analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

ecb55b3ebbd9405138557a7cfcd00bea.xls

Full analysis: https://app.any.run/tasks/3008f00d-5067-4132-98ef-33e2a5764091
Verdict: Malicious activity
Analysis date: January 18, 2019, 01:20:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
Indicators:
MIME: application/vnd.ms-excel
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Mon Dec 24 18:20:02 2018, Security: 0
MD5:

ECB55B3EBBD9405138557A7CFCD00BEA

SHA1:

AE7774754D0AC2E4846B72272D57BEDB13E63B4D

SHA256:

B76FA69E7944C48D6F7D3DC415AFE62F601D7D7D2888F3D3E4D276A79DE02030

SSDEEP:

6144:cZ+RwPONXoRjDhIcp0fDlavx+W26nAHvhJCeHfvgQb:hfR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • procesexplorar3.51.exe (PID: 2164)
    • Unusual execution from Microsoft Office

      • EXCEL.EXE (PID: 2952)
    • Executable content was dropped or overwritten

      • EXCEL.EXE (PID: 2952)
  • SUSPICIOUS

    • Connects to unusual port

      • procesexplorar3.51.exe (PID: 2164)
  • INFO

    • Reads Microsoft Office registry keys

      • EXCEL.EXE (PID: 2952)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xls | Microsoft Excel sheet (48)
.xls | Microsoft Excel sheet (alternate) (39.2)

EXIF

FlashPix

Author: -
LastModifiedBy: -
Software: Microsoft Excel
CreateDate: 2006:09:16 00:00:00
ModifyDate: 2018:12:24 18:20:02
Security: None
CodePage: Windows Latin 1 (Western European)
AppVersion: 12
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts:
  • Sheet1
  • Sheet2
HeadingPairs:
  • Worksheets
  • 2
CompObjUserTypeLen: 38
CompObjUserType: Microsoft Office Excel 2003 Worksheet
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start excel.exe procesexplorar3.51.exe

Process information

PID
CMD
Path
Indicators
Parent process
2952"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Version:
14.0.6024.1000
2164C:\Users\admin\Documents\procesexplorar3.51.exeC:\Users\admin\Documents\procesexplorar3.51.exe
EXCEL.EXE
User:
admin
Company:
Microsoft Corporation Inc
Integrity Level:
MEDIUM
Description:
Process Explorar
Version:
3.01.1.0
Total events
633
Read events
537
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
1
Text files
0
Unknown types
1

Dropped files

PID
Process
Filename
Type
2952EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR8FA3.tmp.cvr
MD5:
SHA256:
2952EXCEL.EXEC:\Users\admin\Documents\VB9D24.tmp
MD5:
SHA256:
2952EXCEL.EXEC:\Users\admin\AppData\Local\Temp\VB9D23.tmp
MD5:
SHA256:
2952EXCEL.EXEC:\Users\admin\AppData\Local\Temp\VBE\MSForms.exdtlb
MD5:41406772F8FB7E6CAA6E45CBE9A92DF2
SHA256:339FD1A9C6F9C892F5735D233F4475EF8EFB26627BFC0A2FE575969F02F11725
2952EXCEL.EXEC:\Users\admin\Documents\procesexplorar3.51.zipcompressed
MD5:DDDACBED33551439182B6CB1C67087CE
SHA256:FEFDF6AF5669ABB5DDB7B0527DD0609285319307538C573614B914CDD3085D04
2952EXCEL.EXEC:\Users\admin\Documents\procesexplorar3.51.exeexecutable
MD5:F08A0BB675F2DFF0C60A07CAE4D43E32
SHA256:1EFD965617A1BBC312DFFEED1F21810660CBE2A9DDBF577754CA0B510D3CEA1E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2164
procesexplorar3.51.exe
193.228.53.0:6881
AT
unknown
2164
procesexplorar3.51.exe
193.228.53.0:3927
AT
unknown
2164
procesexplorar3.51.exe
193.228.53.0:8419
AT
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info