| File name: | www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exe |
| Full analysis: | https://app.any.run/tasks/651f821d-b1c6-4362-b871-a045fddeeb5e |
| Verdict: | Malicious activity |
| Analysis date: | October 31, 2024, 10:55:02 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 6 sections |
| MD5: | 4A61D021B6849C990480D24A3F2E98E4 |
| SHA1: | 563B367A23DAE6CD54FB34D09908739E21F86E9E |
| SHA256: | 9DED1CB75921759C387C43C7C732259B21602A36D77ECD90DFAC97D33966C7B6 |
| SSDEEP: | 98304:5r1wE4M+LVg8nJb3DmrrGjAkXoSeMCGr3RgeD5K9xoQHmW7sH1nOcsEdzJXgyeAb:UfKEEK5cb8wYdx8/gYa17 |
| .exe | | | MS generic-sfx Cabinet File Unpacker (32/64bit MSCFU) (82.5) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (7.3) |
| .exe | | | Win64 Executable (generic) (6.5) |
| .dll | | | Win32 Dynamic Link Library (generic) (1.5) |
| .exe | | | Win32 Executable (generic) (1) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2023:08:28 18:19:40+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 10 |
| CodeSize: | 26112 |
| InitializedDataSize: | 50688 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x301c |
| OSVersion: | 5.2 |
| ImageVersion: | - |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 4.5.0.0 |
| ProductVersionNumber: | 4.5.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | ASCII |
| Comments: | FIGEN YAZILIM EVI TIC. LTD. STI. |
| CompanyName: | FIGEN YAZILIM EVI TIC. LTD. STI. |
| FileDescription: | Poctgoyercini Excel Eklentisi Setup |
| FileVersion: | 4.5.0.0 |
| InternalName: | sf_rt |
| LegalCopyright: | Figensoft Copyright © 2011 - 2023 |
| LegalTrademarks: | Poctgoyercini Excel Eklentisi Setup |
| OriginalFileName: | suf_launch.exe |
| ProductName: | Poctgoyercini Excel Eklentisi |
| ProductVersion: | 4.5.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1748 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | AddInUtil.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1768 | VSTOInstaller.exe /install file:///C:/Users/admin/Desktop/SMSEXCELADDIN_PG.vsto | C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe | rundll32.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual Studio Tools for Office Solution Installer Exit code: 4294967093 Version: 10.0.60828.0 built by: VSTO_Rel Modules
| |||||||||||||||
| 2128 | "rundll32.exe" "c:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\vstoee.dll",InstallVstoSolution C:\Users\admin\Desktop\SMSEXCELADDIN_PG.vsto | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2224 | "c:\WINDOWS\Microsoft.NET\Framework64\v3.5\addinutil.exe" -AddInRoot:"c:\Program Files (x86)\Common Files\Microsoft Shared\VSTA\AppInfoDocument\." -Rebuild | C:\Windows\Microsoft.NET\Framework64\v3.5\AddInUtil.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: AddInUtil.exe Exit code: 0 Version: 3.5.30729.9141 built by: WinRelRS6 Modules
| |||||||||||||||
| 2588 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2864 | "C:\Users\admin\Desktop\uninstall.exe" | C:\Users\admin\Desktop\uninstall.exe | explorer.exe | ||||||||||||
User: admin Company: Indigo Rose Corporation Integrity Level: HIGH Description: Setup Application Exit code: 12 Version: 9.6.0.1 Modules
| |||||||||||||||
| 3676 | "C:\Users\admin\AppData\Local\Temp\www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exe" | C:\Users\admin\AppData\Local\Temp\www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exe | — | explorer.exe | |||||||||||
User: admin Company: FIGEN YAZILIM EVI TIC. LTD. STI. Integrity Level: MEDIUM Description: Poctgoyercini Excel Eklentisi Setup Exit code: 3221226540 Version: 4.5.0.0 Modules
| |||||||||||||||
| 3832 | c:\Windows\System32\MsiExec.exe -Embedding 64E5E733B46AE9A7206A4D7594B86822 E Global\MSI0000 | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3832 | "rundll32.exe" "c:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\vstoee.dll",InstallVstoSolution C:\Users\admin\Desktop\SMSEXCELADDIN_PG.vsto | C:\Windows\SysWOW64\rundll32.exe | — | rundll32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3916 | "rundll32.exe" "c:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\vstoee.dll",InstallVstoSolution C:\Users\admin\Desktop\SMSEXCELADDIN_PG.vsto | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (2588) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 1C0A0000533EF764832BDB01 | |||
| (PID) Process: | (2588) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: C029C4498550316B765E4C497D753651583F7AAF2C25D5716343A476AEED45A7 | |||
| (PID) Process: | (2588) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2588) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders |
| Operation: | write | Name: | c:\Config.Msi\ |
Value: | |||
| (PID) Process: | (2588) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts |
| Operation: | write | Name: | c:\Config.Msi\90aa4.rbs |
Value: 31140739 | |||
| (PID) Process: | (2588) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts |
| Operation: | write | Name: | c:\Config.Msi\90aa4.rbsLow |
Value: | |||
| (PID) Process: | (2588) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACD7412E4BDD5424193BDEE5BBA2636E |
| Operation: | write | Name: | 6EA0063C0A397BD37BAA54DB851F335B |
Value: 02:\SOFTWARE\Microsoft\VSTA Runtime Setup\v10.0.31119\Install | |||
| (PID) Process: | (2588) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7E4BD88386A69FA498F277ECC214E817 |
