Overview
overview
10Static
static
100d63eafe7f...99.exe
windows7-x64
80d63eafe7f...99.exe
windows10-2004-x64
8$PLUGINSDI...ge.dll
windows7-x64
1$PLUGINSDI...ge.dll
windows10-2004-x64
1$PLUGINSDI...gs.dll
windows7-x64
3$PLUGINSDI...gs.dll
windows10-2004-x64
31921502319...4.xlam
windows7-x64
101921502319...4.xlam
windows10-2004-x64
127133b9541...e9.vbs
windows7-x64
827133b9541...e9.vbs
windows10-2004-x64
6304278cfa0...1c.xls
windows7-x64
1304278cfa0...1c.xls
windows10-2004-x64
1365771facf...77.exe
windows7-x64
10365771facf...77.exe
windows10-2004-x64
10397900307d...0c.lnk
windows7-x64
3397900307d...0c.lnk
windows10-2004-x64
83d390249d9...ab.lnk
windows7-x64
33d390249d9...ab.lnk
windows10-2004-x64
840e5adc952...73.xls
windows7-x64
140e5adc952...73.xls
windows10-2004-x64
1746afcd799...69.xls
windows7-x64
1746afcd799...69.xls
windows10-2004-x64
185af8304fd...9f.jar
windows7-x64
185af8304fd...9f.jar
windows10-2004-x64
7984646a5a7...41.vbs
windows7-x64
10984646a5a7...41.vbs
windows10-2004-x64
109c33e83331...ce.exe
windows7-x64
109c33e83331...ce.exe
windows10-2004-x64
109f07c02b13...b4.lnk
windows7-x64
39f07c02b13...b4.lnk
windows10-2004-x64
10c0baec4eb2...f.xlam
windows7-x64
10c0baec4eb2...f.xlam
windows10-2004-x64
1Analysis
-
max time kernel
149s -
max time network
159s -
platform
windows10-2004_x64 -
resource
win10v2004-20240611-en -
resource tags
arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system -
submitted
17-06-2024 01:02
Behavioral task
behavioral1
Sample
0d63eafe7f4eebd3b782dd262da6fa3e562c420e0ecfff540ee1a9c5a76b0f99.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
0d63eafe7f4eebd3b782dd262da6fa3e562c420e0ecfff540ee1a9c5a76b0f99.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral3
Sample
$PLUGINSDIR/BgImage.dll
Resource
win7-20240611-en
Behavioral task
behavioral4
Sample
$PLUGINSDIR/BgImage.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral5
Sample
$PLUGINSDIR/nsDialogs.dll
Resource
win7-20240220-en
Behavioral task
behavioral6
Sample
$PLUGINSDIR/nsDialogs.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral7
Sample
19215023198d9ebe4a626113cc6c001bd4d250ebea69aa25afd483aefd4c0984.xlam
Resource
win7-20240221-en
Behavioral task
behavioral8
Sample
19215023198d9ebe4a626113cc6c001bd4d250ebea69aa25afd483aefd4c0984.xlam
Resource
win10v2004-20240508-en
Behavioral task
behavioral9
Sample
27133b9541228c135784f7c6c3bb9425975d7e7880ae278fea040b0ffcb8eee9.vbs
Resource
win7-20240611-en
Behavioral task
behavioral10
Sample
27133b9541228c135784f7c6c3bb9425975d7e7880ae278fea040b0ffcb8eee9.vbs
Resource
win10v2004-20240508-en
Behavioral task
behavioral11
Sample
304278cfa0f9f2e81a48c4f23bcb97920b6263c07484b9a0793c2d1b8c65171c.xls
Resource
win7-20231129-en
Behavioral task
behavioral12
Sample
304278cfa0f9f2e81a48c4f23bcb97920b6263c07484b9a0793c2d1b8c65171c.xls
Resource
win10v2004-20240508-en
Behavioral task
behavioral13
Sample
365771facf4476f03189fbace015a962f6fd021650f4ebd61acd0c675bc85b77.exe
Resource
win7-20240611-en
Behavioral task
behavioral14
Sample
