analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

details1910.xls

Full analysis: https://app.any.run/tasks/88c4ef1d-f974-4f29-8d25-96ef40fc7bd6
Verdict: Malicious activity
Analysis date: October 19, 2020, 21:32:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros40
Indicators:
MIME: application/vnd.ms-excel
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: XMgXOblU, Last Saved By: fckav, Name of Creating Application: Microsoft Excel, Create Time/Date: Mon Sep 14 22:28:14 2020, Last Saved Time/Date: Mon Oct 19 12:56:08 2020, Security: 1
MD5:

AA533F3325ACA3C1DE116F1C6DED8E85

SHA1:

9D19EE326384074D7C2A1ADF178276A58930C83E

SHA256:

A449DB8785122E372305E3611767533D26DB08CA147B043FBCF15E006106EDAD

SSDEEP:

6144:YLtffRrlfODceiP1ZU2w4UbPaQrwG4T0IKxSLPG/rE5bkNSi:+OceiP1ZU2w40aQTIkSLPQrE5fi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual execution from Microsoft Office

      • EXCEL.EXE (PID: 1204)
  • SUSPICIOUS

    • Uses RUNDLL32.EXE to load library

      • EXCEL.EXE (PID: 1204)
    • Writes to a desktop.ini file (may be used to cloak folders)

      • EXCEL.EXE (PID: 1204)
  • INFO

    • Creates files in the user directory

      • EXCEL.EXE (PID: 1204)
    • Reads Internet Cache Settings

      • EXCEL.EXE (PID: 1204)
    • Reads Microsoft Office registry keys

      • EXCEL.EXE (PID: 1204)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xls | Microsoft Excel sheet (78.9)

EXIF

FlashPix

Author: XMgXOblU
LastModifiedBy: fckav
Software: Microsoft Excel
CreateDate: 2020:09:14 21:28:14
ModifyDate: 2020:10:19 11:56:08
Security: Password protected
CodePage: Windows Latin 1 (Western European)
Company: -
AppVersion: 16
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts:
  • Sheet1
  • b
HeadingPairs:
  • Worksheets
  • 1
  • Excel 4.0 Macros
  • 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start excel.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1204"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Version:
14.0.6024.1000
2820"C:\Windows\System32\rundll32.exe" C:\vOLhDcU\QbsIdRa\izlpQqC.dll,DllRegisterServerC:\Windows\System32\rundll32.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
758
Read events
698
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
6
Unknown types
2

Dropped files

PID
Process
Filename
Type
1204EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR4309.tmp.cvr
MD5:
SHA256:
1204EXCEL.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\details1910.xls.LNKlnk
MD5:3AD6536B3A6738BD639FFC815FCE88E0
SHA256:58543F4396CEB6B4F46A41C38700F7DC286C040D0383D98C697E4997ABE15946
1204EXCEL.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dattext
MD5:8C13347D19F88BB2C15B06C16C7F236E
SHA256:B161E0880C7C6A9DA54FD69B2806E974D0E2DB2170EA4FD4F236B78B3C9321BB
1204EXCEL.EXEC:\Users\admin\Documents\My Data Sources\FOLDER.ICOimage
MD5:A6DDCCFDAD18D5CA7AAEB168B6D02253
SHA256:3114451F95C7FB8D7D884A19C724F6C7FF906B6D9BEC1BF7C6300D2CCA4F43A6
1204EXCEL.EXEC:\Users\admin\Documents\My Data Sources\+Connect to New Data Source.odchtml
MD5:16A8A9A2B0A8B65FAF28E1007DB6733F
SHA256:3A13080059292811E5AC3F9E8B04B2C8EEA95D6A5538116AD751D11C834E6056
1204EXCEL.EXEC:\Users\admin\Documents\My Data Sources\+NewSQLServerConnection.odchtml
MD5:149E8C684B9EA9887DD2E7E596E7187C
SHA256:43B12E68FB3B5BCC4099D796FA670A62B116A894437454A20050661DEF9D8816
1204EXCEL.EXEC:\Users\admin\Documents\My Data Sources\DESKTOP.INIini
MD5:466AFDBDD30770A1A6B47AFD85099E82
SHA256:D63E228A2173E58FA14818AAF610E9E6676D2D9836C5C2ED83BA6A783B7BB999
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info