| File name: | po-56-ns 056374TI.docx |
| Full analysis: | https://app.any.run/tasks/d89cb5cb-d2cd-4ac7-a861-a5abd5c28518 |
| Verdict: | Malicious activity |
| Analysis date: | February 18, 2025, 10:47:03 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.openxmlformats-officedocument.wordprocessingml.document |
| File info: | Microsoft Word 2007+ |
| MD5: | 5BB0748E984E42985549C56B9682C320 |
| SHA1: | 8CF7E8DB51BEE240B2807F84D31ADF390D3C8B6D |
| SHA256: | 2A988F6A3C40C1F991CC6AAE354ED27FAD6C39C416B1DCE03732114A98759C3C |
| SSDEEP: | 3072:jQekrxhg+ki1fSsMQDarf5cJG+xRkHX038nGCv/T:c9rxhg+D1fS/Drf5cJlxRk3038nGo |
| .docx | | | Word Microsoft Office Open XML Format document (52.2) |
|---|---|---|
| .zip | | | Open Packaging Conventions container (38.8) |
| .zip | | | ZIP compressed archive (8.8) |
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0002 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2025:02:18 11:28:40 |
| ZipCRC: | 0xf5c0e2b4 |
| ZipCompressedSize: | 432 |
| ZipUncompressedSize: | 2503 |
| ZipFileName: | [Content_Types].xml |
| Template: | Normal.dotm |
|---|---|
| TotalEditTime: | - |
| Pages: | 1 |
| Words: | - |
| Characters: | - |
| Application: | Microsoft Office Word |
| DocSecurity: | None |
| Lines: | 1 |
| Paragraphs: | 1 |
| ScaleCrop: | No |
| Company: | Grizli777 |
| LinksUpToDate: | No |
| CharactersWithSpaces: | - |
| SharedDoc: | No |
| HyperlinksChanged: | No |
| AppVersion: | 12 |
| Keywords: | - |
| LastModifiedBy: | 91974 |
| RevisionNumber: | 2 |
| CreateDate: | 2025:02:11 05:56:00Z |
| ModifyDate: | 2025:02:11 05:56:00Z |
| Title: | - |
|---|---|
| Subject: | - |
| Creator: | 91974 |
| Description: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6076 | "C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\po-56-ns 056374TI.docx" /o "" | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 16.0.16026.20146 Modules
| |||||||||||||||
| 6416 | "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe" "939A8574-3C1E-4F8F-A9E1-398A9DCE7690" "BEE0185D-F627-475E-9818-33D985700CB3" "6076" | C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe | — | WINWORD.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Artificial Intelligence (AI) Host for the Microsoft® Windows® Operating System and Platform x64. Version: 0.12.2.0 Modules
| |||||||||||||||
| (PID) Process: | (6076) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--syslcid=1033&build=16.0.16026&crev=3\0 |
| Operation: | write | Name: | FilePath |
Value: officeclient.microsoft.com\845F3DC9-2A30-4AFD-A7D7-9F1A301BB4C6 | |||
| (PID) Process: | (6076) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--syslcid=1033&build=16.0.16026&crev=3\0 |
| Operation: | write | Name: | StartDate |
Value: 508FD076F281DB01 | |||
| (PID) Process: | (6076) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--syslcid=1033&build=16.0.16026&crev=3\0 |
| Operation: | write | Name: | EndDate |
Value: 504F3AA1BB82DB01 | |||
| (PID) Process: | (6076) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Word\AddinsData\Genko.Connect12 |
| Operation: | write | Name: | LoadCount |
Value: 5 | |||
| (PID) Process: | (6076) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Word\AddInLoadTimes |
| Operation: | write | Name: | Genko.Connect12 |
Value: 040000006D0000002F0000003F0000001000000000000000 | |||
| (PID) Process: | (6076) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Word\Resiliency\StartupItems |
| Operation: | delete value | Name: | 7"% |
Value: ∷%ូ | |||
| (PID) Process: | (6076) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\WINWORD\6076 |
| Operation: | write | Name: | 0 |
Value: 0B0E100C39CA3C78F65B4B989EED115302EEB6230046BCBCDFAAA7BEE0ED016A04102400449A7D64B29D01008500A907556E6B6E6F776EC906022222CA0DA200C2190000C50E8908C91003783634C511BC2FD2120B770069006E0077006F00720064002E00650078006500C51620C517808004C91808323231322D44656300 | |||
| (PID) Process: | (6076) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\WINWORD\6076 |
