Malicious
Classifications
-
Threat Names
-
Dynamic Analysis Report
Created on 2024-06-03T09:26:25+00:00
msk.xls
Excel Document
Remarks (2/2)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "23 minutes, 6 seconds" to "1 minute, 10 seconds" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\kEecfMwgj\Desktop\msk.xls | Sample File | Office File |
Malicious
|
...
|
»
Office Information
»
Creator | Usuario Agrest |
Last Modified By | george |
Create Time | 2018-11-27 15:26 (UTC) |
Modify Time | 2024-05-16 15:13 (UTC) |
Application | Microsoft Excel |
App Version | 16.0300 |
Document Security | NONE |
Worksheets | 10 |
Titles Of Parts | Hoja2, Hoja1, Listado, 2019, 2020, 2021, 2022, 2023, 2024, por persona |
ScaleCrop | False |
SharedDoc | False |
VBA Macros (8)
»
Macro #1: Module7
»
Macro #2: Módulo1
»
Macro #3: Módulo2
»
Macro #4: Módulo3
»
Macro #5: Módulo4
»
Macro #6: Módulo5
»
Macro #7: Módulo6
»
Macro #8: UserForm1
»
Extracted Image Texts (1)
»
Image #1:
image1.jpeg
»
AGREST
|
Extracted URLs (1)
»
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
https://picstate.com/file/20260941_ugxbx/B7CHZ11.png |
Not Queried
|
- |
...
|
C:\Users\kEecfMwgj\AppData\Local\{D77D06B2-C71E-C031-9266-658FBD2652B7}\B79266.DLL | Dropped File | Binary |
Suspicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x00428ED0 |
Size Of Code | 0x0002C000 |
Size Of Initialized Data | 0x00009000 |
File Type | IMAGE_FILE_DLL |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_AMD64 |
Compile Timestamp | 2024-01-04 03:42 (UTC) |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Application Compatibility Client Library |
FileVersion | 6.0.6300.13146 (vista_rtm.-2022) |
InternalName | VBhelp |
LegalCopyright | Microsoft Corporation. All rights reserved. |
OriginalFilename | VBB5 |
ProductName | Microsoft Windows Operating System |
ProductVersion | 08.09.2023.1495 |
Sections (10)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002BE50 | 0x0002C000 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.78 |
.data | 0x0042D000 | 0x00003D18 | 0x00003E00 | 0x0002C400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.18 |
.bss | 0x00431000 | 0x00007D20 | 0x00000000 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x00439000 | 0x00001200 | 0x00001200 | 0x00030200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.21 |
.didata | 0x0043B000 | 0x000000C8 | 0x00000200 | 0x00031400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.88 |
.edata | 0x0043C000 | 0x000000E2 | 0x00000200 | 0x00031600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.72 |
.rdata | 0x0043D000 | 0x00000045 | 0x00000200 | 0x00031800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.19 |
.reloc | 0x0043E000 | 0x00001420 | 0x00001600 | 0x00031A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.59 |
