File name: | Leaked_Records_15072019_Col.accdb |
Full analysis: | https://app.any.run/tasks/67d4c83e-35f0-41a0-8dba-f6a06064d756 |
Verdict: | Malicious activity |
Analysis date: | July 17, 2019, 14:11:57 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-msaccess |
File info: | Microsoft Access Database |
MD5: | BEFC603B7E59E0B739AE150FFC0CAD3A |
SHA1: | 4BF499C320E6806E877E68876A3BEB2ADA2A45AC |
SHA256: | 7C02D2F27147C49030C0619D1D313CFA24234F789E149B2E3D1478400496A32C |
SSDEEP: | 1536:DAQxNqc6lh3WHzVdGduAixBQdpdzdmdudJ:DAQxNqc6lsfkuAixAjJEcJ |
.accdb | | | Microsoft Access 2007 Database (90.4) |
---|---|---|
.pi2 | | | DEGAS med-res bitmap (9.5) |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3756 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Leaked_Records_15072019_Col.accdb | C:\Windows\system32\rundll32.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3416 | "C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE" /NOSTARTUP "C:\Users\admin\AppData\Local\Temp\Leaked_Records_15072019_Col.accdb" | C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE | rundll32.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Access Version: 14.0.6024.1000 | ||||
416 | "C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE" /NOSTARTUP "C:\Users\admin\AppData\Local\Temp\Leaked_Records_15072019_Col.accdb" | C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE | — | rundll32.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Access Version: 14.0.6024.1000 | ||||
904 | "C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE" /NOSTARTUP "C:\Users\admin\AppData\Local\Temp\Leaked_Records_15072019_Col.accdb" | C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE | — | rundll32.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Access Version: 14.0.6024.1000 | ||||
2260 | "C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE" /NOSTARTUP "C:\Users\admin\AppData\Local\Temp\Leaked_Records_15072019_Col.accdb" | C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE | — | rundll32.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Access Version: 14.0.6024.1000 | ||||
2276 | "C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE" /NOSTARTUP "C:\Users\admin\AppData\Local\Temp\Leaked_Records_15072019_Col.accdb" | C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE | — | rundll32.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Access Version: 14.0.6024.1000 | ||||
2168 | "C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE" /NOSTARTUP "C:\Users\admin\AppData\Local\Temp\Leaked_Records_15072019_Col.accdb" | C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE | — | rundll32.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Access Version: 14.0.6024.1000 | ||||
2192 | "C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE" /NOSTARTUP "C:\Users\admin\AppData\Local\Temp\Leaked_Records_15072019_Col.accdb" | C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE | — | rundll32.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Access Version: 14.0.6024.1000 | ||||
2188 | "C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE" /NOSTARTUP "C:\Users\admin\AppData\Local\Temp\Leaked_Records_15072019_Col.accdb" | C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE | — | rundll32.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Access Version: 14.0.6024.1000 | ||||
2704 | "C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE" /NOSTARTUP "C:\Users\admin\AppData\Local\Temp\Leaked_Records_15072019_Col.accdb" | C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE | — | rundll32.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Access Version: 14.0.6024.1000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3416 | MSACCESS.EXE | C:\Users\admin\AppData\Local\Temp\CVR19FC.tmp.cvr | — | |
MD5:— | SHA256:— | |||
904 | MSACCESS.EXE | C:\Users\admin\AppData\Local\Temp\CVR6CB0.tmp.cvr | — | |
MD5:— | SHA256:— | |||
416 | MSACCESS.EXE | C:\Users\admin\AppData\Local\Temp\CVR6CBF.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2276 | MSACCESS.EXE | C:\Users\admin\AppData\Local\Temp\CVR8141.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2168 | MSACCESS.EXE | C:\Users\admin\AppData\Local\Temp\CVR8141.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2260 | MSACCESS.EXE | C:\Users\admin\AppData\Local\Temp\CVR8151.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2188 | MSACCESS.EXE | C:\Users\admin\AppData\Local\Temp\CVR8161.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2192 | MSACCESS.EXE | C:\Users\admin\AppData\Local\Temp\CVR818F.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2704 | MSACCESS.EXE | C:\Users\admin\AppData\Local\Temp\CVR942D.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2708 | MSACCESS.EXE | C:\Users\admin\AppData\Local\Temp\CVR943D.tmp.cvr | — | |
MD5:— | SHA256:— |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3124 | cutil.exe | 104.20.208.21:443 | pastebin.com | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
---|---|---|
pastebin.com |
| shared |
Process | Message |
---|---|
MSACCESS.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Access\System.mdw |