365771facf4476f03189fbace015a962f6fd021650f4ebd61acd0c675bc85b77.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral15
Sample
397900307dd4900066b97d9cdbf0e4cdaf145572b84293e1e08c2a15e7963a0c.lnk
Resource
win7-20240508-en
Behavioral task
behavioral16
Sample
397900307dd4900066b97d9cdbf0e4cdaf145572b84293e1e08c2a15e7963a0c.lnk
Resource
win10v2004-20240611-en
Behavioral task
behavioral17
Sample
3d390249d9ba45f8e6198dde8319ee8ccd5b9b23921472095ed453544ca537ab.lnk
Resource
win7-20240508-en
Behavioral task
behavioral18
Sample
3d390249d9ba45f8e6198dde8319ee8ccd5b9b23921472095ed453544ca537ab.lnk
Resource
win10v2004-20240611-en
Behavioral task
behavioral19
Sample
40e5adc952e8c472e083a539cd67ac339132f2e41a2c99dd3083dd720c041673.xls
Resource
win7-20240221-en
Behavioral task
behavioral20
Sample
40e5adc952e8c472e083a539cd67ac339132f2e41a2c99dd3083dd720c041673.xls
Resource
win10v2004-20240611-en
Behavioral task
behavioral21
Sample
746afcd79967881e5a7a21ff847a60c9ef6f1c2dbd796b4ad0c16bc85009d069.xls
Resource
win7-20240508-en
Behavioral task
behavioral22
Sample
746afcd79967881e5a7a21ff847a60c9ef6f1c2dbd796b4ad0c16bc85009d069.xls
Resource
win10v2004-20240508-en
Behavioral task
behavioral23
Sample
85af8304fde85bfbd5323012e0f79fab0045a85943454c7757dece03686b049f.jar
Resource
win7-20240220-en
Behavioral task
behavioral24
Sample
85af8304fde85bfbd5323012e0f79fab0045a85943454c7757dece03686b049f.jar
Resource
win10v2004-20240508-en
Behavioral task
behavioral25
Sample
984646a5a7686265df256e88616dc046b8daa6fbc1807ae67d2933caf0e6af41.vbs
Resource
win7-20240611-en
Behavioral task
behavioral26
Sample
984646a5a7686265df256e88616dc046b8daa6fbc1807ae67d2933caf0e6af41.vbs
Resource
win10v2004-20240226-en
Behavioral task
behavioral27
Sample
9c33e83331c4e2e954f355f453bd32add84016d45e6434d568fb56b690de26ce.exe
Resource
win7-20240611-en
Behavioral task
behavioral28
Sample
9c33e83331c4e2e954f355f453bd32add84016d45e6434d568fb56b690de26ce.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral29
Sample
9f07c02b13a50bb84630841a7a9876c9ced2ab66d406c54f4673c88e7cd70bb4.lnk
Resource
win7-20240508-en
Behavioral task
behavioral30
Sample
9f07c02b13a50bb84630841a7a9876c9ced2ab66d406c54f4673c88e7cd70bb4.lnk
Resource
win10v2004-20240611-en
Behavioral task
behavioral31
Sample
c0baec4eb2deb38c2f86c250a7aae50a417652429439bb5ecce82e8bac6892ef.xlam
Resource
win7-20240221-en
Behavioral task
behavioral32
Sample
c0baec4eb2deb38c2f86c250a7aae50a417652429439bb5ecce82e8bac6892ef.xlam
Resource
win10v2004-20240611-en
General
-
Target
40e5adc952e8c472e083a539cd67ac339132f2e41a2c99dd3083dd720c041673.xls
-
Size
1.3MB
-
MD5
9b57a1c10146136ab07052d49c75bf76
-
SHA1
23d56976bbc90ecd3c00581ba7cd379c2b0b6c9c
-
SHA256
40e5adc952e8c472e083a539cd67ac339132f2e41a2c99dd3083dd720c041673
-
SHA512
36c6b33d454b3c6a7a4c8f97dbb62ea36a28ec2bfe6f4002a743baea7817cf644fd07dfa1b84a8f5621939e7d25106939fd16c18772a3b968dfbd93d94c62490
-
SSDEEP
24576:N9vAixudwuVjUzskic7aIPAmH/JeGUwQKI:PvHxIwSIAk
Malware Config
Signatures
-
Checks processor information in registry 2 TTPs 3 IoCs
Processor information is often read in order to detect sandboxing environments.
