | False |
Data ASCII: | r U . . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . 8 . . . . . . . . . . . . . . . ` . . ) . 8 . . . . . . . . . . . P . ! . . . . . . . . . . . . . . ` . . @ . @ . . . . . . . . . . . . . . . . ! . . . . . . . . . . . . . . . . . . . C . 8 . A . . . . . . . . . . . . . . ` . . 1 . . . . . . . . . . . @ . . . . . . . . . . . . . . . . ` . . H . H . . . . . ! . . . . . . . . . . . . . . . . . C . 8 . Q . . . . . . . |
Data Raw: | 72 55 00 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 02 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 78 00 00 00 08 00 38 00 e1 01 00 00 00 00 00 00 00 00 02 00 00 00 03 60 00 00 29 08 38 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_4 |
File Type: | data |
Stream Size: | 186 |
Entropy: | 1.8823179470172933 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . @ . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . a . . . . . . . . . . . . . . . . . . . . Z . . . 2 . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 04 00 00 00 00 00 00 7e 78 00 00 00 00 00 00 7f 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 05 00 10 00 00 00 00 00 00 00 00 00 04 00 02 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff |
General | |
Stream Path: | VBA/__SRP_5 |
File Type: | data |
Stream Size: | 362 |
Entropy: | 2.0232778204868094 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . P . A . . . . . . . . . . . . . . p . . . . . . Q . . . . . . . . . . . q . . . . . . . . . . . . . . . . . . . . . H . . . . . . . . . . . . . 8 . . p . . . . . . . . . . . . . . . . . . . . . . . U . @ . . . . . . . . . . . . . . . ` . . . . . . . . . . . . . . . . . . . . . . . . . . . P . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 04 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 10 00 00 00 08 00 50 00 41 19 00 00 00 00 00 00 00 00 00 00 00 00 00 70 08 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_6 |
File Type: | data |
Stream Size: | 1591 |
Entropy: | 2.2212140095451516 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . @ . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . q . . . . . . . . . . q . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . H . . . . . . . . . . . . . . . i . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 01 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 04 00 00 00 00 00 00 7e 78 00 00 00 00 00 00 7f 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 07 00 10 00 00 00 00 00 00 00 00 00 06 00 09 00 09 00 07 00 00 00 71 ac 00 00 00 00 00 00 00 00 00 00 71 17 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_7 |
File Type: | data |
Stream Size: | 712 |
Entropy: | 2.2519115019353473 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . @ . . . . . . . . . . . . . . . ` . . . . . . . . . . . . . . . . . . . . . . . . . @ . q . . . . . . . . . . . . . . ` . . . . . . . . . . . . . . . . . . . . . . . . . P . . . . . . . . . . . . . . . . ` . . . . . . . . . . . . . . . . . . A . . . . . . . . . . . . . . . . . P . H . @ . . . . . . . . . . . . . . . ` . . . . . . a . . . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 06 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 10 00 00 00 08 00 40 00 f1 00 00 00 00 00 00 00 00 00 06 00 00 00 00 60 04 00 fd ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_8 |
File Type: | data |
Stream Size: | 47369 |
Entropy: | 4.669136243548821 |
Base64 Encoded: | False |
Data ASCII: | r U . . . . . . . @ . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Q . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A . . . . . . . . . . . . . . . . . . . . Q . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Q . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . q |
Data Raw: | 72 55 80 02 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 04 00 00 00 00 00 00 7e 78 00 00 00 00 00 00 7f 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 09 00 10 00 00 00 00 00 00 00 00 00 08 00 16 00 16 00 fa 00 00 00 81 90 00 00 00 00 00 00 00 00 00 00 c1 91 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_9 |
File Type: | data |
Stream Size: | 1596 |
Entropy: | 2.3534686628384525 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . ` . . . . . . . . . . . . 8 . q . . . . . . . . . . . . . . ` . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . . ` . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . ` . . . . . . . . . . . . P . . . . . . . . . . . . . . . ` . . . . . . A . . . . . . . . . . . a . . . . . . . . . . . . . . . . . P . P . 8 . 1 . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 08 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 10 00 00 00 08 00 38 00 f1 00 00 00 00 00 00 00 00 00 08 00 00 00 00 60 00 00 fd ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_a |
File Type: | data |
Stream Size: | 1162 |
Entropy: | 2.6566971348723456 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 . 1 . . . . . . . . . . . . . . ` . . . 8 . . . . . . . . . . . X . . . . . . . . . . . . . . . . ` . . . 8 . . . . . ! . . . . . . . . . . . ! . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . C . 8 . q . . . . . . . . . . . . . . ` . . . 8 . . . . . . . . . . . 8 . 1 . . . . . . . . . . . . . . ` . . . 8 . . . . . . . . . . . 8 . ! . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 0b 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 f8 00 00 00 08 00 38 00 31 0d 00 00 00 00 00 00 00 00 0b 00 00 00 03 60 00 00 80 05 38 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_b |
