File name:

Kutools for Excel 21.00.zip

Full analysis: https://app.any.run/tasks/79c498dc-fb67-423f-b955-6786f5080205
Verdict: Malicious activity
Analysis date: April 10, 2020, 15:50:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

8858454AF40BE21876D4EC5885FBE68B

SHA1:

700F6EB649AEB1BA9A2C572CFD92A629A25FEE80

SHA256:

120D070C386766FBBB77B21A412AD6E33B029592F5D881FF9EE6668EA7F4B943

SSDEEP:

12288:RsbAHQocAiiYYSZVhyGA0aOkEiphuha1A1o9RIRAkIiNGa0mc/i80:REaiamVhyrtOyf4a1uRAkTg/i1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Kutools for Excel 21.00.exe (PID: 912)
      • Kutools for Excel 21.00.exe (PID: 1136)
      • sysinfo.exe (PID: 3032)
    • Uses Task Scheduler to run other applications

      • sysinfo.exe (PID: 3032)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 3800)
      • schtasks.exe (PID: 1928)
    • Actions looks like stealing of personal data

      • explorer.exe (PID: 3196)
  • SUSPICIOUS

    • Reads Windows owner or organization settings

      • Kutools for Excel 21.00.tmp (PID: 2612)
    • Executable content was dropped or overwritten

      • Kutools for Excel 21.00.exe (PID: 912)
      • Kutools for Excel 21.00.tmp (PID: 2612)
      • 7za.exe (PID: 856)
      • Kutools for Excel 21.00.exe (PID: 1136)
    • Reads the Windows organization settings

      • Kutools for Excel 21.00.tmp (PID: 2612)
    • Creates files in the user directory

      • Kutools for Excel 21.00.tmp (PID: 2612)
      • sysinfo.exe (PID: 3032)
    • Executed via COM

      • explorer.exe (PID: 3196)
  • INFO

    • Application was dropped or rewritten from another process

      • Kutools for Excel 21.00.tmp (PID: 3076)
      • Kutools for Excel 21.00.tmp (PID: 2612)
      • 7za.exe (PID: 856)
      • 7za.exe (PID: 3772)
      • 7za.exe (PID: 3860)
    • Manual execution by user

      • Kutools for Excel 21.00.exe (PID: 1136)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2020:04:10 18:46:21
ZipCRC: 0xf92aa080
ZipCompressedSize: 697364
ZipUncompressedSize: 771230
ZipFileName: Kutools for Excel 21.00.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
14
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start winrar.exe no specs kutools for excel 21.00.exe kutools for excel 21.00.tmp no specs kutools for excel 21.00.exe kutools for excel 21.00.tmp 7za.exe no specs 7za.exe 7za.exe no specs sysinfo.exe no specs schtasks.exe no specs schtasks.exe no specs explorer.exe no specs explorer.exe notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
440"explorer.exe" "C:\Users\admin\Desktop\Kutools for Excel 21.00"C:\Windows\explorer.exeKutools for Excel 21.00.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
856"C:\Users\admin\AppData\Local\Temp\is-8T70C.tmp\7za.exe" x "C:\Users\admin\AppData\Local\Temp\is-8T70C.tmp\form.res" -p"b1lig@n_vl"C:\Users\admin\AppData\Local\Temp\is-8T70C.tmp\7za.exe
Kutools for Excel 21.00.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
4.65
Modules
Images
c:\users\admin\appdata\local\temp\is-8t70c.tmp\7za.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
912"C:\Users\admin\Desktop\Kutools for Excel 21.00.exe" /SPAWNWND=$701C2 /NOTIFYWND=$701E0 C:\Users\admin\Desktop\Kutools for Excel 21.00.exe
Kutools for Excel 21.00.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
4.9
Modules
Images
c:\users\admin\desktop\kutools for excel 21.00.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1136"C:\Users\admin\Desktop\Kutools for Excel 21.00.exe" C:\Users\admin\Desktop\Kutools for Excel 21.00.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
4.9
Modules
Images
c:\users\admin\desktop\kutools for excel 21.00.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1780"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Kutools for Excel 21.00\license.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1928"C:\Windows\system32\schtasks.exe" /Delete /tn "Microsoft\Windows\Windows Error Reporting\SystemInfo" /fC:\Windows\system32\schtasks.exesysinfo.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2612"C:\Users\admin\AppData\Local\Temp\is-755KJ.tmp\Kutools for Excel 21.00.tmp" /SL5="$901E8,369076,121344,C:\Users\admin\Desktop\Kutools for Excel 21.00.exe" /SPAWNWND=$701C2 /NOTIFYWND=$701E0 C:\Users\admin\AppData\Local\Temp\is-755KJ.tmp\Kutools for Excel 21.00.tmp
Kutools for Excel 21.00.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-755kj.tmp\kutools for excel 21.00.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3032"C:\Users\admin\AppData\Roaming\SystemDiag\sysinfo.exe" -cr -tu 8C:\Users\admin\AppData\Roaming\SystemDiag\sysinfo.exeKutools for Excel 21.00.tmp
User:
admin
Integrity Level:
HIGH
Description:
System Info Tool Lite
Exit code:
0
Version:
1.0.51.2
Modules
Images
c:\users\admin\appdata\roaming\systemdiag\sysinfo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3076"C:\Users\admin\AppData\Local\Temp\is-KQJ05.tmp\Kutools for Excel 21.00.tmp" /SL5="$701E0,369076,121344,C:\Users\admin\Desktop\Kutools for Excel 21.00.exe" C:\Users\admin\AppData\Local\Temp\is-KQJ05.tmp\Kutools for Excel 21.00.tmpKutools for Excel 21.00.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-kqj05.tmp\kutools for excel 21.00.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3196C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
1 225
Read events
1 120
Write events
105
Delete events
0

