File name:

form.7z

Full analysis: https://app.any.run/tasks/cc4715ed-cbcd-4267-85bd-f743309e7625
Verdict: Malicious activity
Analysis date: November 28, 2023, 05:05:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

9B1A27347947E01DA73BE780CE0C420C

SHA1:

262520A6E5F68D1063080B7916D5C1A434107599

SHA256:

0EF057FA1AA8BE3935056CBF94B4A5822D705525DA49E1239D4F25E9B635413B

SSDEEP:

1536:UOiAkSeMcMALr98Tk5zCOwhAbkXQGyBqBoHkQB7IXzxPPAG9UCQT2S/iqOH:THcak5zhrAXWyoHkQhIxHUCm2SRc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Calls Win API functions (MACROS)

      • EXCEL.EXE (PID: 1064)
    • Connection from MS Office application

      • EXCEL.EXE (PID: 1064)
    • Registers / Runs the DLL via REGSVR32.EXE

      • EXCEL.EXE (PID: 1064)
    • Unusual execution from MS Office

      • EXCEL.EXE (PID: 1064)
  • SUSPICIOUS

    • Connects to the server without a host name

      • EXCEL.EXE (PID: 1064)
  • INFO

    • Manual execution by a user

      • notepad++.exe (PID: 2948)
      • WinRAR.exe (PID: 3008)
      • EXCEL.EXE (PID: 1064)
      • wmpnscfg.exe (PID: 3084)
    • Checks supported languages

      • wmpnscfg.exe (PID: 3084)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3084)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
8
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe no specs notepad++.exe excel.exe regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
888"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\form.7z"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1064"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\excel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2764regsvr32 -silent ..\Drezd.red2C:\Windows\System32\regsvr32.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2948"C:\Program Files\Notepad++\notepad++.exe" "C:\Users\admin\Desktop\ad.bat"C:\Program Files\Notepad++\notepad++.exe
explorer.exe
User:
admin
Company:
Don HO don.h@free.fr
Integrity Level:
MEDIUM
Description:
Notepad++ : a free (GNU) source code editor
Exit code:
0
Version:
7.91
Modules
Images
c:\program files\notepad++\notepad++.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2996regsvr32 -silent ..\Drezd.red1C:\Windows\System32\regsvr32.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3008"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\form.7z" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3084"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3112regsvr32 -silent ..\Drezd.redC:\Windows\System32\regsvr32.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 390
Read events
2 293
Write events
83
Delete events
14

Modification events

(PID) Process:(888) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(888) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
1
Suspicious files
6
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
1064EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR4A98.tmp.cvr
MD5:
SHA256:
3008WinRAR.exeC:\Users\admin\Desktop\ad.battext
MD5:D868A643D42E435700806D981F597B97
SHA256:3D831D5ABD52E5E067458EA9F4D2B09449DBB35A682EF09DD6CA553F94C96A42
1064EXCEL.EXEC:\Users\admin\AppData\Local\Temp\VBE\MSForms.exdbinary
MD5:365160A04F55E9ECC0EEA98E88A889BA
SHA256:FB35764DFCE813DA6E53DA091CDB233FA68A6FE20EF0C35A1F9B81192BE75185
2948notepad++.exeC:\Users\admin\AppData\Roaming\Notepad++\config.xmlxml
MD5:75DAF0C838CA0F9DAA89D4074A504E1B
SHA256:97901B6DEF410AA997B0E91A0FD0947EB3A26B7D5C83FD7228FDE04F981AC53C
3008WinRAR.exeC:\Users\admin\Desktop\form_1484004552-07142023.xlsdocument
MD5:F9191123817870609289C3F9F8D4C3C5
SHA256:D659B116029F90C571D42944DE0383ED2F25F5B7E9EA60C3CBA545E2672F814D
1064EXCEL.EXEC:\Users\admin\AppData\Local\Temp\VBE\RefEdit.exdbinary
MD5:A1D64ED7C353C940074C20610E10766A
SHA256:12F2F6D75D54F1F533E085AC24C496AAD24CC2CDC40EEB187CFDD773F3901550
1064EXCEL.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\form_1484004552-07142023.xls.LNKbinary
MD5:FC73D55526787A61E4115D77884AACA0
SHA256:703D643F115568C30547CD6386D066F07184BFC3FDB13FDECE935DB6CAC825B8
1064EXCEL.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dattext
MD5:AE02B526EAE05CF05087707C5310B0E9
SHA256:BFD591DC4704EDFF7C59F37771C4A9E9E8EAEE9A6A8E63DF4BF4ABEEA1618E84
3008WinRAR.exeC:\Users\admin\Desktop\readme.lnkbinary
MD5:C868EE195D4AE11EE09C9EA0EC5F4A6D
SHA256:B42631A7F7D7BA47934FCB7CB78EF4DECD7F1BB960C5669C85EBD69D7E2BD8CF
2948notepad++.exeC:\Users\admin\AppData\Roaming\Notepad++\session.xmltext
MD5:D9F133F8A343F5ECBD4BB53578C9076A
SHA256:6540FDC6B6D2C3E93D760559E48B1AFD6A6A1A75E66D6B57AEF869C45601CC22
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
8
DNS requests
0
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1064
EXCEL.EXE
GET
502
190.14.37.241:80
http://190.14.37.241/45258.2131856482.dat
unknown
html
552 b
unknown
1064
EXCEL.EXE
GET
404
111.90.151.238:80
http://111.90.151.238/45258.2131856482.dat
unknown
html
260 b
unknown
1064
EXCEL.EXE
GET
404
84.32.188.11:80
http://84.32.188.11/45258.2131856482.dat
unknown
html
167 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
1064
EXCEL.EXE
190.14.37.241:80
Offshore Racks S.A
PA
unknown
1064
EXCEL.EXE
111.90.151.238:80
Shinjiru Technology Sdn Bhd
MY
unknown
1064
EXCEL.EXE
84.32.188.11:80
UAB Cherry Servers
LT
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\plugins\Config\nppPluginList.dll
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3