analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

fara_titlu-6000 6539654721.doc

Full analysis: https://app.any.run/tasks/22913773-c7fa-40ef-9a99-4502d15d7739
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: October 20, 2020, 09:13:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
emotet-doc
emotet
generated-doc
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Facere., Author: Victor Brun, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Fri Oct 16 07:31:00 2020, Last Saved Time/Date: Fri Oct 16 07:31:00 2020, Number of Pages: 1, Number of Words: 2837, Number of Characters: 16174, Security: 8
MD5:

80ECDBB4979308806C15DC62F755EC7D

SHA1:

C555A9EEE3A110F2851972D262D0EAE9BD84579F

SHA256:

0477D3C46A4B4854CD9E0A70B203E6DA1A9F815BB7C2287532ADAEDCEF8EFB3B

SSDEEP:

3072:JueCmMmDBeY5kb0TUNAuBqVPlB11nBkEUGI5rKZvFh9D:UdmM+EYOb0TUquBqt7nBSr5O9Fh9D

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Creates files in the user directory

      • WINWORD.EXE (PID: 2028)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 2028)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (54.2)
.doc | Microsoft Word document (old ver.) (32.2)

EXIF

FlashPix

Title: Facere.
Subject: -
Author: Victor Brun
Keywords: -
Comments: -
Template: Normal.dotm
LastModifiedBy: -
RevisionNumber: 1
Software: Microsoft Office Word
TotalEditTime: -
CreateDate: 2020:10:16 06:31:00
ModifyDate: 2020:10:16 06:31:00
Pages: 1
Words: 2837
Characters: 16174
Security: Locked for annotations
Company: -
Lines: 134
Paragraphs: 37
CharCountWithSpaces: 18974
AppVersion: 15
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts: -
HeadingPairs:
  • Title
  • 1
CodePage: Unicode UTF-16, little endian
LocaleIndicator: 1033
CompObjUserTypeLen: 32
CompObjUserType: Microsoft Word 97-2003 Document
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
1
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winword.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2028"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\fara_titlu-6000 6539654721.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
Total events
1 512
Read events
965
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
2

Dropped files

PID
Process
Filename
Type
2028WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR4173.tmp.cvr
MD5:
SHA256:
2028WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~$ra_titlu-6000 6539654721.docpgc
MD5:4672900F591B7006409B5DAD1677352A
SHA256:3373D7E8B29C1FAF13AC5399E111C67E5F41A9BD57E40B6142FE3B5BC2A2BAF7
2028WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:0618BAB61C3D90EDFF29F8D76433B2BE
SHA256:8119F9FD4D2767D6A44B659E3CD3BC6C2C85BEC44410493E146A21A17F14DAD7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info