| File name: | RF083209.xls |
| Full analysis: | https://app.any.run/tasks/dd22b40c-a2f2-4e0e-af81-89c075186259 |
| Verdict: | Malicious activity |
| Analysis date: | February 27, 2024, 20:06:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| MIME: | application/vnd.ms-excel |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 00:00:00 2006, Last Saved Time/Date: Tue Feb 27 06:15:35 2024, Security: 1 |
| MD5: | E58465CAFFA9C59B66CBD7F103EFCF4E |
| SHA1: | E256B7C4D8310C13DA7E56740F635EF935B6898B |
| SHA256: | 11E070F1B5265A29906D455F5E9AD3ACB4C2283E091C821FD31599E9C034937F |
| SSDEEP: | 12288:rQTLM75/vKHILRgcjyQ+uapFuJ2++Bo/bIPGp8XRJ7g:0Tg75/vKHILScjyQ+uapFuJ2++BWbIP0 |
| .xls | | | Microsoft Excel sheet (48) |
|---|---|---|
| .xls | | | Microsoft Excel sheet (alternate) (39.2) |
| Title: | - |
|---|---|
| Subject: | - |
| Keywords: | - |
| Comments: | - |
| Template: | - |
| RevisionNumber: | 1 |
| Pages: | - |
| Words: | - |
| Characters: | - |
| ThumbnailClip: | (Binary data 22858 bytes, use -b option to extract) |
| Category: | - |
| PresentationTarget: | - |
| Manager: | - |
| Company: | - |
| Bytes: | - |
| Lines: | - |
| Paragraphs: | - |
| Slides: | - |
| Notes: | - |
| HiddenSlides: | - |
| MMClips: | - |
| CharCountWithSpaces: | - |
| KSOProductBuildVer: | 2052-11.1.0.13703 |
| ICV: | C30860BF318046A5BA3C67275852A6D2 |
| Author: | - |
| LastModifiedBy: | - |
| Software: | Microsoft Excel |
| CreateDate: | 2006:09:16 00:00:00 |
| ModifyDate: | 2024:02:27 06:15:35 |
| Security: | Password protected |
| CodePage: | Windows Latin 1 (Western European) |
| AppVersion: | 12 |
| ScaleCrop: | No |
| LinksUpToDate: | No |
| SharedDoc: | No |
| HyperlinksChanged: | No |
| TitleOfParts: |
|
| HeadingPairs: |
|
| CompObjUserTypeLen: | 38 |
| CompObjUserType: | Microsoft Office Excel 2003 Worksheet |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3212 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3700 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| (PID) Process: | (3700) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
| Operation: | write | Name: | qm' |
Value: 716D2700740E0000010000000000000000000000 | |||
| (PID) Process: | (3700) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (3700) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1041 |
Value: Off | |||
| (PID) Process: | (3700) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1046 |
Value: Off | |||
| (PID) Process: | (3700) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1036 |
Value: Off | |||
| (PID) Process: | (3700) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1031 |
Value: Off | |||
| (PID) Process: | (3700) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1040 |
Value: Off | |||
| (PID) Process: | (3700) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1049 |
Value: Off | |||
| (PID) Process: | (3700) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 3082 |
Value: Off | |||
| (PID) Process: | (3700) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1042 |
Value: Off | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3700 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVRF9D1.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3700 | EXCEL.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat | text | |
MD5:28A2E262752DEF13D4E2C7153ABDBEFE | SHA256:F87BD83B043273A0D400A7B2B122BDE3FE55BBD2A0D1518C5F0BCB0DCD37D99E | |||
| 3700 | EXCEL.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B2BA0AD6.emf | emf | |
MD5:106F9A3162A2FEB3253CE60B96CF9C24 | SHA256:7DA10AA1A57F5CEA9348A782C5B2FB62A7608518D0D5AEB513BA86F2091E1F2C | |||
| 3700 | EXCEL.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\42A9D0DF.emf | emf | |
MD5:483AE6C6365079806FD873C25CFC1596 | SHA256:D7E1766D155BA0D2358E470BC40187E0DC37FAE52A4496AFB933D23758B3B7F3 | |||
| 3700 | EXCEL.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\RF083209.xls.LNK | lnk | |
MD5:5C9CB0F0AE2B9FE81D8A61EF8D3D86FF | SHA256:5EBD86191FE7B2FE2B3F7DCAAA9907EF18F930BC01DADD912A7072BADCCB303C | |||
| 3700 | EXCEL.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\719F7554.emf | emf | |
MD5:9ABE7EB352E0DB96B52C99AC2FDEA85F | SHA256:EC022DFF1CC8251BA9D849C16431914635473FC5457AE73AA277651B47948869 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3700 | EXCEL.EXE | GET | 404 | 172.67.204.84:80 | http://shtu.be/4adfc0 | unknown | xml | 341 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3700 | EXCEL.EXE | 172.67.204.84:80 | shtu.be | CLOUDFLARENET | US | unknown |
Domain | IP | Reputation |
|---|---|---|
shtu.be |
| unknown |