.pdata | 0x00440000 | 0x00001D40 | 0x00001E00 | 0x00033000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.21 |
.rsrc | 0x00442000 | 0x00000454 | 0x00000600 | 0x00034E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.06 |
Imports (6)
»
mpr.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetEnumResourceW | - | 0x004394D0 | 0x00039090 | 0x00030290 | 0x00000000 |
WNetOpenEnumW | - | 0x004394D8 | 0x00039098 | 0x00030298 | 0x00000000 |
kernel32.dll (81)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetFileTime | - | 0x004394E8 | 0x000390A8 | 0x000302A8 | 0x00000000 |
GetFileType | - | 0x004394F0 | 0x000390B0 | 0x000302B0 | 0x00000000 |
RtlUnwindEx | - | 0x004394F8 | 0x000390B8 | 0x000302B8 | 0x00000000 |
GetACP | - | 0x00439500 | 0x000390C0 | 0x000302C0 | 0x00000000 |
SetFilePointer | - | 0x00439508 | 0x000390C8 | 0x000302C8 | 0x00000000 |
CloseHandle | - | 0x00439510 | 0x000390D0 | 0x000302D0 | 0x00000000 |
LocalFree | - | 0x00439518 | 0x000390D8 | 0x000302D8 | 0x00000000 |
TlsAlloc | - | 0x00439520 | 0x000390E0 | 0x000302E0 | 0x00000000 |
GetTickCount | - | 0x00439528 | 0x000390E8 | 0x000302E8 | 0x00000000 |
TerminateThread | - | 0x00439530 | 0x000390F0 | 0x000302F0 | 0x00000000 |
FindNextFileW | - | 0x00439538 | 0x000390F8 | 0x000302F8 | 0x00000000 |
VirtualFree | - | 0x00439540 | 0x00039100 | 0x00030300 | 0x00000000 |
GetFileSize | - | 0x00439548 | 0x00039108 | 0x00030308 | 0x00000000 |
GetStartupInfoW | - | 0x00439550 | 0x00039110 | 0x00030310 | 0x00000000 |
ExitProcess | - | 0x00439558 | 0x00039118 | 0x00030318 | 0x00000000 |
InitializeCriticalSection | - | 0x00439560 | 0x00039120 | 0x00030320 | 0x00000000 |
GetCurrentProcess | - | 0x00439568 | 0x00039128 | 0x00030328 | 0x00000000 |
GlobalLock | - | 0x00439570 | 0x00039130 | 0x00030330 | 0x00000000 |
VirtualAlloc | - | 0x00439578 | 0x00039138 | 0x00030338 | 0x00000000 |
RtlUnwind | - | 0x00439580 | 0x00039140 | 0x00030340 | 0x00000000 |
GetTempPathW | - | 0x00439588 | 0x00039148 | 0x00030348 | 0x00000000 |
GetCommandLineW | - | 0x00439590 | 0x00039150 | 0x00030350 | 0x00000000 |
GetSystemInfo | - | 0x00439598 | 0x00039158 | 0x00030358 | 0x00000000 |
GetProcAddress | - | 0x004395A0 | 0x00039160 | 0x00030360 | 0x00000000 |
GetStdHandle | - | 0x004395A8 | 0x00039168 | 0x00030368 | 0x00000000 |
FileTimeToLocalFileTime | - | 0x004395B0 | 0x00039170 | 0x00030370 | 0x00000000 |
WinExec | - | 0x004395B8 | 0x00039178 | 0x00030378 | 0x00000000 |
GetVersionExW | - | 0x004395C0 | 0x00039180 | 0x00030380 | 0x00000000 |
GetModuleHandleA | - | 0x004395C8 | 0x00039188 | 0x00030388 | 0x00000000 |
GetModuleHandleW | - | 0x004395D0 | 0x00039190 | 0x00030390 | 0x00000000 |
FreeLibrary | - | 0x004395D8 | 0x00039198 | 0x00030398 | 0x00000000 |
FileTimeToDosDateTime | - | 0x004395E0 | 0x000391A0 | 0x000303A0 | 0x00000000 |
