File name: | Bill Payment_000010818.xls |
Full analysis: | https://app.any.run/tasks/20424d37-5079-4c27-bb07-6639876064d5 |
Verdict: | Malicious activity |
Analysis date: | December 13, 2023, 10:43:13 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
MIME: | application/vnd.ms-excel |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1251, Author: 1, Last Saved By: Microsoft Office, Name of Creating Application: Microsoft Excel, Create Time/Date: Thu Jul 30 06:24:02 2015, Last Saved Time/Date: Fri Nov 6 10:41:03 2015, Security: 0 |
MD5: | 6C21A09C80E076EC5B60B7415135AE7A |
SHA1: | CD375C9BB413FE187783B508588359AA3E9DCBA4 |
SHA256: | 5BE589570751F4D8EAD65EC9CE502637464568ECA45F35DCA61A195E6CB35F90 |
SSDEEP: | 1536:t4dvxHlcaQPy0iWYOcG4BDhnxDV8ixSrx0wfd9EI8H0g:t4dvxHlcaAy0iWYOcG4BDhnxDV8ixSSR |
.xls | | | Microsoft Excel sheet (78.9) |
---|
CompObjUserType: | ???? Microsoft Office Excel |
---|---|
CompObjUserTypeLen: | 28 |
HeadingPairs: |
|
TitleOfParts: |
|
HyperlinksChanged: | No |
SharedDoc: | No |
LinksUpToDate: | No |
ScaleCrop: | No |
AppVersion: | 11.9999 |
CodePage: | Windows Cyrillic |
Security: | None |
ModifyDate: | 2015:11:06 10:41:03 |
CreateDate: | 2015:07:30 05:24:02 |
Software: | Microsoft Excel |
LastModifiedBy: | Microsoft Office |
Author: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1864 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 Modules
|
(PID) Process: | (1864) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1033 |
Value: On | |||
(PID) Process: | (1864) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1041 |
Value: On | |||
(PID) Process: | (1864) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1046 |
Value: On | |||
(PID) Process: | (1864) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1036 |
Value: On | |||
(PID) Process: | (1864) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1031 |
Value: On | |||
(PID) Process: | (1864) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1040 |
Value: On | |||
(PID) Process: | (1864) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1049 |
Value: On | |||
(PID) Process: | (1864) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 3082 |
Value: On | |||
(PID) Process: | (1864) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1042 |
Value: On | |||
(PID) Process: | (1864) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1055 |
Value: On |
PID | Process | Filename | Type | |
---|---|---|---|---|
1864 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR8C.tmp.cvr | — | |
MD5:— | SHA256:— | |||
1864 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\Bill Payment_000010818.xls | document | |
MD5:0DBEBB33C8BBED5B9F5B931160816165 | SHA256:F1F6262C24D5FF31C903A815C3CDFC28FE90B47239ED3DBC37E826977616C1D5 | |||
1864 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF6951F48D6F25635F.TMP | binary | |
MD5:463F08DCFE2B29D8A92639789EFA348A | SHA256:B588A79684BC08A289DA9A49A115891E9C5FB3AA070E4AF6FD84F42E39131052 | |||
1864 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF53FADA9A6CE32A1B.TMP | binary | |
MD5:ABE9FBDF1427FA5C43C3CBD3F307A986 | SHA256:96B97DD72845C1F4E1F6D998774715148AD7C9CED543EE115D5F27B3DB59B17C |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
Domain | IP | Reputation |
---|---|---|
advancedgroup.net.au |
| unknown |