| Operation: | write | Name: | 6EA0063C0A397BD37BAA54DB851F335B |
Value: c:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\msvcr90.dll | |||
| (PID) Process: | (2588) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9BA4899E4018DB34F88F23D4D8A68F69 |
| Operation: | write | Name: | 6EA0063C0A397BD37BAA54DB851F335B |
Value: c:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\msvcp90.dll | |||
| (PID) Process: | (2588) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F82E61F66BE0564C937495374CFBBE8 |
| Operation: | write | Name: | 6EA0063C0A397BD37BAA54DB851F335B |
Value: c:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\msvcm90.dll | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6340 | www.PoctGoyercini.com_SMS_EXCEL_ADDIN_v6.50.exe | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe | executable | |
MD5:6CCBB32F704537B2A48E7F19306D5A8F | SHA256:A412F87C3A56AF9CACFF6B216EA95E68A630D1652CE1FFEF30AD6E32D05853CB | |||
| 4692 | irsetup.exe | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\IRIMG1.JPG | image | |
MD5:0CBE6F2BD01D8D0EF2E7E0EE70671E37 | SHA256:C14D3E7D5A3AD622021F54B2B9049AD1DE78AB3F44C03964B62ADEF8D64F4D64 | |||
| 4476 | vstor40_x64.exe | C:\4a23dfd79856504f12fb30\vstor40_x64.cab | compressed | |
MD5:B0C2E188C1B05FFAEEEDBEA1F5D2FAB2 | SHA256:7EC18C4BA95412F62FDA3A7D9AED83B8F4898AB5B93A0D5A55160C0FD03A8DF7 | |||
| 4692 | irsetup.exe | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\office_tool\vstor40_x86.exe | executable | |
MD5:7A57B77C2CF1F22C408B32AA1D54C2C1 | SHA256:681BB354DD5476F63258026A2CEE9F6A68C9E4AB27DBFA029456620F212E4E1D | |||
| 4692 | irsetup.exe | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\IRIMG2.JPG | image | |
MD5:5E088935115FCA3BD9772E7A521521B1 | SHA256:E93314AF64ACBE0915093BE1017FA931AA6420E18C89AA9ADFF699D3A9BE546F | |||
| 4476 | vstor40_x64.exe | C:\4a23dfd79856504f12fb30\vstor40_x64.msi | executable | |
MD5:D873488D7D417B8310B3519B9651030F | SHA256:AE0F8D05580EB085FA9A8C2DCB6FAD0048EF492C0CD278217FD8D4CB99E48556 | |||
| 4692 | irsetup.exe | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\office_tool\vstor40_x64.exe | executable | |
MD5:69C7F5486BA44B1600B3DC9F25347242 | SHA256:75219EA8DEA06F15BE5830761C2381FF17B841FAB3B4BD4A6F04D3C5D8DE4DC6 | |||
| 4476 | vstor40_x64.exe | C:\4a23dfd79856504f12fb30\install.exe | executable | |
MD5:D633FD62D38A9F2A656329E7CF272F88 | SHA256:571BDBB819EE8F1FFCB7879441CD5AF2B90EF9A62CB60A5A2BCC7BA73514CF03 | |||
| 4476 | vstor40_x64.exe | C:\4a23dfd79856504f12fb30\eula.1033.txt | text | |
MD5:BE6142E24326C7E3F1030B95BBA80D1B | SHA256:030B04CE7FADC9DA232BE9A76BF35D9ECCCE7EB8C37C5E238095D71397A5AFD7 | |||
| 4692 | irsetup.exe | C:\Users\admin\AppData\Local\Temp\www.PoctGoyercini.com SMS EXCEL ADDIN Setup Log.txt | text | |
MD5:04D3D8675F56AE4A8FC6D5A71E960729 | SHA256:70B56E2C24D2AC2311DEE7A3F728C1A94A0E6D971D2CB0549C4BF37C24752349 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5488 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.106:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5488 | MoUsoCoreWorker.exe | GET | 200 | 23.32.185.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4360 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
4004 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7136 | install.exe | GET | 200 | 2.16.164.9:80 | http://crl.microsoft.com/pki/crl/products/CSPCA.crl | unknown | — | — | whitelisted |
3860 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
3676 | SIHClient.exe | GET | 200 | 23.32.185.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
4360 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
4360 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1172 | RUXIMICS.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5488 | MoUsoCoreWorker.exe | 2.16.164.106:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
5488 | MoUsoCoreWorker.exe | 23.32.185.131:80 | www.microsoft.com | AKAMAI-AS | BR | whitelisted |
— | — | 2.23.209.168:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
4360 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
— | — | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4004 | svchost.exe | 20.190.159.23:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
th.bing.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
VSTOInstaller.exe |
*** Status originated: -1073741811
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
|
VSTOInstaller.exe |
*** Status originated: -1073741811
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
|
VSTOInstaller.exe |
*** Status originated: -1073741811
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
|
VSTOInstaller.exe |
*** Status originated: -1073741811
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
|
VSTOInstaller.exe |
*** Status originated: -1073741811
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
|
VSTOInstaller.exe |
*** Status originated: -1073741811
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
|
VSTOInstaller.exe |
*** Status originated: -1073741811
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
|
VSTOInstaller.exe |
*** Status originated: -1073741811
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
|
VSTOInstaller.exe |
*** Status originated: -1073741811
*** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
|