Modification events

(PID) Process:(3484) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3484) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3484) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3484) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Kutools for Excel 21.00.zip
(PID) Process:(3484) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3484) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3484) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3484) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3484) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(2612) Kutools for Excel 21.00.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
340A0000924BBCD44F0FD601
Executable files
5
Suspicious files
3
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
3484WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3484.18187\Kutools for Excel 21.00.exe
MD5:
SHA256:
2612Kutools for Excel 21.00.tmpC:\Users\admin\AppData\Local\Temp\{87C839E9-883D-48EB-B78B-FAE90103C456}\is-TF6J2.tmp
MD5:
SHA256:
2612Kutools for Excel 21.00.tmpC:\Users\admin\AppData\Local\Temp\{87C839E9-883D-48EB-B78B-FAE90103C456}\license.txt
MD5:
SHA256:
2612Kutools for Excel 21.00.tmpC:\Users\admin\AppData\Local\Temp\is-8T70C.tmp\misc.rescompressed
MD5:
SHA256:
2612Kutools for Excel 21.00.tmpC:\Users\admin\AppData\Local\Temp\is-8T70C.tmp\form.rescompressed
MD5:
SHA256:
37727za.exeC:\Users\admin\AppData\Local\Temp\is-8T70C.tmp\misc.xmlxml
MD5:
SHA256:
2612Kutools for Excel 21.00.tmpC:\Users\admin\Desktop\Kutools for Excel 21.00\license.txttext
MD5:
SHA256:
912Kutools for Excel 21.00.exeC:\Users\admin\AppData\Local\Temp\is-755KJ.tmp\Kutools for Excel 21.00.tmpexecutable
MD5:34ACC2BDB45A9C436181426828C4CB49
SHA256:9C81817ACD4982632D8C7F1DF3898FCA1477577738184265D735F49FC5480F07
38607za.exeC:\Users\admin\AppData\Local\Temp\is-8T70C.tmp\sub.xmlxml
MD5:C047508A4A1F583B7ED31EC7B0DF9695
SHA256:CD999BAA036D44D442FE43A541D69F04BA206C58938F3C22EC0F226493C63E35
3032sysinfo.exeC:\Users\admin\AppData\Roaming\SystemDiag\data.xmlxml
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2612
Kutools for Excel 21.00.tmp
POST
200
216.58.208.46:80
http://www.google-analytics.com/collect
US
image
35 b
whitelisted
2612
Kutools for Excel 21.00.tmp
GET
200
104.28.31.94:80
http://video-box.org/getchannel
US
binary
1 b
malicious
2612
Kutools for Excel 21.00.tmp
POST
200
216.58.208.46:80
http://www.google-analytics.com/collect
US
image
35 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2612
Kutools for Excel 21.00.tmp
216.58.208.46:80
www.google-analytics.com
Google Inc.
US
whitelisted
2612
Kutools for Excel 21.00.tmp
104.28.31.94:80
video-box.org
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
www.google-analytics.com
  • 216.58.208.46
whitelisted
video-box.org
  • 104.28.31.94
  • 104.28.30.94
malicious

Threats

No threats detected
No debug info