analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

d642109e621c6758027c2fc0e5ea3d1126963a001ab1858b95f82e09403943bd.xls

Full analysis: https://app.any.run/tasks/b6ba49c4-d8c1-4f96-9d74-7f2c03bef7b2
Verdict: Malicious activity
Analysis date: May 20, 2022, 16:55:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
opendir
Indicators:
MIME: application/vnd.ms-excel
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: Posik, Last Saved By: Dream, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:19:34 2015, Last Saved Time/Date: Thu May 19 10:49:31 2022, Security: 0
MD5:

64D4AB18BBD8E191F74FC14198FDEC87

SHA1:

0A13D417F779071B5263163AD7DA839E6B3C5738

SHA256:

D642109E621C6758027C2FC0E5EA3D1126963A001AB1858B95F82E09403943BD

SSDEEP:

1536:t5nKpb8rGYrMPe3q7Q0XV5xtezEsi8/dgYAezwrMC1vJec/RtbEtfE:/Kpb8rGYrMPe3q7Q0XV5xtezEsi8/dgt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual execution from Microsoft Office

      • EXCEL.EXE (PID: 2920)
    • Registers / Runs the DLL via REGSVR32.EXE

      • EXCEL.EXE (PID: 2920)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads settings of System Certificates

      • EXCEL.EXE (PID: 2920)
    • Reads the computer name

      • EXCEL.EXE (PID: 2920)
    • Checks supported languages

      • EXCEL.EXE (PID: 2920)
      • regsvr32.exe (PID: 1448)
      • regsvr32.exe (PID: 3272)
      • regsvr32.exe (PID: 2580)
      • regsvr32.exe (PID: 2788)
    • Checks Windows Trust Settings

      • EXCEL.EXE (PID: 2920)
    • Reads Microsoft Office registry keys

      • EXCEL.EXE (PID: 2920)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xls | Microsoft Excel sheet (78.9)

EXIF

FlashPix

Author: Posik
LastModifiedBy: Dream
Software: Microsoft Excel
CreateDate: 2015:06:05 18:19:34
ModifyDate: 2022:05:19 09:49:31
Security: None
CodePage: Windows Cyrillic
Company: -
AppVersion: 16
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts:
  • Sheet
  • Fhgyk
  • Tjdtjf
  • Vehsrg
  • PVVEBZ
  • Btd
  • Btdd
HeadingPairs:
  • Листы
  • 4
  • Макросы Excel 4.0
  • 3
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start excel.exe regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2920"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXE
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Version:
14.0.6024.1000
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\microsoft office\office14\excel.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1448C:\Windows\System32\regsvr32.exe /S ..\soam1.dllC:\Windows\System32\regsvr32.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3272C:\Windows\System32\regsvr32.exe /S ..\soam2.dllC:\Windows\System32\regsvr32.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2580C:\Windows\System32\regsvr32.exe /S ..\soam3.dllC:\Windows\System32\regsvr32.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2788C:\Windows\System32\regsvr32.exe /S ..\soam4.dllC:\Windows\System32\regsvr32.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
4 451
Read events
4 364
Write events
76
Delete events
11

Modification events

(PID) Process:(2920) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
Operation:writeName:7h;
Value:
37683B00680B0000010000000000000000000000
(PID) Process:(2920) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(2920) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
Off
(PID) Process:(2920) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
Off
(PID) Process:(2920) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
Off
(PID) Process:(2920) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
Off
(PID) Process:(2920) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
Off
(PID) Process:(2920) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
Off
(PID) Process:(2920) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
Off
(PID) Process:(2920) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
Off
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2920EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVRD037.tmp.cvr
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
6
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2920
EXCEL.EXE
GET
404
173.231.245.32:80
http://mybiscotto.com/images/BDcjQT/
US
xml
341 b
suspicious
2920
EXCEL.EXE
GET
404
2.16.107.82:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?42d2bcaae5d72a26
unknown
xml
341 b
whitelisted
2920
EXCEL.EXE
GET
404
50.31.160.160:80
http://myramark.com/mail/rdhEPylXD8BuTA/
US
xml
341 b
suspicious
1088
svchost.exe
GET
404
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?001d3f4afd4e8c70
US
xml
341 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2920
EXCEL.EXE
103.1.238.211:443
myphamcuatui.com
SUPERDATA
VN
suspicious
2920
EXCEL.EXE
50.31.160.160:80
myramark.com
Server Central Network
US
suspicious
2920
EXCEL.EXE
2.16.107.82:80
ctldl.windowsupdate.com
Akamai International B.V.
suspicious
1088
svchost.exe
209.197.3.8:80
ctldl.windowsupdate.com
Highwinds Network Group, Inc.
US
whitelisted
2920
EXCEL.EXE
173.231.245.32:80
mybiscotto.com
tzulo, inc.
US
suspicious
2920
EXCEL.EXE
103.227.62.66:443
myechoproject.com
Diadem Technologies Pvt. Ltd.
IN
suspicious

DNS requests

Domain
IP
Reputation
myphamcuatui.com
  • 103.1.238.211
suspicious
ctldl.windowsupdate.com
  • 2.16.107.82
  • 2.16.107.50
  • 209.197.3.8
whitelisted
myramark.com
  • 50.31.160.160
suspicious
myechoproject.com
  • 103.227.62.66
suspicious
mybiscotto.com
  • 173.231.245.32
suspicious

Threats

Found threats are available for the paid subscriptions
2 ETPRO signatures available at the full report
No debug info