File name:

fun.xls.exe

Full analysis: https://app.any.run/tasks/c01281cc-58fc-429d-8f12-19e49a03f974
Verdict: Malicious activity
Analysis date: November 22, 2023, 16:52:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

24279B569C7F301460E0C092C80F0919

SHA1:

EA45E9655A260869ED6778223BDB88182A241397

SHA256:

6752376C0E3E56D65AD86F1FA377987C9E666E76BBE0E78328FAB86091C621FB

SSDEEP:

1536:yzzgpYDI0hxfnFcwlp1bs4U4X48Dbq0rUCQLU3xT4Wr5qeo2SW3GilXeTD8jeP2t:yvg+DI0hxfnFcwlp1bs4U4X48Dbq0rdb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file in the system directory

      • fun.xls.exe (PID: 3648)
    • Drops the executable file immediately after the start

      • fun.xls.exe (PID: 3648)
      • algsrvs.exe (PID: 3700)
    • Changes appearance of the Explorer extensions

      • algsrvs.exe (PID: 3700)
  • SUSPICIOUS

    • Starts itself from another location

      • fun.xls.exe (PID: 3648)
  • INFO

    • Create files in a temporary directory

      • fun.xls.exe (PID: 3384)
      • fun.xls.exe (PID: 3988)
      • algsrvs.exe (PID: 3700)
      • fun.xls.exe (PID: 3648)
    • Reads the Internet Settings

      • explorer.exe (PID: 3432)
      • explorer.exe (PID: 3808)
      • explorer.exe (PID: 3992)
    • Reads the machine GUID from the registry

      • fun.xls.exe (PID: 3384)
      • algsrvs.exe (PID: 3700)
      • fun.xls.exe (PID: 3648)
      • fun.xls.exe (PID: 3988)
    • Checks supported languages

      • fun.xls.exe (PID: 3384)
      • fun.xls.exe (PID: 3988)
      • algsrvs.exe (PID: 3700)
      • fun.xls.exe (PID: 3648)
    • Manual execution by a user

      • fun.xls.exe (PID: 3988)
      • fun.xls.exe (PID: 3648)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Microsoft Visual Basic 6 (90.6)
.exe | Win32 Executable (generic) (4.9)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2006:10:27 11:35:28+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 36864
InitializedDataSize: 8192
UninitializedDataSize: -
EntryPoint: 0x1a0c
OSVersion: 4
ImageVersion: 2
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.0
ProductVersionNumber: 2.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: Microsoft Corp.
ProductName: FireWall Files
FileVersion: 2
ProductVersion: 2
InternalName: msfun80
OriginalFileName: msfun80.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
10
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fun.xls.exe no specs explorer.exe no specs explorer.exe no specs fun.xls.exe no specs explorer.exe no specs explorer.exe no specs fun.xls.exe algsrvs.exe no specs explorer.exe no specs explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2116explorer C:\C:\Windows\explorer.exefun.xls.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3384"C:\Users\admin\AppData\Local\Temp\fun.xls.exe" C:\Users\admin\AppData\Local\Temp\fun.xls.exeexplorer.exe
User:
admin
Company:
Microsoft Corp.
Integrity Level:
MEDIUM
Exit code:
0
Version:
2.00
Modules
Images
c:\users\admin\appdata\local\temp\fun.xls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3432C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3440explorer C:\C:\Windows\explorer.exefun.xls.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3648"C:\Users\admin\Desktop\fun.xls.exe" C:\Users\admin\Desktop\fun.xls.exe
explorer.exe
User:
admin
Company:
Microsoft Corp.
Integrity Level:
HIGH
Exit code:
0
Version:
2.00
Modules
Images
c:\users\admin\desktop\fun.xls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3700C:\Windows\system32\algsrvs.exeC:\Windows\System32\algsrvs.exefun.xls.exe
User:
admin
Company:
Microsoft Corp.
Integrity Level:
HIGH
Exit code:
0
Version:
2.00
Modules
Images
c:\windows\system32\algsrvs.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3736explorer C:\C:\Windows\explorer.exefun.xls.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3808C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3988"C:\Users\admin\Desktop\fun.xls.exe" C:\Users\admin\Desktop\fun.xls.exeexplorer.exe
User:
admin
Company:
Microsoft Corp.
Integrity Level:
MEDIUM
Exit code:
0
Version:
2.00
Modules
Images
c:\users\admin\desktop\fun.xls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3992C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
13 753
Read events
13 561
Write events
192
Delete events
0

Modification events

(PID) Process:(3432) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(3432) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
01000000020000000700000000000000060000000C0000000B0000000D0000000A0000000900000008000000030000000500000004000000FFFFFFFF
(PID) Process:(3432) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar
Operation:writeName:Locked
Value:
1
(PID) Process:(3432) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\34\Shell
Operation:writeName:SniffedFolderType
Value:
Generic
(PID) Process:(3432) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3432) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3432) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3432) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3432) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3432) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
Operation:writeName:NavBar
Value:
000000000000000000000000000000008B000000870000003153505305D5CDD59C2E1B10939708002B2CF9AE6B0000005A000000007B00360044003800420042003300440033002D0039004400380037002D0034004100390031002D0041004200350036002D003400460033003000430046004600450046004500390046007D005F0057006900640074006800000013000000F00000000000000000000000
Executable files
5
Suspicious files
3
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3988fun.xls.exeC:\Users\admin\AppData\Local\Temp\~DFDD7F98D3211A9036.TMPbinary
MD5:7AB995158FF3A13E2CA87320504C518D
SHA256:442A1C2019A9CBB801456187E981BC3E2A68B4FE7D1334C6B5DA9AD1B574E0BF
3648fun.xls.exeC:\Windows\system32\algsrvs.exeexecutable
MD5:24279B569C7F301460E0C092C80F0919
SHA256:6752376C0E3E56D65AD86F1FA377987C9E666E76BBE0E78328FAB86091C621FB
3700algsrvs.exeC:\AUTORUN.INFtext
MD5:9FC696C9F3D3B80A4093375F229100A9
SHA256:7DABAFEAC737D4DEADA7878CEBF42050D2664966B3EE0B28A5DD3CCAD9D0C88C
3700algsrvs.exeC:\fun.xls.exeexecutable
MD5:24279B569C7F301460E0C092C80F0919
SHA256:6752376C0E3E56D65AD86F1FA377987C9E666E76BBE0E78328FAB86091C621FB
3384fun.xls.exeC:\Users\admin\AppData\Local\Temp\~DFBDF787F8A577E705.TMPbinary
MD5:56C7CEAC8428C6F43EE1493C3E41EEE8
SHA256:57A3A3914A8ECE689F6F716DE3FD185D75DFFBF916F3DA5341063C334F7DF9EB
3648fun.xls.exeC:\Windows\system32\msime82.exeexecutable
MD5:24279B569C7F301460E0C092C80F0919
SHA256:6752376C0E3E56D65AD86F1FA377987C9E666E76BBE0E78328FAB86091C621FB
3648fun.xls.exeC:\Users\admin\AppData\Local\Temp\~DF9BA41850EC2BBE74.TMPbinary
MD5:57D8AAE309079F691AD88C408E21D715
SHA256:CD5D7B3005CDD22D6C7BD56CE4EA06E3433C1BCBFD479CD7D0491A4B0935F84D
3648fun.xls.exeC:\Windows\system32\msfun80.exeexecutable
MD5:24279B569C7F301460E0C092C80F0919
SHA256:6752376C0E3E56D65AD86F1FA377987C9E666E76BBE0E78328FAB86091C621FB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info