| File name: | fun.xls.exe |
| Full analysis: | https://app.any.run/tasks/c01281cc-58fc-429d-8f12-19e49a03f974 |
| Verdict: | Malicious activity |
| Analysis date: | November 22, 2023, 16:52:22 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 24279B569C7F301460E0C092C80F0919 |
| SHA1: | EA45E9655A260869ED6778223BDB88182A241397 |
| SHA256: | 6752376C0E3E56D65AD86F1FA377987C9E666E76BBE0E78328FAB86091C621FB |
| SSDEEP: | 1536:yzzgpYDI0hxfnFcwlp1bs4U4X48Dbq0rUCQLU3xT4Wr5qeo2SW3GilXeTD8jeP2t:yvg+DI0hxfnFcwlp1bs4U4X48Dbq0rdb |
| .exe | | | Win32 Executable Microsoft Visual Basic 6 (90.6) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (4.9) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2006:10:27 11:35:28+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 36864 |
| InitializedDataSize: | 8192 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1a0c |
| OSVersion: | 4 |
| ImageVersion: | 2 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.0.0 |
| ProductVersionNumber: | 2.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | Microsoft Corp. |
| ProductName: | FireWall Files |
| FileVersion: | 2 |
| ProductVersion: | 2 |
| InternalName: | msfun80 |
| OriginalFileName: | msfun80.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2116 | explorer C:\ | C:\Windows\explorer.exe | — | fun.xls.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3384 | "C:\Users\admin\AppData\Local\Temp\fun.xls.exe" | C:\Users\admin\AppData\Local\Temp\fun.xls.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corp. Integrity Level: MEDIUM Exit code: 0 Version: 2.00 Modules
| |||||||||||||||
| 3432 | C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | C:\Windows\explorer.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3440 | explorer C:\ | C:\Windows\explorer.exe | — | fun.xls.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3648 | "C:\Users\admin\Desktop\fun.xls.exe" | C:\Users\admin\Desktop\fun.xls.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corp. Integrity Level: HIGH Exit code: 0 Version: 2.00 Modules
| |||||||||||||||
| 3700 | C:\Windows\system32\algsrvs.exe | C:\Windows\System32\algsrvs.exe | — | fun.xls.exe | |||||||||||
User: admin Company: Microsoft Corp. Integrity Level: HIGH Exit code: 0 Version: 2.00 Modules
| |||||||||||||||
| 3736 | explorer C:\ | C:\Windows\explorer.exe | — | fun.xls.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3808 | C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | C:\Windows\explorer.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3988 | "C:\Users\admin\Desktop\fun.xls.exe" | C:\Users\admin\Desktop\fun.xls.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corp. Integrity Level: MEDIUM Exit code: 0 Version: 2.00 Modules
| |||||||||||||||
| 3992 | C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | C:\Windows\explorer.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3432) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | NodeSlots |
Value: 02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 | |||
| (PID) Process: | (3432) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | MRUListEx |
Value: 01000000020000000700000000000000060000000C0000000B0000000D0000000A0000000900000008000000030000000500000004000000FFFFFFFF | |||
| (PID) Process: | (3432) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar |
| Operation: | write | Name: | Locked |
Value: 1 | |||
| (PID) Process: | (3432) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\34\Shell |
| Operation: | write | Name: | SniffedFolderType |
Value: Generic | |||
| (PID) Process: | (3432) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3432) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3432) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3432) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3432) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3432) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell |
| Operation: | write | Name: | NavBar |
Value: 000000000000000000000000000000008B000000870000003153505305D5CDD59C2E1B10939708002B2CF9AE6B0000005A000000007B00360044003800420042003300440033002D0039004400380037002D0034004100390031002D0041004200350036002D003400460033003000430046004600450046004500390046007D005F0057006900640074006800000013000000F00000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3988 | fun.xls.exe | C:\Users\admin\AppData\Local\Temp\~DFDD7F98D3211A9036.TMP | binary | |
MD5:7AB995158FF3A13E2CA87320504C518D | SHA256:442A1C2019A9CBB801456187E981BC3E2A68B4FE7D1334C6B5DA9AD1B574E0BF | |||
| 3648 | fun.xls.exe | C:\Windows\system32\algsrvs.exe | executable | |
MD5:24279B569C7F301460E0C092C80F0919 | SHA256:6752376C0E3E56D65AD86F1FA377987C9E666E76BBE0E78328FAB86091C621FB | |||
| 3700 | algsrvs.exe | C:\AUTORUN.INF | text | |
MD5:9FC696C9F3D3B80A4093375F229100A9 | SHA256:7DABAFEAC737D4DEADA7878CEBF42050D2664966B3EE0B28A5DD3CCAD9D0C88C | |||
| 3700 | algsrvs.exe | C:\fun.xls.exe | executable | |
MD5:24279B569C7F301460E0C092C80F0919 | SHA256:6752376C0E3E56D65AD86F1FA377987C9E666E76BBE0E78328FAB86091C621FB | |||
| 3384 | fun.xls.exe | C:\Users\admin\AppData\Local\Temp\~DFBDF787F8A577E705.TMP | binary | |
MD5:56C7CEAC8428C6F43EE1493C3E41EEE8 | SHA256:57A3A3914A8ECE689F6F716DE3FD185D75DFFBF916F3DA5341063C334F7DF9EB | |||
| 3648 | fun.xls.exe | C:\Windows\system32\msime82.exe | executable | |
MD5:24279B569C7F301460E0C092C80F0919 | SHA256:6752376C0E3E56D65AD86F1FA377987C9E666E76BBE0E78328FAB86091C621FB | |||
| 3648 | fun.xls.exe | C:\Users\admin\AppData\Local\Temp\~DF9BA41850EC2BBE74.TMP | binary | |
MD5:57D8AAE309079F691AD88C408E21D715 | SHA256:CD5D7B3005CDD22D6C7BD56CE4EA06E3433C1BCBFD479CD7D0491A4B0935F84D | |||
| 3648 | fun.xls.exe | C:\Windows\system32\msfun80.exe | executable | |
MD5:24279B569C7F301460E0C092C80F0919 | SHA256:6752376C0E3E56D65AD86F1FA377987C9E666E76BBE0E78328FAB86091C621FB | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |