| File name: | attach#8108-18-03-2024.xlsx |
| Full analysis: | https://app.any.run/tasks/9a32f41b-fb9c-4791-bc93-819f6edc7dbc |
| Verdict: | Malicious activity |
| Analysis date: | March 18, 2024, 19:12:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/vnd.openxmlformats-officedocument.spreadsheetml.sheet |
| File info: | Microsoft Excel 2007+ |
| MD5: | A80C60F9C6BAA6F18555D670DA539F46 |
| SHA1: | F8BA3E9F73978FC623EF5D8A922208C43FAD2D9A |
| SHA256: | 15B3ACCF9B2E23A76DAA98A524807CE8F3D14D141A4898CD6F626E5751638067 |
| SSDEEP: | 1536:dQYvyAaANsave4O+Nv/FI0iHw0YjwHk9Ulg/QQU:dQYsAv4+Nv/FIa0Yjt97YP |
| .xlsx | | | Excel Microsoft Office Open XML Format document (61.2) |
|---|---|---|
| .zip | | | Open Packaging Conventions container (31.5) |
| .zip | | | ZIP compressed archive (7.2) |
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0006 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 1980:01:01 00:00:00 |
| ZipCRC: | 0xfa08cdcc |
| ZipCompressedSize: | 361 |
| ZipUncompressedSize: | 1202 |
| ZipFileName: | [Content_Types].xml |
| Application: | Microsoft Excel |
|---|---|
| DocSecurity: | None |
| ScaleCrop: | No |
| HeadingPairs: |
|
| TitlesOfParts: | Sheet1 |
| Company: | - |
| LinksUpToDate: | No |
| SharedDoc: | No |
| HyperlinksChanged: | No |
| AppVersion: | 16.03 |
| LastModifiedBy: | admin |
| CreateDate: | 2015:06:05 18:17:20Z |
| ModifyDate: | 2024:03:18 15:45:49Z |
| Creator: | egofyymv |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1164 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1560 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3500 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| (PID) Process: | (1164) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0 |
| Operation: | write | Name: | CheckSetting |
Value: 01000000D08C9DDF0115D1118C7A00C04FC297EB01000000FFCE8581E02E0545BA732230B3DFAACE00000000020000000000106600000001000020000000A62BB6483B6FA300FA23E6114165E6227F1543BE3725F8674CB844C29900D7DA000000000E800000000200002000000084C5382B5444011F5165AF8F87D6E84C194A286BFAD53A1081C40F3D07510FF1300000001F882AFD13B7DC64345708A69C7D53A3709C413126E77B6A92651D91D8675E1F5351D681168D2B2E136F340C717C252D400000005D72C47A5C00CA72E085F28C30607BDCC1470A02C57A8CF3DC69B203E1932526A976837B95861F24505033DBB962E245873424516A0B44FCBFC83B554A9D1099 | |||
| (PID) Process: | (3500) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
| Operation: | write | Name: | ,m |
Value: 2C6D2000AC0D0000010000000000000000000000 | |||
| (PID) Process: | (3500) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (3500) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1041 |
Value: Off | |||
| (PID) Process: | (3500) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1046 |
Value: Off | |||
| (PID) Process: | (3500) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1036 |
Value: Off | |||
| (PID) Process: | (3500) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1031 |
Value: Off | |||
| (PID) Process: | (3500) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1040 |
Value: Off | |||
| (PID) Process: | (3500) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1049 |
Value: Off | |||
| (PID) Process: | (3500) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 3082 |
Value: Off | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3500 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR21AC.tmp.cvr | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1164 | explorer.exe | OPTIONS | — | 143.198.197.14:80 | http://143.198.197.14/ | unknown | — | — | unknown |
1164 | explorer.exe | OPTIONS | — | 143.198.197.14:80 | http://143.198.197.14/ | unknown | — | — | unknown |
1164 | explorer.exe | OPTIONS | — | 143.198.197.14:80 | http://143.198.197.14/ | unknown | — | — | unknown |
1164 | explorer.exe | OPTIONS | — | 143.198.197.14:80 | http://143.198.197.14/ | unknown | — | — | unknown |
1164 | explorer.exe | OPTIONS | — | 143.198.197.14:80 | http://143.198.197.14/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 143.198.197.14:445 | — | DIGITALOCEAN-ASN | SG | unknown |
4 | System | 143.198.197.14:139 | — | DIGITALOCEAN-ASN | SG | unknown |
1164 | explorer.exe | 143.198.197.14:80 | — | DIGITALOCEAN-ASN | SG | unknown |
Domain | IP | Reputation |
|---|---|---|
dns.msftncsi.com |
| shared |