Managed XDR

standard_celeration_excel.xls (ZLoader) — malware analysis report

File info

Filename
standard_celeration_excel.xls
File type
Composite Document File V2 Document, Little Endian, Os: MacOS, Version 4.14, Code page: 10000, Title: SCCFB (daily count per minute), Subject: Standard Chart Templates, Author: Owen White, Stuart Harder, & Scott Born, Keywords: celeration line, bounce, record floor, acceleration, deceleration, total possible, Comments: Original Template designed by Owen White 19?? Chart formatting by Scott Born and Additional functionality and program support for data entry and celeration lines by Stuart Harder. Owen White provided protocol for the Median Slope trend line method and Stuart Harder converted the method into code for the template. Bounce line analysis by Stuart Harder., Last Saved By: Martell, Kim, Revision Number: 1, Name of Creating Application: Microsoft Macintosh Excel, Last Printed: Wed Nov 5 17:34:03 2008, Create Time/Date: Tue Sep 12 22:41:17 2000, Last Saved Time/Date: Wed Jul 10 00:54:59 2024, Security: 0
File size
2.2 MB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
7ceeb8cb52d72e7ef0247a8b12631fc0ab672cb3
SHA256
a40310890767665f2f06d4dad0799c86fe09cce73b42047434bb9e793be80f08
MD5
f6192d985db0178d639b223184ba7c21

Malwares

  • ZLoader

Signatures

Execution

T1064 office_macros_hidden: Document contains suspicious Excel 4.0 macro
T1064 office_macros: The document contains macro
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1064 office_macros_hidden: Document contains suspicious Excel 4.0 macro
T1064 office_macros: The document contains macro
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Credential Access

T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files

Discovery

T1083 checks_recent_files: Attempt to check recently opened files through registry
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1497.002 async_mouse: Watches for mouse clicks using GetAsyncKeyState to detect human activity
T1082 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining

Other

yara_rules: Static rules
office_summary: The document contains suspicious metadata
create_rpc_bindings: Creates RPC connection
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
checktokenmembership: Checks user token with CheckTokenMembership call

Related reports