MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 295fd997fff27d84839e01a87ab308f71dc37b56757ff3139c66ee22e70ec76e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 11
Maldoc score: 43
| SHA256 hash: | 295fd997fff27d84839e01a87ab308f71dc37b56757ff3139c66ee22e70ec76e |
|---|---|
| SHA3-384 hash: | 9ccc95972060f44431fcb3b045329ccda4a194029e3252fd884065a2dd0a05df9a8b3cdd7a7c696f2f16a958e01d0f97 |
| SHA1 hash: | cb11289d047db3087408a741f05ee0283cf420b2 |
| MD5 hash: | 3b2d339436af476adb10fd7a41f57483 |
| humanhash: | social-mango-bluebird-lamp |
| File name: | Pre arrival Kiel Canal.xls |
| Download: | download sample |
| File size: | 1'956'352 bytes |
| First seen: | 2026-09-12 13:05:15 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/vnd.ms-excel |
| ssdeep | 24576:b93uqqNjpQ3uOXMo96m+Q7ynR4J74CWh9vF2a:Nuv9o9+Q7yn |
| TLSH | T15095D642F72AC667C2585A354DDBC7A47730BD06AE46570330C9BB3E3DF7A90AE01689 |
| TrID | 34.9% (.XLS) Microsoft Excel sheet (32500/1/3) 30.1% (.XLS) Microsoft Excel sheet (alternate) (28000/1/3) 26.3% (.XLS) Microsoft Excel sheet (alternate) (24500/1/2) 8.6% (.) Generic OLE2 / Multistream Compound (8000/1) |
| Magika | xls |
| Reporter | |
| Tags: | xls |
Office OLE Information
This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.
OLE id
| Maldoc score: 43 |
| Application name is Microsoft Excel |
| Author of this document is Brunet |
| File Format is MS Excel 97-2003 |
| Container Format is OLE |
| Office document contains VBA Macros |
OLE dump
MalwareBazaar was able to identify 146 sections in this file using oledump:
| Section ID | Section size | Section name |
|---|---|---|
| 1 | 108 bytes | CompObj |
| 2 | 916 bytes | DocumentSummaryInformation |
| 3 | 240 bytes | SummaryInformation |
| 4 | 175395 bytes | Ctls |
| 5 | 704442 bytes | Workbook |
| 6 | 2406 bytes | _VBA_PROJECT_CUR/PROJECT |
| 7 | 1013 bytes | _VBA_PROJECT_CUR/PROJECTwm |
| 8 | 3841 bytes | _VBA_PROJECT_CUR/VBA/DieseArbeitsmappe |
| 9 | 3008 bytes | _VBA_PROJECT_CUR/VBA/Klasse1 |
| 10 | 53279 bytes | _VBA_PROJECT_CUR/VBA/Modul1 |
| 11 | 2614 bytes | _VBA_PROJECT_CUR/VBA/Modul2 |
| 12 | 4604 bytes | _VBA_PROJECT_CUR/VBA/Modul3 |
| 13 | 2500 bytes | _VBA_PROJECT_CUR/VBA/Tabelle01 |
| 14 | 23658 bytes | _VBA_PROJECT_CUR/VBA/Tabelle02 |
| 15 | 18469 bytes | _VBA_PROJECT_CUR/VBA/Tabelle03 |
| 16 | 25670 bytes | _VBA_PROJECT_CUR/VBA/Tabelle04 |
| 17 | 13771 bytes | _VBA_PROJECT_CUR/VBA/Tabelle05 |
| 18 | 13593 bytes | _VBA_PROJECT_CUR/VBA/Tabelle06 |
| 19 | 15311 bytes | _VBA_PROJECT_CUR/VBA/Tabelle07 |
| 20 | 28431 bytes | _VBA_PROJECT_CUR/VBA/Tabelle08 |
| 21 | 35101 bytes | _VBA_PROJECT_CUR/VBA/Tabelle09 |