ReadFile | - | 0x004395E8 | 0x000391A8 | 0x000303A8 | 0x00000000 |
DosDateTimeToFileTime | - | 0x004395F0 | 0x000391B0 | 0x000303B0 | 0x00000000 |
FindFirstFileW | - | 0x004395F8 | 0x000391B8 | 0x000303B8 | 0x00000000 |
TlsFree | - | 0x00439600 | 0x000391C0 | 0x000303C0 | 0x00000000 |
GetConsoleOutputCP | - | 0x00439608 | 0x000391C8 | 0x000303C8 | 0x00000000 |
GetConsoleCP | - | 0x00439610 | 0x000391D0 | 0x000303D0 | 0x00000000 |
GetLastError | - | 0x00439618 | 0x000391D8 | 0x000303D8 | 0x00000000 |
GetModuleFileNameW | - | 0x00439620 | 0x000391E0 | 0x000303E0 | 0x00000000 |
GlobalAlloc | - | 0x00439628 | 0x000391E8 | 0x000303E8 | 0x00000000 |
GlobalUnlock | - | 0x00439630 | 0x000391F0 | 0x000303F0 | 0x00000000 |
DisableThreadLibraryCalls | - | 0x00439638 | 0x000391F8 | 0x000303F8 | 0x00000000 |
CreateThread | - | 0x00439640 | 0x00039200 | 0x00030400 | 0x00000000 |
QueryPerformanceCounter | - | 0x00439648 | 0x00039208 | 0x00030408 | 0x00000000 |
SetEndOfFile | - | 0x00439650 | 0x00039210 | 0x00030410 | 0x00000000 |
CopyFileW | - | 0x00439658 | 0x00039218 | 0x00030418 | 0x00000000 |
WideCharToMultiByte | - | 0x00439660 | 0x00039220 | 0x00030420 | 0x00000000 |
FindClose | - | 0x00439668 | 0x00039228 | 0x00030428 | 0x00000000 |
MultiByteToWideChar | - | 0x00439670 | 0x00039230 | 0x00030430 | 0x00000000 |
LoadLibraryW | - | 0x00439678 | 0x00039238 | 0x00030438 | 0x00000000 |
LoadLibraryA | - | 0x00439680 | 0x00039240 | 0x00030440 | 0x00000000 |
GetVolumeInformationW | - | 0x00439688 | 0x00039248 | 0x00030448 | 0x00000000 |
CreateFileW | - | 0x00439690 | 0x00039250 | 0x00030450 | 0x00000000 |
GetDriveTypeW | - | 0x00439698 | 0x00039258 | 0x00030458 | 0x00000000 |
GetVersion | - | 0x004396A0 | 0x00039260 | 0x00030460 | 0x00000000 |
DeleteFileW | - | 0x004396A8 | 0x00039268 | 0x00030468 | 0x00000000 |
MoveFileW | - | 0x004396B0 | 0x00039270 | 0x00030470 | 0x00000000 |
RaiseException | - | 0x004396B8 | 0x00039278 | 0x00030478 | 0x00000000 |
IsDBCSLeadByteEx | - | 0x004396C0 | 0x00039280 | 0x00030480 | 0x00000000 |
OpenProcess | - | 0x004396C8 | 0x00039288 | 0x00030488 | 0x00000000 |
SwitchToThread | - | 0x004396D0 | 0x00039290 | 0x00030490 | 0x00000000 |
GetExitCodeThread | - | 0x004396D8 | 0x00039298 | 0x00030498 | 0x00000000 |
WaitForSingleObject | - | 0x004396E0 | 0x000392A0 | 0x000304A0 | 0x00000000 |
GetSystemPowerStatus | - | 0x004396E8 | 0x000392A8 | 0x000304A8 | 0x00000000 |
WriteFile | - | 0x004396F0 | 0x000392B0 | 0x000304B0 | 0x00000000 |
LocalFileTimeToFileTime | - | 0x004396F8 | 0x000392B8 | 0x000304B8 | 0x00000000 |
DeleteCriticalSection | - | 0x00439700 | 0x000392C0 | 0x000304C0 | 0x00000000 |
TlsGetValue | - | 0x00439708 | 0x000392C8 | 0x000304C8 | 0x00000000 |
SleepEx | - | 0x00439710 | 0x000392D0 | 0x000304D0 | 0x00000000 |
TlsSetValue | - | 0x00439718 | 0x000392D8 | 0x000304D8 | 0x00000000 |
