File name: | invoice-42369643.xlsm |
Full analysis: | https://app.any.run/tasks/2c07759b-3296-4a84-b3da-f91c96b6b3c9 |
Verdict: | Malicious activity |
Analysis date: | October 04, 2022, 19:55:02 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.openxmlformats-officedocument.spreadsheetml.sheet |
File info: | Microsoft Excel 2007+ |
MD5: | B54C993E941836BF2C9C69948B30BCF0 |
SHA1: | A3E6234B5310A3918B9E01C08BADF3EB5F44A4B8 |
SHA256: | 3861795ECE849D6B417A3C9870A7E0A0ECCD27F74E706B9242D94D5E8885B705 |
SSDEEP: | 768:YLsShCAVaV5WqShv3H4+jbXAAQpyQyAtewZP8a88ULsR6LQkZt5mZ2:YbhCLVkqStYuQgrCl38896LbZt5mQ |
.xlsm | | | Excel Microsoft Office Open XML Format document (with Macro) (29.2) |
---|---|---|
.xlsx | | | Excel Microsoft Office Open XML Format document (17.3) |
.zip | | | Open Packaging Conventions container (8.9) |
.zip | | | ZIP compressed archive (2) |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
1124 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | Explorer.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Version: 14.0.6024.1000 | ||||
1084 | mshta C:\Users\admin\AppData\Local\Temp\LwTHLrGh.hta | C:\Windows\system32\mshta.exe | — | EXCEL.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft (R) HTML Application host Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) |
PID | Process | Filename | Type | |
---|---|---|---|---|
1124 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR98E5.tmp.cvr | — | |
MD5:— | SHA256:— | |||
1124 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\VBE\MSForms.exd | tlb | |
MD5:7D730C137E5D39EDCEE6B2B5E60669A2 | SHA256:187DBC41DBC91270086ACE004D889E51B31229FC194889ECE165B2D5E4A1C203 | |||
1124 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\LwTHLrGh.hta | html | |
MD5:084149C0FC6722B43B42EBC96F22EFFE | SHA256:8D74853D271EC7A12880C4E33591DF212628E3CB6A2F4038ADAD28C4B6891A96 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 192.168.100.2:53 | — | — | — | whitelisted |
Domain | IP | Reputation |
---|---|---|
www.microsoft.com |
| whitelisted |