| 22 | 16400 bytes | _VBA_PROJECT_CUR/VBA/Tabelle10 |
| 23 | 19393 bytes | _VBA_PROJECT_CUR/VBA/Tabelle11 |
| 24 | 15831 bytes | _VBA_PROJECT_CUR/VBA/Tabelle12 |
| 25 | 22451 bytes | _VBA_PROJECT_CUR/VBA/Tabelle13 |
| 26 | 22537 bytes | _VBA_PROJECT_CUR/VBA/Tabelle14 |
| 27 | 24358 bytes | _VBA_PROJECT_CUR/VBA/Tabelle15 |
| 28 | 24660 bytes | _VBA_PROJECT_CUR/VBA/Tabelle16 |
| 29 | 9943 bytes | _VBA_PROJECT_CUR/VBA/Tabelle17 |
| 30 | 12383 bytes | _VBA_PROJECT_CUR/VBA/Tabelle18 |
| 31 | 12448 bytes | _VBA_PROJECT_CUR/VBA/Tabelle19 |
| 32 | 1183 bytes | _VBA_PROJECT_CUR/VBA/Tabelle21 |
| 33 | 18119 bytes | _VBA_PROJECT_CUR/VBA/_VBA_PROJECT |
| 34 | 36488 bytes | _VBA_PROJECT_CUR/VBA/__SRP_0 |
| 35 | 4925 bytes | _VBA_PROJECT_CUR/VBA/__SRP_1 |
| 36 | 1568 bytes | _VBA_PROJECT_CUR/VBA/__SRP_10 |
| 37 | 312 bytes | _VBA_PROJECT_CUR/VBA/__SRP_11 |
| 38 | 18775 bytes | _VBA_PROJECT_CUR/VBA/__SRP_12 |
| 39 | 1564 bytes | _VBA_PROJECT_CUR/VBA/__SRP_13 |
| 40 | 19875 bytes | _VBA_PROJECT_CUR/VBA/__SRP_14 |
| 41 | 1202 bytes | _VBA_PROJECT_CUR/VBA/__SRP_15 |
| 42 | 24639 bytes | _VBA_PROJECT_CUR/VBA/__SRP_16 |
| 43 | 2260 bytes | _VBA_PROJECT_CUR/VBA/__SRP_17 |
| 44 | 2194 bytes | _VBA_PROJECT_CUR/VBA/__SRP_18 |
| 45 | 306 bytes | _VBA_PROJECT_CUR/VBA/__SRP_19 |
| 46 | 13719 bytes | _VBA_PROJECT_CUR/VBA/__SRP_1a |
| 47 | 960 bytes | _VBA_PROJECT_CUR/VBA/__SRP_1b |
| 48 | 13895 bytes | _VBA_PROJECT_CUR/VBA/__SRP_1c |
| 49 | 1012 bytes | _VBA_PROJECT_CUR/VBA/__SRP_1d |
| 50 | 13915 bytes | _VBA_PROJECT_CUR/VBA/__SRP_1e |
| 51 | 1318 bytes | _VBA_PROJECT_CUR/VBA/__SRP_1f |
| 52 | 2060 bytes | _VBA_PROJECT_CUR/VBA/__SRP_2 |
| 53 | 27067 bytes | _VBA_PROJECT_CUR/VBA/__SRP_20 |
| 54 | 2958 bytes | _VBA_PROJECT_CUR/VBA/__SRP_21 |
| 55 | 32901 bytes | _VBA_PROJECT_CUR/VBA/__SRP_22 |
| 56 | 4380 bytes | _VBA_PROJECT_CUR/VBA/__SRP_23 |
| 57 | 13363 bytes | _VBA_PROJECT_CUR/VBA/__SRP_24 |
| 58 | 1294 bytes | _VBA_PROJECT_CUR/VBA/__SRP_25 |
| 59 | 23135 bytes | _VBA_PROJECT_CUR/VBA/__SRP_26 |
| 60 | 804 bytes | _VBA_PROJECT_CUR/VBA/__SRP_27 |
| 61 | 12151 bytes | _VBA_PROJECT_CUR/VBA/__SRP_28 |
| 62 | 1626 bytes | _VBA_PROJECT_CUR/VBA/__SRP_29 |
| 63 | 17047 bytes | _VBA_PROJECT_CUR/VBA/__SRP_2a |
| 64 | 2132 bytes | _VBA_PROJECT_CUR/VBA/__SRP_2b |
| 65 | 17433 bytes | _VBA_PROJECT_CUR/VBA/__SRP_2c |
| 66 | 2132 bytes | _VBA_PROJECT_CUR/VBA/__SRP_2d |
| 67 | 19999 bytes | _VBA_PROJECT_CUR/VBA/__SRP_2e |
| 68 | 2406 bytes | _VBA_PROJECT_CUR/VBA/__SRP_2f |
| 69 | 284 bytes | _VBA_PROJECT_CUR/VBA/__SRP_3 |
| 70 | 20199 bytes | _VBA_PROJECT_CUR/VBA/__SRP_30 |
| 71 | 2406 bytes | _VBA_PROJECT_CUR/VBA/__SRP_31 |
| 72 | 6617 bytes | _VBA_PROJECT_CUR/VBA/__SRP_32 |