File Type: | data |
Stream Size: | 6228 |
Entropy: | 3.1596566289809243 |
Base64 Encoded: | False |
Data ASCII: | r U . . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . . . . . . . . . . . . . . . . . . . . . y . . . . . . . . . . - . . . . . . . . . . 1 % . . . . . . . . . . ) . . . . . . . . . . A . . . . . . . . . . . . . . . . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . 1 . . . . . . . . . . . . . . . . . . . ! . . . . . . . . . . . . . . . . |
Data Raw: | 72 55 00 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 0a 00 f0 0a 00 00 00 00 00 00 00 00 00 00 0c 00 0c 00 0c 00 00 00 f1 1d 01 00 00 00 00 00 00 00 00 00 f1 21 01 00 00 00 00 00 00 00 00 00 d1 1f 01 00 00 00 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_c |
File Type: | data |
Stream Size: | 49041 |
Entropy: | 2.6494568920205404 |
Base64 Encoded: | False |
Data ASCII: | r U ( . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . o . Q 9 . . . . . . . . . . 9 . . . . . . . . . . 9 . . . . . . . . . . 9 . . . . . . . . . . ! 9 . . . . . . . . . . . . . . . . . . : . . . . . . . . . . A . . . . . . . . . . . A : . . . . . . . . . . e . . . e . . . e . . . . . U . . ` . . ` . . . . . . . . . . ! 9 . . . . . . . . . . . . . . . . . . : . . . . . |
Data Raw: | 72 55 8b 28 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 38 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 0d 00 20 03 00 00 00 00 00 00 00 00 00 00 bd 00 bd 00 00 00 00 00 02 00 01 00 00 00 6f 00 51 39 00 00 00 00 00 00 00 00 00 00 81 39 00 00 00 00 00 00 00 00 00 00 b1 39 |
General | |
Stream Path: | VBA/__SRP_d |
File Type: | data |
Stream Size: | 15262 |
Entropy: | 2.779876081764107 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ` . . . . . X . . . . . . . . . . . . . . . ` t . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A . . . . . . . . . . . q . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A . . . . . . . . . . . q . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 0c 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 60 04 00 00 08 00 58 01 e1 01 00 00 00 00 00 00 00 00 0c 00 00 00 03 60 74 01 91 06 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 |
General | |
Stream Path: | VBA/__SRP_e |
File Type: | data |
Stream Size: | 314 |
Entropy: | 2.0336709495517145 |
Base64 Encoded: | False |
Data ASCII: | r U . . . . . . . . @ . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . ~ x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . a . . . . . . . . . . . . . . . . . . . . . S . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S . . " |
Data Raw: | 72 55 00 03 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 04 00 00 00 00 00 00 7e 78 00 00 00 00 00 00 7f 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 0f 00 10 00 00 00 00 00 00 00 00 00 0e 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff |
General | |
Stream Path: | VBA/__SRP_f |
File Type: | data |
Stream Size: | 328 |
Entropy: | 1.9053797189114703 |
Base64 Encoded: | False |
Data ASCII: | r U @ . . . . . . . . . . . . . . . @ . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . ` . . . . . . . . . . . . . 1 . . . . . . . . . . . . . . . . . . . . . 8 . a . . . . . . . . . . . . . . ` . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . . ` . . . . . . . . . . . . 8 . . . . . . . . . . . . . . . ` . . . . . . . . . . . . . 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . b . . . . . . . |
Data Raw: | 72 55 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 00 00 00 00 00 00 00 11 00 00 00 00 00 00 00 00 00 0e 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 10 00 00 00 08 00 38 00 f1 00 00 00 00 00 00 00 00 00 0e 00 00 00 00 60 00 00 fd ff ff ff e1 11 00 00 00 00 00 00 00 00 01 00 31 12 00 00 00 00 00 00 |
General | |
Stream Path: | VBA/dir |
File Type: | data |
Stream Size: | 1155 |
Entropy: | 6.637241864567654 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . V B A P r o j e c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . y [ . . . . J < . . . . . r s t d o l e > . . . s . t . d . o . l . e . . . h . % . ^ . . * \\ G { 0 0 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s t e m 3 2 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . E O f f D i c E O . f . i . c E . . E . 2 D F 8 D 0 4 C . - 5 B F A - 1 0 1 B - B D E 5 E A A C 4 . 2 E |
Data Raw: | 01 7f b4 80 01 00 04 00 00 00 03 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e2 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 b4 79 96 5b 0b 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47 |
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 18:15:16 |
Start date: | 24/11/2022 |
Path: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x13ffc0000 |
File size: | 28253536 bytes |
MD5 hash: | D53B85E21886D2AF9815C377537BCAC3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |