File name:

RF083209.xls

Full analysis: https://app.any.run/tasks/dd22b40c-a2f2-4e0e-af81-89c075186259
Verdict: Malicious activity
Analysis date: February 27, 2024, 20:06:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
phishing
phishing-xls
MIME: application/vnd.ms-excel
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 00:00:00 2006, Last Saved Time/Date: Tue Feb 27 06:15:35 2024, Security: 1
MD5:

E58465CAFFA9C59B66CBD7F103EFCF4E

SHA1:

E256B7C4D8310C13DA7E56740F635EF935B6898B

SHA256:

11E070F1B5265A29906D455F5E9AD3ACB4C2283E091C821FD31599E9C034937F

SSDEEP:

12288:rQTLM75/vKHILRgcjyQ+uapFuJ2++Bo/bIPGp8XRJ7g:0Tg75/vKHILScjyQ+uapFuJ2++BWbIP0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Phishing has been detected

      • EXCEL.EXE (PID: 3700)
    • Connection from MS Office application

      • EXCEL.EXE (PID: 3700)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads the computer name

      • wmpnscfg.exe (PID: 3212)
    • Checks supported languages

      • wmpnscfg.exe (PID: 3212)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3212)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xls | Microsoft Excel sheet (48)
.xls | Microsoft Excel sheet (alternate) (39.2)

EXIF

FlashPix

Title: -
Subject: -
Keywords: -
Comments: -
Template: -
RevisionNumber: 1
Pages: -
Words: -
Characters: -
ThumbnailClip: (Binary data 22858 bytes, use -b option to extract)
Category: -
PresentationTarget: -
Manager: -
Company: -
Bytes: -
Lines: -
Paragraphs: -
Slides: -
Notes: -
HiddenSlides: -
MMClips: -
CharCountWithSpaces: -
KSOProductBuildVer: 2052-11.1.0.13703
ICV: C30860BF318046A5BA3C67275852A6D2
Author: -
LastModifiedBy: -
Software: Microsoft Excel
CreateDate: 2006:09:16 00:00:00
ModifyDate: 2024:02:27 06:15:35
Security: Password protected
CodePage: Windows Latin 1 (Western European)
AppVersion: 12
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts:
  • Sheet1
  • Sheet2
  • Sheet3
HeadingPairs:
  • Worksheets
  • 3
CompObjUserTypeLen: 38
CompObjUserType: Microsoft Office Excel 2003 Worksheet
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start excel.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3212"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3700"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\excel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
4 698
Read events
4 486
Write events
72
Delete events
140

Modification events

(PID) Process:(3700) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
Operation:writeName:qm'
Value:
716D2700740E0000010000000000000000000000
(PID) Process:(3700) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(3700) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
Off
(PID) Process:(3700) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
Off
(PID) Process:(3700) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
Off
(PID) Process:(3700) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
Off
(PID) Process:(3700) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
Off
(PID) Process:(3700) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
Off
(PID) Process:(3700) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
Off
(PID) Process:(3700) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
Off
Executable files
1
Suspicious files
5
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3700EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVRF9D1.tmp.cvr
MD5:
SHA256:
3700EXCEL.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dattext
MD5:28A2E262752DEF13D4E2C7153ABDBEFE
SHA256:F87BD83B043273A0D400A7B2B122BDE3FE55BBD2A0D1518C5F0BCB0DCD37D99E
3700EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B2BA0AD6.emfemf
MD5:106F9A3162A2FEB3253CE60B96CF9C24
SHA256:7DA10AA1A57F5CEA9348A782C5B2FB62A7608518D0D5AEB513BA86F2091E1F2C
3700EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\42A9D0DF.emfemf
MD5:483AE6C6365079806FD873C25CFC1596
SHA256:D7E1766D155BA0D2358E470BC40187E0DC37FAE52A4496AFB933D23758B3B7F3
3700EXCEL.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\RF083209.xls.LNKlnk
MD5:5C9CB0F0AE2B9FE81D8A61EF8D3D86FF
SHA256:5EBD86191FE7B2FE2B3F7DCAAA9907EF18F930BC01DADD912A7072BADCCB303C
3700EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\719F7554.emfemf
MD5:9ABE7EB352E0DB96B52C99AC2FDEA85F
SHA256:EC022DFF1CC8251BA9D849C16431914635473FC5457AE73AA277651B47948869
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3700
EXCEL.EXE
GET
404
172.67.204.84:80
http://shtu.be/4adfc0
unknown
xml
341 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3700
EXCEL.EXE
172.67.204.84:80
shtu.be
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
shtu.be
  • 172.67.204.84
  • 104.21.69.44
unknown

Threats

No threats detected
No debug info