TerminateProcess | - | 0x00439720 | 0x000392E0 | 0x000304E0 | 0x00000000 |
FileTimeToSystemTime | - | 0x00439728 | 0x000392E8 | 0x000304E8 | 0x00000000 |
LocalAlloc | - | 0x00439730 | 0x000392F0 | 0x000304F0 | 0x00000000 |
RemoveDirectoryW | - | 0x00439738 | 0x000392F8 | 0x000304F8 | 0x00000000 |
GetCurrentThreadId | - | 0x00439740 | 0x00039300 | 0x00030500 | 0x00000000 |
UnhandledExceptionFilter | - | 0x00439748 | 0x00039308 | 0x00030508 | 0x00000000 |
VirtualQuery | - | 0x00439750 | 0x00039310 | 0x00030510 | 0x00000000 |
GlobalFree | - | 0x00439758 | 0x00039318 | 0x00030518 | 0x00000000 |
Sleep | - | 0x00439760 | 0x00039320 | 0x00030520 | 0x00000000 |
SetThreadLocale | - | 0x00439768 | 0x00039328 | 0x00030528 | 0x00000000 |
ole32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoInitializeEx | - | 0x00439778 | 0x00039338 | 0x00030538 | 0x00000000 |
CoUninitialize | - | 0x00439780 | 0x00039340 | 0x00030540 | 0x00000000 |
user32.dll (33)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateWindowExW | - | 0x00439790 | 0x00039350 | 0x00030550 | 0x00000000 |
EnumDisplaySettingsW | - | 0x00439798 | 0x00039358 | 0x00030558 | 0x00000000 |
GetMessageW | - | 0x004397A0 | 0x00039360 | 0x00030560 | 0x00000000 |
GetWindowDC | - | 0x004397A8 | 0x00039368 | 0x00030568 | 0x00000000 |
TranslateMessage | - | 0x004397B0 | 0x00039370 | 0x00030570 | 0x00000000 |
GetSystemMetrics | - | 0x004397B8 | 0x00039378 | 0x00030578 | 0x00000000 |
PostMessageW | - | 0x004397C0 | 0x00039380 | 0x00030580 | 0x00000000 |
MessageBoxW | - | 0x004397C8 | 0x00039388 | 0x00030588 | 0x00000000 |
SetWindowTextW | - | 0x004397D0 | 0x00039390 | 0x00030590 | 0x00000000 |
AttachThreadInput | - | 0x004397D8 | 0x00039398 | 0x00030598 | 0x00000000 |
PostQuitMessage | - | 0x004397E0 | 0x000393A0 | 0x000305A0 | 0x00000000 |
keybd_event | - | 0x004397E8 | 0x000393A8 | 0x000305A8 | 0x00000000 |
MapVirtualKeyW | - | 0x004397F0 | 0x000393B0 | 0x000305B0 | 0x00000000 |
LoadImageW | - | 0x004397F8 | 0x000393B8 | 0x000305B8 | 0x00000000 |
GetDesktopWindow | - | 0x00439800 | 0x000393C0 | 0x000305C0 | 0x00000000 |
DispatchMessageW | - | 0x00439808 | 0x000393C8 | 0x000305C8 | 0x00000000 |
GetCursorPos | - | 0x00439810 | 0x000393D0 | 0x000305D0 | 0x00000000 |
SetCursorPos | - | 0x00439818 | 0x000393D8 | 0x000305D8 | 0x00000000 |
GetTopWindow | - | 0x00439820 | 0x000393E0 | 0x000305E0 | 0x00000000 |
SendMessageW | - | 0x00439828 | 0x000393E8 | 0x000305E8 | 0x00000000 |
ShowWindow | - | 0x00439830 | 0x000393F0 | 0x000305F0 | 0x00000000 |
SystemParametersInfoW | - | 0x00439838 | 0x000393F8 | 0x000305F8 | 0x00000000 |
LoadIconW | - | 0x00439840 | 0x00039400 | 0x00030600 | 0x00000000 |
DefWindowProcW | - | 0x00439848 | 0x00039408 | 0x00030608 | 0x00000000 |
