| File name: | threats (9).csv |
| Full analysis: | https://app.any.run/tasks/26845c25-9d9f-4544-9e83-b5554ac3e9a2 |
| Verdict: | Malicious activity |
| Analysis date: | November 10, 2023, 08:42:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/csv |
| File info: | CSV text |
| MD5: | 5E3F3BAF7D9AD291F067CFBF2C3912A3 |
| SHA1: | 492E61CE7A28F6DF652F7A5AEE03A9D9CAAC579F |
| SHA256: | A6C05FA691B7E369BFEA6F92FD9C8B1BB2B1C25B02450E2C7E93A3DAC9207710 |
| SSDEEP: | 384:vwGxR7vdBBFbAQUaDiC//NMMKcugSyfZ1HrHuCsXl1a2RnfA26KWcquIMaGlf7Sa:jSF |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3400 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 3428 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 3844 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 3916 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3428) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: On | |||
| (PID) Process: | (3428) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1041 |
Value: On | |||
| (PID) Process: | (3428) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1046 |
Value: On | |||
| (PID) Process: | (3428) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1036 |
Value: On | |||
| (PID) Process: | (3428) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1031 |
Value: On | |||
| (PID) Process: | (3428) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1040 |
Value: On | |||
| (PID) Process: | (3428) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1049 |
Value: On | |||
| (PID) Process: | (3428) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 3082 |
Value: On | |||
| (PID) Process: | (3428) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1042 |
Value: On | |||
| (PID) Process: | (3428) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1055 |
Value: On | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3428 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR6B42.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3400 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR9F32.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3844 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR9B4.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3428 | EXCEL.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\threats (9).csv.LNK | binary | |
MD5:3B313EF6212A2C266471405ADE9397AD | SHA256:3DA32AEA634595B61638A5F7053621CF6A5C561FAC44F8524151F317958D9927 | |||
| 3428 | EXCEL.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat | text | |
MD5:B331B043CA556E890B97856A359F962F | SHA256:97204C54CDFEC5CFB5712E5CC223555ABCA3CB323DA1ECBE634BBF93D1CB502E | |||
| 3844 | EXCEL.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\threats (9).csv.LNK | binary | |
MD5:3B313EF6212A2C266471405ADE9397AD | SHA256:3DA32AEA634595B61638A5F7053621CF6A5C561FAC44F8524151F317958D9927 | |||
| 3400 | EXCEL.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\threats (9).csv.LNK | binary | |
MD5:3B313EF6212A2C266471405ADE9397AD | SHA256:3DA32AEA634595B61638A5F7053621CF6A5C561FAC44F8524151F317958D9927 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |