Malicious
Classifications
-
Threat Names
C2/Generic-A Mal/Generic-S
Dynamic Analysis Report
Created on 2024-11-21T06:58:11+00:00
MYOeBmolNrZ3oREj.xls
Excel Document
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "40 minutes" to "20 seconds" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
473bf2123f2891c1a5ebc75949cdf50260d4da3715cd7a3160d09155da8b354b | Sample File | Excel Document |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
Names | Mal/Generic-S |
Office Information
»
Creator | xXx |
Last Modified By | xXx |
Create Time | 2022-01-17 21:27 (UTC) |
Modify Time | 2022-01-17 21:59 (UTC) |
Codepage | ANSI_Cyrillic |
Application | Microsoft Excel |
App Version | 16.0 |
Document Security | NONE |
Excel 4.0 Macros | 1 |
Worksheets | 1 |
Titles Of Parts | Sheet1, KEY |
scale_crop | False |
shared_doc | False |
Controls (1)
»
CLSID | Control Name | Associated Vulnerability |
---|---|---|
{00020820-0000-0000-C000-000000000046} | Excel97Sheet | - |
Excel 4.0 Macros (1)
»
Macro #1: KEY
»
Visibility State | HIDDEN |
Triggers | document:AUTO_OPEN |
Labels | AUTO_OPEN, lll |
|
Extracted Image Texts (1)
»
Image #1:
0.JPG
»
THIS DOCUMENT IS ONLY AVAILABLE FOR DESKTOP OR LAPTOP VERSIONS OF MICROSOFT OFFICE EXCEL. Open the document in Microsoft Office. Previewing online is not available for protected documents. CLICK “ENABLE EDITING” FROM YELLOW BAR ABOVE Once you have enabled editing, please click “Enable Content” button
|
CFB Streams (3)
»
Name | ID | Size | Actions |
---|---|---|---|
Root\Workbook | 1 | 117.27 KB |
...
|
Root\SummaryInformation | 2 | 4.00 KB |
...
|
Root\DocumentSummaryInformation | 3 | 4.00 KB |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Document_Office_VeryHiddenMacro | Document contains very hidden Excel 4.0 macro | - |
2/5
|
...
|
c:\users\keecfmwgj\appdata\roaming\microsoft\excel\b083a100 | Dropped File | Stream |
Clean
|
...
|
»