| File name: | TTS_Turbo_Macros_v5.0.xla |
| Full analysis: | https://app.any.run/tasks/34a9efdd-dc8c-41cf-b7fa-fa0cff22cb23 |
| Verdict: | Suspicious activity |
| Analysis date: | May 27, 2020, 23:14:41 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| MIME: | application/vnd.ms-excel |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Title: TTS Turbo Macros 5.0, Author: Teaching The Street, Comments: TTS Turbo Macros 5.0, Last Saved By: Jon Peltier, Name of Creating Application: Microsoft Excel, Create Time/Date: Sun Sep 17 01:56:36 2006, Last Saved Time/Date: Thu Feb 10 18:57:01 2011, Security: 0 |
| MD5: | E77A0ACF28DB8E71DB8E1A75EF5A1CB9 |
| SHA1: | AC3B5B68B368E720E0B35C452D96865E3A6D7D50 |
| SHA256: | EEF9A6C35957500F5745B9A9877EC81DC0F68E788956D9F686123BEC00206D2A |
| SSDEEP: | 12288:andNIlGQwCXk0LE0C8iyp7aqsr3pGCymHeZGYBMRrBWpwr027vM4k:adNIltwCXkA+ypOqsr3pGCymHeZGYBMB |
| .xls | | | Microsoft Excel sheet (48) |
|---|---|---|
| .xls | | | Microsoft Excel sheet (alternate) (39.2) |
| Title: | TTS Turbo Macros 5.0 |
|---|---|
| Author: | Teaching The Street |
| Comments: | TTS Turbo Macros 5.0 |
| LastModifiedBy: | Jon Peltier |
| Software: | Microsoft Excel |
| CreateDate: | 2006:09:17 00:56:36 |
| ModifyDate: | 2011:02:10 18:57:01 |
| Security: | None |
| Company: | Xios |
| AppVersion: | 12 |
| ScaleCrop: | No |
| LinksUpToDate: | No |
| SharedDoc: | No |
| HyperlinksChanged: | No |
| TitleOfParts: |
|
| HeadingPairs: |
|
| CodePage: | Windows Latin 1 (Western European) |
| Hyperlinks: |
|
| CompObjUserTypeLen: | 38 |
| CompObjUserType: | Microsoft Office Excel 2003 Worksheet |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2552 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| (PID) Process: | (2552) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems |
| Operation: | write | Name: | 3=* |
Value: 333D2A00F8090000010000000000000000000000 | |||
| (PID) Process: | (2552) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (2552) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1041 |
Value: Off | |||
| (PID) Process: | (2552) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1046 |
Value: Off | |||
| (PID) Process: | (2552) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1036 |
Value: Off | |||
| (PID) Process: | (2552) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1031 |
Value: Off | |||
| (PID) Process: | (2552) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1040 |
Value: Off | |||
| (PID) Process: | (2552) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1049 |
Value: Off | |||
| (PID) Process: | (2552) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 3082 |
Value: Off | |||
| (PID) Process: | (2552) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1042 |
Value: Off | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2552 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVRA193.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2552 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF21FAF0AFD9F8C763.TMP | — | |
MD5:— | SHA256:— | |||
| 2552 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF4980EF3B42E95365.TMP | — | |
MD5:— | SHA256:— | |||
| 2552 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF642616A3E2916D61.TMP | — | |
MD5:— | SHA256:— | |||
| 2552 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF18DD615EE9713C4A.TMP | — | |
MD5:— | SHA256:— | |||
| 2552 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF6293D597B6174A67.TMP | — | |
MD5:— | SHA256:— | |||
| 2552 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF01E90B0EE12ECC4C.TMP | — | |
MD5:— | SHA256:— | |||
| 2552 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF51E738848E1158B6.TMP | — | |
MD5:— | SHA256:— | |||
| 2552 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF30A4B412B3F2C57F.TMP | — | |
MD5:— | SHA256:— | |||
| 2552 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\VBE\MSForms.exd | tlb | |
MD5:— | SHA256:— | |||