GetForegroundWindow | - | 0x00439850 | 0x00039410 | 0x00030610 | 0x00000000 |
RegisterClassW | - | 0x00439858 | 0x00039418 | 0x00030618 | 0x00000000 |
GetWindowThreadProcessId | - | 0x00439860 | 0x00039420 | 0x00030620 | 0x00000000 |
GetDC | - | 0x00439868 | 0x00039428 | 0x00030628 | 0x00000000 |
GetFocus | - | 0x00439870 | 0x00039430 | 0x00030630 | 0x00000000 |
LoadCursorW | - | 0x00439878 | 0x00039438 | 0x00030638 | 0x00000000 |
ReleaseDC | - | 0x00439880 | 0x00039440 | 0x00030640 | 0x00000000 |
mouse_event | - | 0x00439888 | 0x00039448 | 0x00030648 | 0x00000000 |
FindWindowW | - | 0x00439890 | 0x00039450 | 0x00030650 | 0x00000000 |
oleaut32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysAllocStringLen | - | 0x004398A0 | 0x00039460 | 0x00030660 | 0x00000000 |
SysFreeString | - | 0x004398A8 | 0x00039468 | 0x00030668 | 0x00000000 |
gdi32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetObjectW | - | 0x004398B8 | 0x00039478 | 0x00030678 | 0x00000000 |
SelectPalette | - | 0x004398C0 | 0x00039480 | 0x00030680 | 0x00000000 |
CreateCompatibleBitmap | - | 0x004398C8 | 0x00039488 | 0x00030688 | 0x00000000 |
DeleteObject | - | 0x004398D0 | 0x00039490 | 0x00030690 | 0x00000000 |
SelectObject | - | 0x004398D8 | 0x00039498 | 0x00030698 | 0x00000000 |
DeleteDC | - | 0x004398E0 | 0x000394A0 | 0x000306A0 | 0x00000000 |
BitBlt | - | 0x004398E8 | 0x000394A8 | 0x000306A8 | 0x00000000 |
CreateDIBSection | - | 0x004398F0 | 0x000394B0 | 0x000306B0 | 0x00000000 |
GetDIBits | - | 0x004398F8 | 0x000394B8 | 0x000306B8 | 0x00000000 |
CreateCompatibleDC | - | 0x00439900 | 0x000394C0 | 0x000306C0 | 0x00000000 |
Exports (6)
»
API Name | EAT Address | Ordinal |
---|---|---|
Control_RunDLL | 0x00027D20 | 0x00000003 |
DllCanUnloadNow | 0x00028EB0 | 0x00000005 |
DllGetClassObject | 0x00028B30 | 0x00000006 |
DllRegisterServer | 0x00028B00 | 0x00000004 |
__dbk_fcall_wrapper | 0x0000E450 | 0x00000002 |
dbkFCallWrapperAddr | 0x000371A8 | 0x00000001 |
C:\Users\KEECFM~1\AppData\Local\Temp\TTT.TMP | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\KEECFM~1\AppData\Local\Temp\check01.bat | Dropped File | Text |
Clean
|
...
|
»
C:\Users\KEECFM~1\AppData\Local\Temp\Z11.xml | Dropped File | Text |
Clean
|
...
|
»
C:\Users\KEECFM~1\AppData\Local\Temp\ZZ11.tmp | Dropped File | Text |
Clean
|
...
|
»
C:\Users\KEECFM~1\AppData\Local\Temp\a.xml | Dropped File | Text |
Clean
|
...
|
»
C:\Users\KEECFM~1\AppData\Local\Temp\writebin.vbs | Dropped File | Text |
Clean
|
...
|
»
C:\Users\KEECFM~1\AppData\Local\Temp\MMM.TMP | Dropped File | Text |
Clean
|
...
|
»
C:\Users\KEECFM~1\AppData\Local\Temp\~dr9078 | Dropped File | Empty |
Clean
|
...
|
»
e5b106d13edb2cb1711191948ba614e747fc03e236fd4c9628208231e525d1a9 | Downloaded File | Image |
Clean
|
...
|
»
c:\users\keecfmwgj\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Clean
|
...
|
»