Summary | ZeroBOX

Invoice%2050261765%20from%20Quickbooks,%20LLC.xls

VBA_macro PE32 MSOffice File PE File
Category Machine Started Completed
FILE s1_win7_x6402 July 15, 2021, 10:03 a.m. July 15, 2021, 10:28 a.m.
Size 713.5KB
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Title: Invoice 50261765 from Quickbooks, LLC, Author: Quickbooks, LLC, Last Saved By: user, Name of Creating Application: Microsoft Excel, Create Time/Date: Wed Jul 14 08:38:23 2021, Last Saved Time/Date: Wed Jul 14 14:10:09 2021, Security: 0
MD5 f92a895f8781cd98115c3cb123301e1c
SHA256 13a8c58e52aba7cfb98f7efc413e91cb707fae63404821a678a15d671d00b944
CRC32 9E1D9D55
ssdeep 12288:XRYbXrlUc6XS/CwRl+4MW1H5onZHBDznxcp/c0UGtkbByxlFYd2DrpGsPk:4Uc6EjDMW1UrDjxcNcfgZI2LP
Yara
  • Contains_VBA_macro_code - Detect a MS Office document with embedded VBA macro code [binaries]
  • Microsoft_Office_File_Zero - Microsoft Office File

IP Address Status Action
128.199.243.169 Active Moloch
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9
exception.symbol: qdialoginsertobject+0x21e8
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8680
exception.address: 0x100021e8
registers.esp: 1638276
registers.edi: 0
registers.eax: 0
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0
exception.symbol: qdialoginsertobject+0x21e9
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8681
exception.address: 0x100021e9
registers.esp: 1638276
registers.edi: 0
registers.eax: 0
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00
exception.symbol: qdialoginsertobject+0x21eb
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8683
exception.address: 0x100021eb
registers.esp: 1638276
registers.edi: 0
registers.eax: 1
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00 00
exception.symbol: qdialoginsertobject+0x21ec
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8684
exception.address: 0x100021ec
registers.esp: 1638276
registers.edi: 0
registers.eax: 1
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9
exception.symbol: qdialoginsertobject+0x21e8
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8680
exception.address: 0x100021e8
registers.esp: 1638276
registers.edi: 0
registers.eax: 1
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0
exception.symbol: qdialoginsertobject+0x21e9
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8681
exception.address: 0x100021e9
registers.esp: 1638276
registers.edi: 0
registers.eax: 1
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00
exception.symbol: qdialoginsertobject+0x21eb
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8683
exception.address: 0x100021eb
registers.esp: 1638276
registers.edi: 0
registers.eax: 2
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00 00
exception.symbol: qdialoginsertobject+0x21ec
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8684
exception.address: 0x100021ec
registers.esp: 1638276
registers.edi: 0
registers.eax: 2
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9
exception.symbol: qdialoginsertobject+0x21e8
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8680
exception.address: 0x100021e8
registers.esp: 1638276
registers.edi: 0
registers.eax: 2
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0
exception.symbol: qdialoginsertobject+0x21e9
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8681
exception.address: 0x100021e9
registers.esp: 1638276
registers.edi: 0
registers.eax: 2
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00
exception.symbol: qdialoginsertobject+0x21eb
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8683
exception.address: 0x100021eb
registers.esp: 1638276
registers.edi: 0
registers.eax: 3
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00 00
exception.symbol: qdialoginsertobject+0x21ec
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8684
exception.address: 0x100021ec
registers.esp: 1638276
registers.edi: 0
registers.eax: 3
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9
exception.symbol: qdialoginsertobject+0x21e8
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8680
exception.address: 0x100021e8
registers.esp: 1638276
registers.edi: 0
registers.eax: 3
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0
exception.symbol: qdialoginsertobject+0x21e9
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8681
exception.address: 0x100021e9
registers.esp: 1638276
registers.edi: 0
registers.eax: 3
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00
exception.symbol: qdialoginsertobject+0x21eb
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8683
exception.address: 0x100021eb
registers.esp: 1638276
registers.edi: 0
registers.eax: 4
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00 00
exception.symbol: qdialoginsertobject+0x21ec
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8684
exception.address: 0x100021ec
registers.esp: 1638276
registers.edi: 0
registers.eax: 4
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9
exception.symbol: qdialoginsertobject+0x21e8
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8680
exception.address: 0x100021e8
registers.esp: 1638276
registers.edi: 0
registers.eax: 4
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0
exception.symbol: qdialoginsertobject+0x21e9
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8681
exception.address: 0x100021e9
registers.esp: 1638276
registers.edi: 0
registers.eax: 4
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00
exception.symbol: qdialoginsertobject+0x21eb
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8683
exception.address: 0x100021eb
registers.esp: 1638276
registers.edi: 0
registers.eax: 5
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00 00
exception.symbol: qdialoginsertobject+0x21ec
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8684
exception.address: 0x100021ec
registers.esp: 1638276
registers.edi: 0
registers.eax: 5
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9
exception.symbol: qdialoginsertobject+0x21e8
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8680
exception.address: 0x100021e8
registers.esp: 1638276
registers.edi: 0
registers.eax: 5
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0
exception.symbol: qdialoginsertobject+0x21e9
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8681
exception.address: 0x100021e9
registers.esp: 1638276
registers.edi: 0
registers.eax: 5
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00
exception.symbol: qdialoginsertobject+0x21eb
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8683
exception.address: 0x100021eb
registers.esp: 1638276
registers.edi: 0