| 73 | 1048 bytes | _VBA_PROJECT_CUR/VBA/__SRP_33 |
| 74 | 11057 bytes | _VBA_PROJECT_CUR/VBA/__SRP_34 |
| 75 | 960 bytes | _VBA_PROJECT_CUR/VBA/__SRP_35 |
| 76 | 10909 bytes | _VBA_PROJECT_CUR/VBA/__SRP_36 |
| 77 | 960 bytes | _VBA_PROJECT_CUR/VBA/__SRP_37 |
| 78 | 464 bytes | _VBA_PROJECT_CUR/VBA/__SRP_38 |
| 79 | 106 bytes | _VBA_PROJECT_CUR/VBA/__SRP_39 |
| 80 | 357 bytes | _VBA_PROJECT_CUR/VBA/__SRP_3a |
| 81 | 440 bytes | _VBA_PROJECT_CUR/VBA/__SRP_3b |
| 82 | 269 bytes | _VBA_PROJECT_CUR/VBA/__SRP_3c |
| 83 | 326 bytes | _VBA_PROJECT_CUR/VBA/__SRP_3d |
| 84 | 28113 bytes | _VBA_PROJECT_CUR/VBA/__SRP_4 |
| 85 | 1278 bytes | _VBA_PROJECT_CUR/VBA/__SRP_5 |
| 86 | 1162 bytes | _VBA_PROJECT_CUR/VBA/__SRP_6 |
| 87 | 480 bytes | _VBA_PROJECT_CUR/VBA/__SRP_7 |
| 88 | 1710 bytes | _VBA_PROJECT_CUR/VBA/__SRP_8 |
| 89 | 500 bytes | _VBA_PROJECT_CUR/VBA/__SRP_9 |
| 90 | 2269 bytes | _VBA_PROJECT_CUR/VBA/__SRP_a |
| 91 | 630 bytes | _VBA_PROJECT_CUR/VBA/__SRP_b |
| 92 | 1710 bytes | _VBA_PROJECT_CUR/VBA/__SRP_c |
| 93 | 500 bytes | _VBA_PROJECT_CUR/VBA/__SRP_d |
| 94 | 1498 bytes | _VBA_PROJECT_CUR/VBA/__SRP_e |
| 95 | 450 bytes | _VBA_PROJECT_CUR/VBA/__SRP_f |
| 96 | 1955 bytes | _VBA_PROJECT_CUR/VBA/dir |
| 97 | 10368 bytes | _VBA_PROJECT_CUR/VBA/frmCalendar1 |
| 98 | 3870 bytes | _VBA_PROJECT_CUR/VBA/frmCountryName |
| 99 | 2435 bytes | _VBA_PROJECT_CUR/VBA/frmError |
| 100 | 7202 bytes | _VBA_PROJECT_CUR/VBA/frmF1 |
| 101 | 3739 bytes | _VBA_PROJECT_CUR/VBA/frmNSTCode |
| 102 | 3671 bytes | _VBA_PROJECT_CUR/VBA/frmPurposeOfCall |
| 103 | 3176 bytes | _VBA_PROJECT_CUR/VBA/frmShiptype |
| 104 | 77955 bytes | _VBA_PROJECT_CUR/VBA/frmXML |
| 105 | 97 bytes | _VBA_PROJECT_CUR/frmCalendar1/CompObj |
| 106 | 296 bytes | _VBA_PROJECT_CUR/frmCalendar1/VBFrame |
| 107 | 3323 bytes | _VBA_PROJECT_CUR/frmCalendar1/f |
| 108 | 5670 bytes | _VBA_PROJECT_CUR/frmCalendar1/o |
| 109 | 97 bytes | _VBA_PROJECT_CUR/frmCountryName/CompObj |
| 110 | 301 bytes | _VBA_PROJECT_CUR/frmCountryName/VBFrame |
| 111 | 163 bytes | _VBA_PROJECT_CUR/frmCountryName/f |
| 112 | 115 bytes | _VBA_PROJECT_CUR/frmCountryName/i04/CompObj |
| 113 | 176 bytes | _VBA_PROJECT_CUR/frmCountryName/i04/f |
| 114 | 110 bytes | _VBA_PROJECT_CUR/frmCountryName/i04/i06/CompObj |
| 115 | 108 bytes | _VBA_PROJECT_CUR/frmCountryName/i04/i06/f |
| 116 | 96 bytes | _VBA_PROJECT_CUR/frmCountryName/i04/i06/o |
| 117 | 110 bytes | _VBA_PROJECT_CUR/frmCountryName/i04/i07/CompObj |
| 118 | 108 bytes | _VBA_PROJECT_CUR/frmCountryName/i04/i07/f |
| 119 | 96 bytes | _VBA_PROJECT_CUR/frmCountryName/i04/i07/o |
| 120 | 148 bytes | _VBA_PROJECT_CUR/frmCountryName/i04/o |
