| File name: | Tax_List1.accde |
| Full analysis: | https://app.any.run/tasks/c5122046-3edf-4037-9300-0eaf51563eb1 |
| Verdict: | Malicious activity |
| Analysis date: | August 14, 2024, 15:39:29 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-msaccess |
| File info: | Microsoft Access Database |
| MD5: | 44BA348E73305929239883508FA0380A |
| SHA1: | 7AB2D08EF52D443ACDBD2BC0C754145C83F7B587 |
| SHA256: | 615727E8ED031CA82AE1799893D7B42831F3ED86A1DBC5B4F654D2B5646808B5 |
| SSDEEP: | 1536:UDrxFe+7/PqoFXJdfNrFzmzwxRqZtk6E3or6YF1RiJDjyBJtqByJOqxInPbdM9dp:U/r7/PqoFXJhxFzf3uB8qxokZ |
| .accdb | | | Microsoft Access 2007 Database (90.4) |
|---|---|---|
| .pi2 | | | DEGAS med-res bitmap (9.5) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1568 | "C:\Wintows\KbUpdate.exe" | C:\Wintows\KbUpdate.exe | MSACCESS.EXE | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 2324 | schtasks /create /tn "WindowsUpdate" /tr "cmd" /sc daily /st 15:00 /f | C:\Windows\System32\schtasks.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5052 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | KbUpdate.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5484 | schtasks /create /tn "OneDrive" /tr "cmd" /sc daily /st 09:30 /f | C:\Windows\System32\schtasks.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6236 | schtasks /create /tn "Skype" /tr "cmd" /sc daily /st 12:00 /f | C:\Windows\System32\schtasks.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6632 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6640 | cmd.exe /c " schtasks /create /tn "OneDrive" /tr "cmd" /sc daily /st 09:30 /f && schtasks /create /tn "Skype" /tr "cmd" /sc daily /st 12:00 /f && schtasks /create /tn "WindowsUpdate" /tr "cmd" /sc daily /st 15:00 /f" | C:\Windows\System32\cmd.exe | — | KbUpdate.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6716 | "C:\Program Files\Microsoft Office\Root\Office16\MSACCESS.EXE" /NOSTARTUP C:\Users\admin\AppData\Local\Temp\Tax_List1.accde %2 %3 %4 %5 %6 %7 %8 %9 | C:\Program Files\Microsoft Office\root\Office16\MSACCESS.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Access Version: 16.0.16026.20146 Modules
| |||||||||||||||
| (PID) Process: | (6716) MSACCESS.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\ClientTelemetry\Sampling |
| Operation: | write | Name: | 2 |
Value: 01600E000000001000B24E9A3E01000000000000000200000000000000 | |||
| (PID) Process: | (6716) MSACCESS.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\MSACCESS\6716 |
| Operation: | write | Name: | 0 |
Value: 0B0E10E678BB3F54ADB24BAD9B90B53786451D230046DFB583E382CCBBED016A04102400449A7D64B29D01008500A907556E6B6E6F776EC9062E223733476255664B62784F56664E70753657616837594A2F4D45484154685631664A6E64643072694C4A67493D22CA0DC2190000C91003783634C511BC34D2120C6D0073006100630063006500730073002E00650078006500C51620C517808004C91808323231322D44656300 | |||
| (PID) Process: | (6716) MSACCESS.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | en-US |
Value: 2 | |||
| (PID) Process: | (6716) MSACCESS.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | de-de |
Value: 2 | |||
| (PID) Process: | (6716) MSACCESS.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | fr-fr |
Value: 2 | |||
| (PID) Process: | (6716) MSACCESS.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | es-es |
Value: 2 | |||
| (PID) Process: | (6716) MSACCESS.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | it-it |
Value: 2 | |||
| (PID) Process: | (6716) MSACCESS.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | ja-jp |
Value: 2 | |||
| (PID) Process: | (6716) MSACCESS.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | ko-kr |
Value: 2 | |||
| (PID) Process: | (6716) MSACCESS.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | pt-br |
Value: 2 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6716 | MSACCESS.EXE | C:\Users\admin\AppData\Local\Temp\Tax_List1.accde | accdb | |
MD5:8EEE3218860EF512FC25330A64B59D74 | SHA256:8662A76D708220D5E38F8435176DB4AE2801498FD2D3EF4914EDE24F05809947 | |||
| 6716 | MSACCESS.EXE | C:\Wintows\KbUpdate.exe | executable | |
MD5:12FD9100E372806C878C33F109CEED7C | SHA256:54D3F21009ACDE870817CD42597447786F7C728183FA16966BDEEBB1BC3C87E5 | |||
| 6716 | MSACCESS.EXE | C:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbres | binary | |
MD5:1DB52622988223A9D13A1F3A68C1F0F4 | SHA256:D00DDEDF43E4F53DC2A4646D89219C6353F0EFB957BFB92D1A0DAF939E963535 | |||
| 6716 | MSACCESS.EXE | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A | der | |
MD5:42FB97C861FB0400877CF26CB6FB41F2 | SHA256:B030F6DA934B9EA1C5829C326E4991F7183C550263B3722FF9B61CFA238E8772 | |||
| 6716 | MSACCESS.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\319f01bf9fe00f2d.customDestinations-ms | binary | |
MD5:E4A1661C2C886EBB688DEC494532431C | SHA256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5 | |||
| 6716 | MSACCESS.EXE | C:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbres | binary | |
MD5:269A81A91936EBA081334B24C626496F | SHA256:53FA07DF908297699F527AA39FED43F8BFC0790B11841124E326629724B61997 | |||
| 6716 | MSACCESS.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LA853LEIK0OUWG72DXTR.temp | binary | |
MD5:E4A1661C2C886EBB688DEC494532431C | SHA256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5 | |||
| 6716 | MSACCESS.EXE | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A | binary | |
MD5:A5B7ECE31C9E6A509FA37F32F98A3493 | SHA256:4CA7A0C7E78A4E31B0CD2675CEA954AF7305D19A6751AA3276212ADA06600035 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6716 | MSACCESS.EXE | GET | 200 | 192.229.211.108:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3140 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4324 | svchost.exe | 52.167.17.97:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
6716 | MSACCESS.EXE | 52.113.194.132:443 | ecs.office.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3140 | svchost.exe | 52.167.17.97:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
1568 | KbUpdate.exe | 185.227.82.65:8080 | — | Access2.IT Group B.V. | NL | unknown |
6716 | MSACCESS.EXE | 104.208.16.95:443 | self.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
6716 | MSACCESS.EXE | 192.229.211.108:80 | ocsp.digicert.com | EDGECAST | US | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
ecs.office.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |