File name: | e68fcd845683be392885de766f158a1c6b00cea57bdd68b5ff44d54e62400e1f.zip |
Full analysis: | https://app.any.run/tasks/4bbd60cc-35f3-449e-8023-66ce958241be |
Verdict: | Malicious activity |
Analysis date: | January 24, 2022, 15:38:46 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v5.1 to extract |
MD5: | 9D6F277E7F90A5B67F4D6DEB56F15DAA |
SHA1: | D1F97B078DCBEE9EA39F1BB171E768FB573F21A6 |
SHA256: | 18B99BBD5DB40BFC3B5655989D7F53A2F646F0877FC38272E959B0C0B99EBBA4 |
SSDEEP: | 384:nQpmX/+gmnZCl1jjDbogQtRbzA/PbuufsNURzcXhehBnepC46j7Wbpini73:nImvkrRtB4FFPh5eJ6j7WgS3 |
.zip | | | ZIP compressed archive (100) |
---|
ZipFileName: | e68fcd845683be392885de766f158a1c6b00cea57bdd68b5ff44d54e62400e1f.xls |
---|---|
ZipUncompressedSize: | 51200 |
ZipCompressedSize: | 24571 |
ZipCRC: | 0x951501f8 |
ZipModifyDate: | 2022:01:24 15:38:18 |
ZipCompression: | Unknown (99) |
ZipBitFlag: | 0x0003 |
ZipRequiredVersion: | 51 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3220 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\e68fcd845683be392885de766f158a1c6b00cea57bdd68b5ff44d54e62400e1f.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | Explorer.EXE |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 | ||||
2696 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | Explorer.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 | ||||
1020 | "C:\Program Files\Microsoft Office\Office14\CLVIEW.EXE" "EXCEL" "Microsoft Excel" | C:\Program Files\Microsoft Office\Office14\CLVIEW.EXE | — | EXCEL.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Help Viewer Exit code: 0 Version: 14.0.6015.1000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2696 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVRE893.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2696 | EXCEL.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat | ini | |
MD5:E40DC9078D6B7A57DFB24D49625F8CFA | SHA256:D1713B7E12A8544C8E5D9C57A0F5D1627E84A2919EC918D10F38E9A2C0061285 | |||
3220 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3220.38810\e68fcd845683be392885de766f158a1c6b00cea57bdd68b5ff44d54e62400e1f.xls | document | |
MD5:4E8EC74A93B831A92A1B016722E79365 | SHA256:E68FCD845683BE392885DE766F158A1C6B00CEA57BDD68B5FF44D54E62400E1F | |||
1020 | CLVIEW.EXE | C:\Users\admin\AppData\Local\Temp\IMT3883.tmp | binary | |
MD5:669884C6C1DEC7F6CD03B442E4101692 | SHA256:4447990DB2D42D9DDDA248FF34910A751F77BE3E88B0789672D92BE89B22453F | |||
1020 | CLVIEW.EXE | C:\Users\admin\AppData\Local\Microsoft Help\MS.EXCEL.14.1033_1033_MTOC_EXCEL_COL.HxH | binary | |
MD5:41859B6D703FC3CB5974B8469E641F91 | SHA256:D8759E93651398921103C4BE8909013D6D70F637FA45C844AC3F80FA1EF9A850 | |||
2696 | EXCEL.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\e68fcd845683be392885de766f158a1c6b00cea57bdd68b5ff44d54e62400e1f.xls.LNK | lnk | |
MD5:117C03A9E86F367029377E2A10448DB8 | SHA256:B93654EAC82FBA89645375A720F9DEA3F1B9DB191F07CEF25BF366FB7CA7C725 | |||
1020 | CLVIEW.EXE | C:\Users\admin\AppData\Local\Temp\IMT3882.tmp | binary | |
MD5:77CF07B5075A3B3D6491E1D85A46090F | SHA256:2A4706758F22E2078630AD4334D9FA3946041AACD876E5226E8C8C07D7CE0C7E | |||
1020 | CLVIEW.EXE | C:\Users\admin\AppData\Local\Temp\IMT386D.tmp | binary | |
MD5:7E8B24EECB300B45B19F534EFF40AD54 | SHA256:DAA96DDB007D4387E35263890F76F3CE91EE276D6AE85B0BBF1D9BCB97FCF85B | |||
1020 | CLVIEW.EXE | C:\Users\admin\AppData\Local\Temp\IMT385A.tmp | binary | |
MD5:73E5F16AA352D7188E7266C6C20EAAF1 | SHA256:57408D0184C465A18379CAAF84030C6835B480BC644804F5670A02B985E84A0C | |||
1020 | CLVIEW.EXE | C:\Users\admin\AppData\Local\Temp\IMT386B.tmp | binary | |
MD5:4BE2AEDDA24E0539C95564B48CA9D8BA | SHA256:E4D153F74AC21D4212A83FE030EE7A407B5FDFE2D3A8145F3E826532BD796893 |