| File name: | notif144.xls |
| Full analysis: | https://app.any.run/tasks/631fea80-81c4-40fd-9a78-9ee1faad054e |
| Verdict: | Malicious activity |
| Analysis date: | November 30, 2020, 02:41:44 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.ms-excel |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: IIN, Last Saved By: Administrator, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Nov 27 10:29:15 2020, Last Saved Time/Date: Fri Nov 27 10:29:16 2020, Security: 0 |
| MD5: | 6618DF3D647E0D9191AC1DE4D5B44AFE |
| SHA1: | BE8E64C7281068FD20948FC6F1575F33073106CC |
| SHA256: | 54DFD7C37002E776AAEC020611C1C81A2283D40852DF7A2C110B361E4D186AC7 |
| SSDEEP: | 768:gPqNk3hbdlylKsgqopeJBWhZFGkE+cL2NdAJ4KRuwSyeIhhRC1QEN:sok3hbdlylKsgqopeJBWhZFGkE+cL2NF |
| .xls | | | Microsoft Excel sheet (78.9) |
|---|
| Author: | IIN |
|---|---|
| LastModifiedBy: | Administrator |
| Software: | Microsoft Excel |
| CreateDate: | 2020:11:27 10:29:15 |
| ModifyDate: | 2020:11:27 10:29:16 |
| Security: | None |
| CodePage: | Windows Latin 1 (Western European) |
| Company: | - |
| AppVersion: | 16 |
| ScaleCrop: | No |
| LinksUpToDate: | No |
| SharedDoc: | No |
| HyperlinksChanged: | No |
| TitleOfParts: |
|
| HeadingPairs: |
|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2308 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 3300 | "C:\Windows\system32\rundll32.exe" C:\Users\Public\Documents\ndggM.txt,DllRegisterServer | C:\Windows\system32\rundll32.exe | — | EXCEL.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
| Operation: | write | Name: | zk; |
Value: 7A6B3B0004090000010000000000000000000000 | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1041 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1046 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1036 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1031 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1040 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1049 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 3082 |
Value: Off | |||
| (PID) Process: | (2308) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1042 |
Value: Off | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2308 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR777A.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2308 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CabAE4A.tmp | — | |
MD5:— | SHA256:— | |||
| 2308 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\TarAE4B.tmp | — | |
MD5:— | SHA256:— | |||
| 2308 | EXCEL.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\L9B4NOHT.txt | — | |
MD5:— | SHA256:— | |||
| 2308 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DFF0AF838107213B26.TMP | — | |
MD5:— | SHA256:— | |||
| 2308 | EXCEL.EXE | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9FF67FB3141440EED32363089565AE60_DA1C5B5BE91A874E22473EBE4563D7DB | der | |
MD5:— | SHA256:— | |||
| 2308 | EXCEL.EXE | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\82CB34DD3343FE727DF8890D352E0D8F | der | |
MD5:— | SHA256:— | |||
| 2308 | EXCEL.EXE | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9FF67FB3141440EED32363089565AE60_DA1C5B5BE91A874E22473EBE4563D7DB | binary | |
MD5:— | SHA256:— | |||
| 2308 | EXCEL.EXE | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\82CB34DD3343FE727DF8890D352E0D8F | binary | |
MD5:— | SHA256:— | |||
| 2308 | EXCEL.EXE | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CC197601BE0898B7B0FCC91FA15D8A69_00822B812F3071D0A5AB02FB7D4F1DF9 | der | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2308 | EXCEL.EXE | GET | 200 | 93.184.220.29:80 | http://crl3.digicert.com/Omniroot2025.crl | US | der | 7.30 Kb | whitelisted |
2308 | EXCEL.EXE | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQS14tALDViBvqCf47YkiQRtKz1BAQUpc436uuwdQ6UZ4i0RfrZJBCHlh8CEAcex4mrpL%2FoZUo5uhzD27g%3D | US | der | 278 b | whitelisted |
2308 | EXCEL.EXE | GET | 200 | 172.217.18.3:80 | http://ocsp.pki.goog/gts1o1core/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDliVAU%2F6ZWzwIAAAAAgFX%2B | US | der | 472 b | whitelisted |
2308 | EXCEL.EXE | GET | 200 | 172.217.18.3:80 | http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D | US | der | 468 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2308 | EXCEL.EXE | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2308 | EXCEL.EXE | 172.67.222.45:443 | advertlyasia.com | — | US | unknown |
2308 | EXCEL.EXE | 172.217.21.196:443 | www.google.com | Google Inc. | US | whitelisted |
2308 | EXCEL.EXE | 172.217.18.3:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
advertlyasia.com |
| unknown |
ocsp.digicert.com |
| whitelisted |
crl3.digicert.com |
| whitelisted |
www.google.com |
| malicious |
ocsp.pki.goog |
| whitelisted |