Managed XDR

e-work-eknis-dokumenta...neurc-11_excel2016.xls — malware analysis report

File info

Filename
e-work-eknis-dokumentatsiia-proekty-asdu-chernigivoblenergo-zadachi-2023-11-24-62685-zvit-nkre-oms-chernigivoblenergo-zvit-nkre-chernigivoe-sich-zhov-2023-neurc-11_excel2016.xls
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1251, Author: Verbytskyi+Koval, Last Saved By: , Name of Creating Application: Microsoft Excel, Last Printed: Mon Sep 23 09:32:01 2013, Create Time/Date: Thu Jun 12 16:18:12 2008, Last Saved Time/Date: Fri Dec 28 09:54:28 2018, Security: 1
File size
2.1 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
1cd80dce19db5fcbc2d0f38abb206a9fc4bac459
SHA256
519e8253a7bc5c3984ddc0fe1a48911523124ba5cc4f86174f26bf629f37848d
MD5
3239bd7619f172b51b0d070b3d45a6b3

Signatures

Execution

T1203 office_write_exe: Office document dropped an executable file
T1064 office_macros_suspicious: Document contains suspicious macro
T1559 suspicious_process: Spawns a suspicious process
T1064 office_macros: The document contains macroses (total: 26)
T1064 office_macros_strings: Feature lines found in document macro
T1064 office_macros_autoexec: The document contains an auto-start macro
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1064 office_macros_suspicious: Document contains suspicious macro
T1564 office_vba_stomping: VBA Stomping was detected in the document (the VBA source code and P-code are different)
T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1064 office_macros: The document contains macroses (total: 26)
T1064 office_macros_strings: Feature lines found in document macro
T1064 office_macros_autoexec: The document contains an auto-start macro
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1082 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1083 checks_recent_files: Attempt to check recently opened files through registry

Collection

T1560.001 archive_via_utility: Detected archiving data via utility

Other

executes_dropped_exe: Executes dropped exe files
creates_exe: Creates executable files in the file system
office_summary: The document contains suspicious metadata
create_rpc_bindings: Creates RPC connection
break_limit_exceeded: Warning: function calls limit has been exceeded
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
yara_rules: Static rules