registers.eax: 6
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00 00
exception.symbol: qdialoginsertobject+0x21ec
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8684
exception.address: 0x100021ec
registers.esp: 1638276
registers.edi: 0
registers.eax: 6
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9
exception.symbol: qdialoginsertobject+0x21e8
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8680
exception.address: 0x100021e8
registers.esp: 1638276
registers.edi: 0
registers.eax: 6
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0
exception.symbol: qdialoginsertobject+0x21e9
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8681
exception.address: 0x100021e9
registers.esp: 1638276
registers.edi: 0
registers.eax: 6
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00
exception.symbol: qdialoginsertobject+0x21eb
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8683
exception.address: 0x100021eb
registers.esp: 1638276
registers.edi: 0
registers.eax: 7
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00 00
exception.symbol: qdialoginsertobject+0x21ec
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8684
exception.address: 0x100021ec
registers.esp: 1638276
registers.edi: 0
registers.eax: 7
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9
exception.symbol: qdialoginsertobject+0x21e8
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8680
exception.address: 0x100021e8
registers.esp: 1638276
registers.edi: 0
registers.eax: 7
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0
exception.symbol: qdialoginsertobject+0x21e9
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8681
exception.address: 0x100021e9
registers.esp: 1638276
registers.edi: 0
registers.eax: 7
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00
exception.symbol: qdialoginsertobject+0x21eb
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8683
exception.address: 0x100021eb
registers.esp: 1638276
registers.edi: 0
registers.eax: 8
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00 00
exception.symbol: qdialoginsertobject+0x21ec
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8684
exception.address: 0x100021ec
registers.esp: 1638276
registers.edi: 0
registers.eax: 8
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9
exception.symbol: qdialoginsertobject+0x21e8
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8680
exception.address: 0x100021e8
registers.esp: 1638276
registers.edi: 0
registers.eax: 8
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0
exception.symbol: qdialoginsertobject+0x21e9
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8681
exception.address: 0x100021e9
registers.esp: 1638276
registers.edi: 0
registers.eax: 8
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00
exception.symbol: qdialoginsertobject+0x21eb
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8683
exception.address: 0x100021eb
registers.esp: 1638276
registers.edi: 0
registers.eax: 9
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00 00
exception.symbol: qdialoginsertobject+0x21ec
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8684
exception.address: 0x100021ec
registers.esp: 1638276
registers.edi: 0
registers.eax: 9
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9
exception.symbol: qdialoginsertobject+0x21e8
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8680
exception.address: 0x100021e8
registers.esp: 1638276
registers.edi: 0
registers.eax: 9
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0
exception.symbol: qdialoginsertobject+0x21e9
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8681
exception.address: 0x100021e9
registers.esp: 1638276
registers.edi: 0
registers.eax: 9
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00
exception.symbol: qdialoginsertobject+0x21eb
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8683
exception.address: 0x100021eb
registers.esp: 1638276
registers.edi: 0
registers.eax: 10
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00 00
exception.symbol: qdialoginsertobject+0x21ec
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8684
exception.address: 0x100021ec
registers.esp: 1638276
registers.edi: 0
registers.eax: 10
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9
exception.symbol: qdialoginsertobject+0x21e8
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8680
exception.address: 0x100021e8
registers.esp: 1638276
registers.edi: 0
registers.eax: 10
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0
exception.symbol: qdialoginsertobject+0x21e9
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8681
exception.address: 0x100021e9
registers.esp: 1638276
registers.edi: 0
registers.eax: 10
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00
exception.symbol: qdialoginsertobject+0x21eb
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8683
exception.address: 0x100021eb
registers.esp: 1638276
registers.edi: 0
registers.eax: 11
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00 00
exception.symbol: qdialoginsertobject+0x21ec
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8684
exception.address: 0x100021ec
registers.esp: 1638276
registers.edi: 0
registers.eax: 11
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9
exception.symbol: qdialoginsertobject+0x21e8
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8680
exception.address: 0x100021e8
registers.esp: 1638276
registers.edi: 0
registers.eax: 11
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0
exception.symbol: qdialoginsertobject+0x21e9
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8681
exception.address: 0x100021e9
registers.esp: 1638276
registers.edi: 0
registers.eax: 11
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00
exception.symbol: qdialoginsertobject+0x21eb
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8683
exception.address: 0x100021eb
registers.esp: 1638276
registers.edi: 0
registers.eax: 12
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc eb f2 58 64 a3 00 00 00 00 58 e9 b0 4a 00 00
exception.symbol: qdialoginsertobject+0x21ec
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8684
exception.address: 0x100021ec
registers.esp: 1638276
registers.edi: 0
registers.eax: 12
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9
exception.symbol: qdialoginsertobject+0x21e8
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8680
exception.address: 0x100021e8
registers.esp: 1638276
registers.edi: 0
registers.eax: 12
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77799ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77799ea5

