File name:

C:\Users\admin\Downloads\0208_4029835956334.doc

Full analysis: https://app.any.run/tasks/def673e8-7d80-46fa-829e-55e8523ca447
Verdict: Malicious activity
Threats:

Hancitor was created in 2014 to drop other malware on infected machines. It is also known as Tordal and Chanitor. This malware is available as a service which makes it accessible tools to criminals and contributes to the popularity of this virus.

Analysis date: February 08, 2021, 14:16:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
ole-embedded
macros-on-open
generated-doc
evasion
trojan
hancitor
maldoc-57
Indicators:
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: MyPc, Template: Normal.dotm, Last Saved By: MyPc, Revision Number: 2, Name of Creating Application: Microsoft Office Word, Create Time/Date: Mon Feb 8 13:00:00 2021, Last Saved Time/Date: Mon Feb 8 13:00:00 2021, Number of Pages: 1, Number of Words: 3, Number of Characters: 19, Security: 0
MD5:

109E3E3510B661CA87B5A3B79ACFE02B

SHA1:

45FA7E6F7F782088F182C8146B046ABFB5C51C19

SHA256:

1BD711CAB7B4CA502DC9AC745A06DE0A5FD6CA46A1017F474008751564D1B905

SSDEEP:

24576:AA8N6rVgYpNGhCOndGCl/YSD7aq/Iq9M:+SJkCOo6w

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executable content was dropped or overwritten

      • WINWORD.EXE (PID: 2256)
    • Connects to CnC server

      • rundll32.exe (PID: 1832)
    • Loads dropped or rewritten executable

      • rundll32.exe (PID: 1832)
    • Unusual execution from Microsoft Office

      • WINWORD.EXE (PID: 2256)
    • HANCITOR was detected

      • rundll32.exe (PID: 1832)
  • SUSPICIOUS

    • Uses RUNDLL32.EXE to load library

      • WINWORD.EXE (PID: 2256)
    • Drops a file with too old compile date

      • WINWORD.EXE (PID: 2256)
    • Checks for external IP

      • rundll32.exe (PID: 1832)
  • INFO

    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 2256)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 2256)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (34.5)
.doc | Microsoft Word document (old ver.) (20.5)

EXIF

FlashPix

Title: -
Subject: -
Author: MyPc
Keywords: -
Comments: -
Template: Normal.dotm
LastModifiedBy: MyPc
RevisionNumber: 2
Software: Microsoft Office Word
TotalEditTime: -
CreateDate: 2021:02:08 13:00:00
ModifyDate: 2021:02:08 13:00:00
Pages: 1
Words: 3
Characters: 19
Security: None
CodePage: Windows Latin 1 (Western European)
Company: -
Lines: 1
Paragraphs: 1
CharCountWithSpaces: 21
AppVersion: 16
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts: -
HeadingPairs:
  • Title
  • 1
CompObjUserTypeLen: 32
CompObjUserType: Microsoft Word 97-2003 Document
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winword.exe #HANCITOR rundll32.exe

Process information

PID
CMD
Path
Indicators
Parent process
1832"C:\Windows\System32\rundll32.exe" C:\Users\admin\AppData\Roaming\Microsoft\Templates\W0rd.dll,UminslaIIF0mtC:\Windows\System32\rundll32.exe
WINWORD.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2256"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\0208_4029835956334.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
Total events
1 582
Read events
917
Write events
537
Delete events
128

Modification events

(PID) Process:(2256) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:writeName:;<6
Value:
3B3C3600D0080000010000000000000000000000
(PID) Process:(2256) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(2256) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
Off
(PID) Process:(2256) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
Off
(PID) Process:(2256) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
Off
(PID) Process:(2256) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
Off
(PID) Process:(2256) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
Off
(PID) Process:(2256) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
Off
(PID) Process:(2256) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
Off
(PID) Process:(2256) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
Off
Executable files
2
Suspicious files
0
Text files
0
Unknown types
3

