🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fd71a2fcc0b5dd0fb0dbff257839b67749f2cadf30e2d3dae7f0e941d93d24d3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Maldoc score: 4


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: fd71a2fcc0b5dd0fb0dbff257839b67749f2cadf30e2d3dae7f0e941d93d24d3
SHA3-384 hash: 223ed45567a8513be5fdfa7dfb703070cb8e37be7c9652f1363786dcf75abf290d3153bddd238880db4e095811c511da
SHA1 hash: 015bb306d9e54001d433b3ac2e7212b864f54ae2
MD5 hash: 9e1ee4a42c381eabcf2cde38a1aae7c9
humanhash: lake-delaware-lake-paris
File name:cancel_sub_VCP1234567890123.xlsb
Download: download sample
File size:125'976 bytes
First seen:2021-06-10 20:09:07 UTC
Last seen:2021-06-10 20:47:15 UTC
File type:Excel file xlsx
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
ssdeep 3072:16qiU1d9aIwln/XDeiNv+6CkSKI30dmA+WR1WK2c:cqiO0RBXD5Nv+B4I3+zlvWK/
TLSH 31C3126BD55E5743C28D68B8560229E16A0CB093A369F1CB20A8F5510FDF09B1FEDDCE
Reporter ffforward
Tags:BazarCall mon311 TrickBot xlsb xlsx

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 4
OLE dump

MalwareBazaar was able to identify 11 sections in this file using oledump:

Section IDSection sizeSection name
A1409 bytesPROJECT
A265 bytesPROJECTwm
A31487 bytesVBA/Module1
A4999 bytesVBA/ThisWorkbook
A52505 bytesVBA/_VBA_PROJECT
A61463 bytesVBA/__SRP_0
A7148 bytesVBA/__SRP_1
A8250 bytesVBA/__SRP_2
A9170 bytesVBA/__SRP_3
A10525 bytesVBA/dir
OLE vba

MalwareBazaar was able to extract and deobfuscate VBA script(s) the following information from OLE objects embedded in this file using olevba:

TypeKeywordDescription
SuspiciousCreateObjectMay create an OLE object
SuspiciousHex StringsHex-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)

Intelligence


File Origin
# of uploads :
2
# of downloads :
524
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
cancel_sub_VCP1234567890123.xlsb
Verdict:
No threats detected
Analysis date:
2021-06-10 20:12:15 UTC
Tags:
macros macros40

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Legit
File type:
application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
Has a screenshot:
False
Contains macros:
True
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a process with a hidden window
Creating a file
Launching a process
Running batch commands by exploiting the app vulnerability
Result
Verdict:
Malicious
File Type:
OOXML Excel File with Excel4Macro
Document image
Document image
Result
Threat name:
Unknown
Detection:
malicious
Classification:
troj.expl.bank
Score:
60 / 100
Signature
Document exploit detected (process start blacklist hit)
Performs DNS queries to domains with low reputation
Registers a new ROOT certificate
Sigma detected: Microsoft Office Product Spawning Windows Shell
Sigma detected: Suspicious Certutil Command
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 432895 Sample: cancel_sub_VCP1234567890123.xlsb Startdate: 10/06/2021 Architecture: WINDOWS Score: 60 32 Sigma detected: Microsoft Office Product Spawning Windows Shell 2->32 34 Document exploit detected (process start blacklist hit) 2->34 36 Sigma detected: Suspicious Certutil Command 2->36 7 EXCEL.EXE 26 24 2->7         started        process3 process4 9 TTObk2.exe 16 7->9         started        13 cmd.exe 3 7->13         started        16 cmd.exe 1 7->16         started        dnsIp5 28 195.123.235.51, 49726, 49730, 80 GREENFLOID-ASUA Bulgaria 9->28 30 pshe0pxe339.xyz 34.82.151.137, 49728, 49731, 80 GOOGLEUS United States 9->30 38 Performs DNS queries to domains with low reputation 9->38 40 Registers a new ROOT certificate 9->40 18 conhost.exe 9->18         started        26 C:\ProgramData\TTObk2\TTObk2.exe, PE32 13->26 dropped 20 conhost.exe 13->20         started        22 rundll32.exe 16->22         started        24 conhost.exe 16->24         started        file6 signatures7 process8
Threat name:
Win32.Dropper.Generic
Status:
Suspicious
First seen:
2021-06-10 20:10:12 UTC
AV detection:
3 of 46 (6.52%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
macro xlm
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Suspicious behavior: AddClipboardFormatListener
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Office loads VBA resources, possible macro or embedded object present
Loads dropped DLL
Executes dropped EXE
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Excel file xlsx fd71a2fcc0b5dd0fb0dbff257839b67749f2cadf30e2d3dae7f0e941d93d24d3

(this sample)

  
Delivery method
Distributed via web download

Comments