| 121 | 48 bytes | _VBA_PROJECT_CUR/frmCountryName/i04/x |
| 122 | 0 bytes | _VBA_PROJECT_CUR/frmCountryName/o |
| 123 | 97 bytes | _VBA_PROJECT_CUR/frmError/CompObj |
| 124 | 288 bytes | _VBA_PROJECT_CUR/frmError/VBFrame |
| 125 | 415 bytes | _VBA_PROJECT_CUR/frmError/f |
| 126 | 468 bytes | _VBA_PROJECT_CUR/frmError/o |
| 127 | 97 bytes | _VBA_PROJECT_CUR/frmF1/CompObj |
| 128 | 280 bytes | _VBA_PROJECT_CUR/frmF1/VBFrame |
| 129 | 147 bytes | _VBA_PROJECT_CUR/frmF1/f |
| 130 | 96 bytes | _VBA_PROJECT_CUR/frmF1/o |
| 131 | 97 bytes | _VBA_PROJECT_CUR/frmNSTCode/CompObj |
| 132 | 293 bytes | _VBA_PROJECT_CUR/frmNSTCode/VBFrame |
| 133 | 159 bytes | _VBA_PROJECT_CUR/frmNSTCode/f |
| 134 | 96 bytes | _VBA_PROJECT_CUR/frmNSTCode/o |
| 135 | 97 bytes | _VBA_PROJECT_CUR/frmPurposeOfCall/CompObj |
| 136 | 306 bytes | _VBA_PROJECT_CUR/frmPurposeOfCall/VBFrame |
| 137 | 159 bytes | _VBA_PROJECT_CUR/frmPurposeOfCall/f |
| 138 | 96 bytes | _VBA_PROJECT_CUR/frmPurposeOfCall/o |
| 139 | 97 bytes | _VBA_PROJECT_CUR/frmShipType/CompObj |
| 140 | 294 bytes | _VBA_PROJECT_CUR/frmShipType/VBFrame |
| 141 | 159 bytes | _VBA_PROJECT_CUR/frmShipType/f |
| 142 | 96 bytes | _VBA_PROJECT_CUR/frmShipType/o |
| 143 | 97 bytes | _VBA_PROJECT_CUR/frmXML/CompObj |
| 144 | 290 bytes | _VBA_PROJECT_CUR/frmXML/VBFrame |
| 145 | 195 bytes | _VBA_PROJECT_CUR/frmXML/f |
| 146 | 104 bytes | _VBA_PROJECT_CUR/frmXML/o |
OLE vba
MalwareBazaar was able to extract and deobfuscate VBA script(s) the following information from OLE objects embedded in this file using olevba:
| Type | Keyword | Description |
|---|---|---|
| AutoExec | Workbook_Open | Runs when the Excel Workbook is opened |
| AutoExec | Workbook_BeforeClose | Runs when the Excel Workbook is closed |
| AutoExec | CheckBox1_GotFocus | Runs when the file is opened and ActiveXobjects trigger events |
| AutoExec | CommandButton2_Click | Runs when the file is opened and ActiveXobjects trigger events |
| AutoExec | cboM_Change | Runs when the file is opened and ActiveXobjects trigger events |
| AutoExec | UserForm_Resize | Runs when the file is opened and ActiveXobjects trigger events |
| Base64 | HDU | SERV |
| IOC | http://www.w3.org/2001/XMLSchema | URL |
| IOC | http://e-declaration.dakosy.de/EdiMessages | URL |
| String | code and P-code are different, this may havebeen used to hide malicious code | |
| Suspicious | Open | May open a file |
| Suspicious | Write | May write to a file (if combined with Open) |
| Suspicious | Put | May write to a file (if combined with Open) |
| Suspicious | Output | May write to a file (if combined with Open) |
| Suspicious | Binary | May read or write a binary file (if combinedwith Open) |
