File name:

xongrid-4-win32-win64.zip

Full analysis: https://app.any.run/tasks/8b623307-f21f-4c07-9f04-c0b60d547d68
Verdict: Suspicious activity
Analysis date: May 15, 2019, 21:02:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
macros-on-close
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

86D56DCA057589EFB15E74C01EBD66A7

SHA1:

07A9150E50AE12DC2F416508011C713ED4DBF8B3

SHA256:

5A0DDD0F9471E696BD85531972CBD3595F4977A0F3AB1134557E5CDA540916D8

SSDEEP:

49152:34CSuNhz8Nv+aOUS5VOQ1hlbOEhH50k9sd4R1rz9fRKBkryv:3jaO9LOQrIk9s2pfSkY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3456)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 3456)
    • Reads Microsoft Office registry keys

      • EXCEL.EXE (PID: 2732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2013:07:17 12:44:07
ZipCRC: 0xc594b24e
ZipCompressedSize: 24635
ZipUncompressedSize: 119808
ZipFileName: Example-1D.xls
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe excel.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2732"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\excel.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3456"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\xongrid-4-win32-win64.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
1 735
Read events
1 575
Write events
153
Delete events
7

Modification events

(PID) Process:(3456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3456) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\xongrid-4-win32-win64.zip
(PID) Process:(3456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3456) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
(PID) Process:(3456) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@C:\Windows\System32\hhctrl.ocx,-452
Value:
Compiled HTML Help file
Executable files
2
Suspicious files
9
Text files
2
Unknown types
6

Dropped files

PID
Process
Filename
Type
2732EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR8CB7.tmp.cvr
MD5:
SHA256:
2732EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DFE12598866E6EACC8.TMP
MD5:
SHA256:
2732EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DFB24B390EEDD74203.TMP
MD5:
SHA256:
2732EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\msoEBB.tmp
MD5:
SHA256:
2732EXCEL.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\msoEDB.tmp
MD5:
SHA256:
3456WinRAR.exeC:\Users\admin\AppData\Local\Temp\xongrid-4-win32-win64\Example-4D.xlsdocument
MD5:B531374560179034C4C9BD38D6E6FF53
SHA256:4BF670C62AE429F8A53F452D98C829AE09B962202D427BC478F1006F9CD7AEEB
3456WinRAR.exeC:\Users\admin\AppData\Local\Temp\xongrid-4-win32-win64\Example-3D.xlsdocument
MD5:D5064DA722026BDA4A4EA76367CEFC49
SHA256:BD69D5FB8616CC3F38E465041A998985F4067C1620FEA01433364D0213EE75CF
3456WinRAR.exeC:\Users\admin\AppData\Local\Temp\xongrid-4-win32-win64\Example-2D.xlsdocument
MD5:FF78E1A51516420A71368584D92AB461
SHA256:E1705352E8198905E46794A751B753F17C9DDA9D8556670280E52828D9A2FCF9
3456WinRAR.exeC:\Users\admin\AppData\Local\Temp\xongrid-4-win32-win64\README.txttext
MD5:18EA69B60F5E9D3DD5095F26B41D854B
SHA256:9E57C8EDBBB1A668258C7D53D7680C9EDF2BAD981A636C4EF3A65DCE26A0CBBD
3456WinRAR.exeC:\Users\admin\AppData\Local\Temp\xongrid-4-win32-win64\Example-1D.xlsdocument
MD5:ADA9A6423818FB1CA806C3EEF261AA46
SHA256:D016D09FA7B60C395BD44B7D63CA3011D8AF58827521FDC9B28A896DA83420DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info