analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

INVOICE 1132918.xlsx

Full analysis: https://app.any.run/tasks/24e92384-21b5-493e-9154-ecaed8688dec
Verdict: Malicious activity
Analysis date: July 17, 2019, 14:08:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
generated-doc
exploit
CVE-2017-11882
Indicators:
MIME: application/octet-stream
File info: Microsoft OOXML
MD5:

E76D9026CE8629FF9281924C4A9B0722

SHA1:

CF053F1F524812A0DDF52C94340E56158843A43E

SHA256:

58423FA6D95615991E5C47F6366DBBFEF3C439D82DF140BDC99527C8314345FC

SSDEEP:

192:EQn9Y3d/X+eQ9FGuLI3RnLpFI30KXAb5x7+fKYgk/H:Eu9Y39ujJI35I30KXE5x7+fKYgUH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Equation Editor starts application (CVE-2017-11882)

      • EQNEDT32.EXE (PID: 2720)
  • SUSPICIOUS

    • Executed via COM

      • EQNEDT32.EXE (PID: 2720)
    • Executes application which crashes

      • EQNEDT32.EXE (PID: 2720)
    • Creates files in the user directory

      • EQNEDT32.EXE (PID: 2720)
  • INFO

    • Reads Microsoft Office registry keys

      • EXCEL.EXE (PID: 2840)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xlsx | Excel Microsoft Office Open XML Format document (61.2)
.zip | Open Packaging Conventions container (31.5)
.zip | ZIP compressed archive (7.2)

EXIF

XMP

Creator: xx

XML

ModifyDate: 2006:09:16 00:00:00Z
CreateDate: 2006:09:16 00:00:00Z
AppVersion: 14.03
HyperlinksChanged: No
SharedDoc: No
LinksUpToDate: No
Company: -
TitlesOfParts: Sheet1
HeadingPairs:
  • Worksheets
  • 1
ScaleCrop: No
DocSecurity: None
Application: Microsoft Excel

ZIP

ZipFileName: [Content_Types].xml
ZipUncompressedSize: 1396
ZipCompressedSize: 373
ZipCRC: 0xb0fb548e
ZipModifyDate: 2019:07:16 11:18:20
ZipCompression: Deflated
ZipBitFlag: 0x0002
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start excel.exe no specs eqnedt32.exe ntvdm.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2840"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Version:
14.0.6024.1000
2720"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -EmbeddingC:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
svchost.exe
User:
admin
Company:
Design Science, Inc.
Integrity Level:
MEDIUM
Description:
Microsoft Equation Editor
Exit code:
0
Version:
00110900
2296"C:\Windows\system32\ntvdm.exe" -i1 C:\Windows\system32\ntvdm.exeEQNEDT32.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
NTVDM.EXE
Exit code:
255
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
630
Read events
574
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2840EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVRE8BC.tmp.cvr
MD5:
SHA256:
2296ntvdm.exeC:\Users\admin\AppData\Local\Temp\scsF4E1.tmp
MD5:
SHA256:
2296ntvdm.exeC:\Users\admin\AppData\Local\Temp\scsF4E2.tmp
MD5:
SHA256:
2720EQNEDT32.EXEC:\Users\admin\AppData\Roaming\gtesyayjuf.exehtml
MD5:9978C46FFCEC12E3B8A2186C0DDC5D82
SHA256:7B0DE07078291716D9E26C3F4CF7C0CDDF406B8EE34AF679AB8B8DC7CCA74727
2720EQNEDT32.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\UCE[1].htmhtml
MD5:9978C46FFCEC12E3B8A2186C0DDC5D82
SHA256:7B0DE07078291716D9E26C3F4CF7C0CDDF406B8EE34AF679AB8B8DC7CCA74727
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2720
EQNEDT32.EXE
50.87.115.208:443
bonbonii.com
Unified Layer
US
malicious

DNS requests

Domain
IP
Reputation
bonbonii.com
  • 50.87.115.208
malicious

Threats

No threats detected
No debug info