| Suspicious | FileCopy | May copy a file |
| Suspicious | CopyHere | May copy a file |
| Suspicious | Kill | May delete a file |
| Suspicious | Shell | May run an executable file or a systemcommand |
| Suspicious | MkDir | May create a directory |
| Suspicious | CreateObject | May create an OLE object |
| Suspicious | Shell.Application | May run an application (if combined withCreateObject) |
| Suspicious | Chr | May attempt to obfuscate specific strings(use option --deobf to deobfuscate) |
| Suspicious | Xor | May attempt to obfuscate specific strings(use option --deobf to deobfuscate) |
| Suspicious | Hex Strings | Hex-encoded strings were detected, may beused to obfuscate strings (option --decode tosee all) |
| Suspicious | Base64 Strings | Base64-encoded strings were detected, may beused to obfuscate strings (option --decode tosee all) |
Intelligence
File Origin
SEVendor Threat Intelligence
Details
Result
Behaviour
Document image
Result
Signature
Behaviour
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | CP_Script_Inject_Detector |
|---|---|
| Author: | DiegoAnalytics |
| Description: | Detects attempts to inject code into another process across PE, ELF, Mach-O binaries |
| Rule name: | DebuggerCheck__API |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | DebuggerException__SetConsoleCtrl |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | FreddyBearDropper |
|---|---|
| Author: | Dwarozh Hoshiar |
| Description: | Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip. |
| Rule name: | golang_bin_JCorn_CSC846 |
|---|---|
| Author: | Justin Cornwell |
| Description: | CSC-846 Golang detection ruleset |
| Rule name: | informational_win_ole_protected |
|---|---|
| Author: | Jeff White (karttoon@gmail.com) @noottrak |
| Description: | Identify OLE Project protection within documents. |
| Rule name: | RANSOMWARE |
|---|---|
| Author: | ToroGuitar |
| Rule name: | TA505_Maldoc_21Nov_2 |
|---|---|
| Author: | Arkbird_SOLG |
| Description: | invitation (1).xls |
| Reference: | https://twitter.com/58_158_177_102/status/1197432303057637377 |
| Rule name: | test_Malaysia |
|---|---|
| Author: | rectifyq |
| Description: | Detects file containing malaysia string |
| Rule name: | TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE |
|---|---|
| Author: | CYFARE |
| Description: | Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments |
| Reference: | https://cyfare.net/ |
| Rule name: | VECT_Ransomware |
|---|---|
| Author: | Mustafa Bakhit |
| Description: | Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments. |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.