Dropped files

PID
Process
Filename
Type
2256WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRC43B.tmp.cvr
MD5:
SHA256:
2256WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:
SHA256:
2256WINWORD.EXEC:\Users\admin\AppData\Local\Temp\Wh102yYa.tmpexecutable
MD5:
SHA256:
2256WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\W0rd.dllexecutable
MD5:
SHA256:
2256WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~$08_4029835956334.docpgc
MD5:
SHA256:
2256WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\84311CF1.emfemf
MD5:A08286784C9F2B367F405D02EECA6D49
SHA256:91EC41F1FBBB6769B0F1D9062384CAFD742AF6B2E0FC790B60FF24E1E9BFE2E3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
8
DNS requests
9
Threats
14

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1832
rundll32.exe
GET
404
54.243.164.148:80
http://api.ipify.org/
US
xml
341 b
shared
1832
rundll32.exe
POST
404
213.5.229.12:80
http://satursed.com/8/forum.php
RU
xml
341 b
malicious
1832
rundll32.exe
GET
404
54.243.164.148:80
http://api.ipify.org/
US
xml
341 b
shared
1832
rundll32.exe
POST
404
91.238.104.241:80
http://ludiesibut.ru/8/forum.php
CZ
xml
341 b
malicious
1832
rundll32.exe
POST
404
95.216.84.231:80
http://sameastar.ru/8/forum.php
DE
xml
341 b
malicious
1832
rundll32.exe
POST
404
213.5.229.12:80
http://satursed.com/8/forum.php
RU
xml
341 b
malicious
1832
rundll32.exe
POST
404
95.216.84.231:80
http://sameastar.ru/8/forum.php
DE
xml
341 b
malicious
1832
rundll32.exe
POST
404
91.238.104.241:80
http://ludiesibut.ru/8/forum.php
CZ
xml
341 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
91.238.104.241:80
ludiesibut.ru
FOP Reznichenko Sergey Mykolayovich
CZ
malicious
1832
rundll32.exe
213.5.229.12:80
satursed.com
ArtPlanet LLC
RU
malicious
1832
rundll32.exe
54.243.164.148:80
api.ipify.org
Amazon.com, Inc.
US
suspicious
1832
rundll32.exe
91.238.104.241:80
ludiesibut.ru
FOP Reznichenko Sergey Mykolayovich
CZ
malicious
54.243.164.148:80
api.ipify.org
Amazon.com, Inc.
US
suspicious
1832
rundll32.exe
95.216.84.231:80
sameastar.ru
Hetzner Online GmbH
DE
malicious

DNS requests

Domain
IP
Reputation
api.ipify.org
  • 54.243.164.148
  • 23.21.126.66
  • 23.21.252.4
  • 23.21.140.41
  • 23.21.76.253
  • 54.225.220.115
  • 23.21.48.44
  • 54.235.147.252
shared
satursed.com
  • 213.5.229.12
malicious
sameastar.ru
  • 95.216.84.231
malicious
ludiesibut.ru
  • 91.238.104.241
malicious
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

PID
Process
Class
Message
1832
rundll32.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup api.ipify.org
1832
rundll32.exe
A Network Trojan was detected
MALWARE [PTsecurity] Hancitor POST Data send
1832
rundll32.exe
A Network Trojan was detected
MALWARE [PTsecurity] Hancitor POST Data send
1832
rundll32.exe
A Network Trojan was detected
MALWARE [PTsecurity] Hancitor POST Data send
1832
rundll32.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup api.ipify.org
1832
rundll32.exe
A Network Trojan was detected
MALWARE [PTsecurity] Hancitor POST Data send
1832
rundll32.exe
A Network Trojan was detected
MALWARE [PTsecurity] Hancitor POST Data send
1832
rundll32.exe
A Network Trojan was detected
MALWARE [PTsecurity] Hancitor POST Data send
6 ETPRO signatures available at the full report
No debug info