exception.instruction_r: cc 40 cc cc eb f2 58 64 a3 00 00 00 00 58 e9 b0
exception.symbol: qdialoginsertobject+0x21e9
exception.instruction: int3
exception.module: qDialogInsertObject.exe
exception.exception_code: 0x80000003
exception.offset: 8681
exception.address: 0x100021e9
registers.esp: 1638276
registers.edi: 0
registers.eax: 12
registers.ebp: 1638292
registers.edx: 1637888
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 1638068
1 0 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2472
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6bc17000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2472
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6b8b3000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2472
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x059c9000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2472
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x059c9000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2620
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73bf2000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2620
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6b8b3000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2760
region_size: 24576
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00680000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
file C:\ProgramData\qDialogInsertObject.exe
cmdline mshta "C:\ProgramData\qSmartTagControlActiveX.sct"
parent_process excel.exe martian_process mshta "C:\ProgramData\qSmartTagControlActiveX.sct"
Time & API Arguments Status Return Repeated

__anomaly__

tid: 2764
message: Encountered 65537 exceptions, quitting.
subcategory: exception
function_name:
1 0 0
Elastic malicious (high confidence)
Arcabit VBA.Heur2.Dridex.2.1C723EC4.Gen
Symantec W97M.Downloader
Avast SNH:Script [Dropper]
ClamAV Doc.Dropper.MSHTA-6966166-0
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender VBA.Heur2.Dridex.2.1C723EC4.Gen
NANO-Antivirus Trojan.Ole2.Vbs-heuristic.druvzi
MicroWorld-eScan VBA.Heur2.Dridex.2.1C723EC4.Gen
Ad-Aware VBA.Heur2.Dridex.2.1C723EC4.Gen
DrWeb Exploit.Siggen3.18816
McAfee-GW-Edition BehavesLike.OLE2.Downloader.bb
FireEye VBA.Heur2.Dridex.2.1C723EC4.Gen
Emsisoft VBA.Heur2.Dridex.2.1C723EC4.Gen (B)
Microsoft TrojanDownloader:O97M/Dridex.PSTT!MTB
GData VBA.Heur2.Dridex.2.1C723EC4.Gen
TACHYON Suspicious/X97M.Dropper.Gen
ALYac VBA.Heur2.Dridex.2.1C723EC4.Gen
MAX malware (ai score=86)
SentinelOne Static AI - Suspicious OLE
AVG SNH:Script [Dropper]