Processes:
EXCEL.EXEdescription ioc process Key opened \REGISTRY\MACHINE\Hardware\Description\System\CentralProcessor\0 EXCEL.EXE Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\~MHz EXCEL.EXE Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString EXCEL.EXE -
Enumerates system info in registry 2 TTPs 3 IoCs
Processes:
EXCEL.EXEdescription ioc process Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS\SystemSKU EXCEL.EXE Key opened \REGISTRY\MACHINE\Hardware\Description\System\BIOS EXCEL.EXE Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS\SystemFamily EXCEL.EXE -
Suspicious behavior: AddClipboardFormatListener 1 IoCs
Processes:
EXCEL.EXEpid process 2348 EXCEL.EXE -
Suspicious use of SetWindowsHookEx 8 IoCs
Processes:
EXCEL.EXEpid process 2348 EXCEL.EXE 2348 EXCEL.EXE 2348 EXCEL.EXE 2348 EXCEL.EXE 2348 EXCEL.EXE 2348 EXCEL.EXE 2348 EXCEL.EXE 2348 EXCEL.EXE
Processes
-
C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE"C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\Admin\AppData\Local\Temp\40e5adc952e8c472e083a539cd67ac339132f2e41a2c99dd3083dd720c041673.xls"1⤵
- Checks processor information in registry
- Enumerates system info in registry
- Suspicious behavior: AddClipboardFormatListener
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/2348-2-0x00007FFCAB690000-0x00007FFCAB6A0000-memory.dmpFilesize
64KB
-
memory/2348-3-0x00007FFCAB690000-0x00007FFCAB6A0000-memory.dmpFilesize
64KB
-
memory/2348-1-0x00007FFCAB690000-0x00007FFCAB6A0000-memory.dmpFilesize
64KB
-
memory/2348-0-0x00007FFCAB690000-0x00007FFCAB6A0000-memory.dmpFilesize
64KB
-
memory/2348-5-0x00007FFCAB690000-0x00007FFCAB6A0000-memory.dmpFilesize
64KB
-
memory/2348-7-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-6-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-10-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-11-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-12-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-13-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-9-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-15-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-14-0x00007FFCA8DC0000-0x00007FFCA8DD0000-memory.dmpFilesize
64KB
-
memory/2348-8-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-4-0x00007FFCEB6AD000-0x00007FFCEB6AE000-memory.dmpFilesize
4KB
-
memory/2348-16-0x00007FFCA8DC0000-0x00007FFCA8DD0000-memory.dmpFilesize
64KB
-
memory/2348-17-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-19-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-22-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-21-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-20-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-18-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-36-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB
-
memory/2348-53-0x00007FFCAB690000-0x00007FFCAB6A0000-memory.dmpFilesize
64KB
-
memory/2348-54-0x00007FFCAB690000-0x00007FFCAB6A0000-memory.dmpFilesize
64KB
-
memory/2348-56-0x00007FFCAB690000-0x00007FFCAB6A0000-memory.dmpFilesize
64KB
-
memory/2348-55-0x00007FFCAB690000-0x00007FFCAB6A0000-memory.dmpFilesize
64KB
-
memory/2348-57-0x00007FFCEB610000-0x00007FFCEB805000-memory.dmpFilesize
2.0MB