| Operation: | write | Name: | 0 |
Value: 0B0E100C39CA3C78F65B4B989EED115302EEB6230046BCBCDFAAA7BEE0ED016A04102400449A7D64B29D01008500A907556E6B6E6F776EC906022222CA0D2201A200C2190000C50E8908C91003783634C511BC2FD2120B770069006E0077006F00720064002E00650078006500C51620C517808004C91808323231322D44656300 | |||
| (PID) Process: | (6076) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\word |
| Operation: | write | Name: | Expires |
Value: int64_t|0 | |||
| (PID) Process: | (6076) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\word |
| Operation: | delete value | Name: | ConfigIds |
Value: P-D-29635-1-1,P-D-27087-1-9,P-D-29719-1-1,P-D-29718-1-1,P-D-29593-1-1,P-X-46178-1-3,P-X-45046-7-9,P-E-38713-2-4,P-E-38485-C1-6,P-E-38231-C1-4,P-R-45365-2-4,P-R-41741-18-10,P-R-38306-C17-3,P-R-35717-4-26,P-R-34019-4-3,P-D-37560-2-4,extes787:4008,exnop721cf:3280,P-E-29662-2-3,P-R-46411-1-3,P-R-46410-1-3,P-R-46111-1-4,P-R-45967-1-2,P-R-45966-1-2,P-R-45965-1-2,P-R-45964-1-5,P-R-45117-4-3,P-R-44092-2-3,P-R-44090-2-3,P-R-42512-1-2,P-R-42555-2-2,P-R-42557-2-3,P-R-42418-2-3,P-R-42417-2-2,P-R-40543-18-13,P-R-40169-8-9,P-R-39747-2-3,P-R-39746-2-3,P-R-39588-2-4,P-R-39582-2-5,P-R-39574-1-3,P-R-39568-1-3,P-R-39554-1-3,P-R-39522-1-4,P-R-39521-1-3,P-R-39467-2-4,P-R-39120-18-25,P-R-38704-4-6,P-R-37389-18-16,P-R-32143-5-17,P-R-36664-4-3,P-R-36385-18-10,P-R-35973-2-3,P-R-35946-6-3,P-R-35846-8-3,P-R-35476-2-3,P-R-35407-4-3,P-R-35234-14-6,P-R-35150-2-3,P-R-35129-2-3,P-R-35101-14-3,P-R-35056-4-3,P-R-35049-4-5,P-R-34904-2-3,P-R-34889-8-3,P-R-34044-2-3,P-R-33911-4-4,P-R-33824-1-4,P-R-33786-18-5,P-R-33718-6-4,P-R-33678-2-4,P-R-33459-1-4,P-R-33197-4-7,P-R-33176-4-17,P-R-33137-1-3,P-R-33136-2-6,P-R-32252-C39-56,P-R-32240-1-7,P-R-31921-C19-59,P-R-30649-1-5,P-R-30509-18-10,P-R-30293-4-7,P-R-29310-2-5,P-R-29301-4-10,P-R-29230-2-8,P-R-29224-5-11,P-R-29207-3-7,P-R-29208-2-4,P-R-29304-2-5,P-R-29279-2-8,P-R-29204-2-5,P-R-29056-2-4,P-R-29054-2-5,P-R-29025-9-26,P-R-28999-3-9,P-R-29000-4-7,P-R-28992-8-9,P-R-28988-8-11,P-R-28984-8-11,P-R-28644-1-4,P-R-25886-3-5,P-R-24037-1-6,P-R-23445-3-6,P-R-23410-1-5,P-R-23370-2-6,P-R-23485-1-6,P-R-23434-3-6,P-R-23403-3-6,P-R-20642-2-8,P-R-20640-1-7,P-R-19608-2-12,P-R-19841-2-8,P-R-18513-1-30,P-R-19024-9-58,P-D-34699-4-3,P-D-34697-2-3,P-D-34683-6-3,P-D-34675-1-3,P-D-34673-1-3,P-D-34654-1-3,P-D-34638-1-3,P-D-34609-1-3,P-D-34607-3-3,P-D-34587-3-3,P-D-34281-1-3,P-D-34278-4-3,P-D-34266-1-3,P-D-34263-1-3,P-D-34262-1-3,P-D-34260-1-3,P-D-34258-2-3,P-D-34250-1-3,P-D-34247-5-3,P-D-34225-1-3,P-D-32487-1-3,P-D-32471-3-3,P-D-32465-1-3,P-D-32459-2-3,P-D-32458-5-3,P-D-32403-1-3,P-D-30203-1-2,P-D-30202-1-3,P-D-30201-1-2,P-D-27615-1-3,P-D-27593-1-4,P-R-44990-1-4,P-R-43597-1-3,P-R-42114-18-8,P-R-42643-18-9,P-R-39888-1-3,P-R-39119-18-31,P-R-38346-2-3,P-R-37340-12-25,P-R-35848-14-14,P-R-33661-C17-6,P-R-33115-18-21,P-R-32298-18-11,P-R-25893-1-6,P-R-25867-1-5,P-R-25316-1-6,P-R-23348-1-7,P-X-45362-1-3,P-X-42197-2-3,P-E-44774-C1-6,P-E-29661-C1-3,P-R-46701-1-3,P-R-46309-1-4,P-R-46205-1-3,P-R-45832-1-4,P-R-45584-16-7,P-R-45452-2-3,P-R-45269-1-5,P-R-44738-16-3,P-R-44068-C15-4,P-R-44058-1-3,P-R-43957-C15-3,P-R-43718-16-4,P-R-42866-16-6,P-R-42865-16-8,P-R-42702-16-10,P-R-42794-2-2,P-R-42732-16-10,P-R-42547-16-12,P-R-42356-16-8,P-R-38028-C17-32,P-R-41047-16-19,P-R-41391-1-3,P-R-41370-18-10,P-R-40791-C15-7,P-R-37391-20-19,P-R-38531-16-16,P-R-39129-2-6,P-R-29934-6-17,P-R-36893-16-15,P-R-37769-16-19,P-R-38732-16-10,P-R-37487-16-14,P-R-37773-18-33,P-R-36381-16-14,P-R-36130-54-7,P-R-36102-8-3,P-R-35880-16-20,P-R-35006-4-3,P-R-34998-6-3,P-R-34958-2-3,P-R-34091-12-13,P-R-33918-1-5,P-R-33895-1-4,P-R-33883-2-4,P-R-33875-4-4,P-R-33738-2-11,P-R-32032-3-4,P-R-32026-12-7,P-R-31600-5-4,P-R-30442-20-52,P-R-27730-2-10,P-R-26653-1-4,P-R-26642-1-4,P-D-34604-1-3,P-D-32551-1-3,P-D-32550-1-3,P-D-32472-6-3,wotes819:3296,wotes907cf:1474,P-R-33555-1-4,P-R-46377-10-5,P-R-38462-1-11,P-R-30262-9-40,P-R-36932-2-11,P-R-46186-1-4,P-R-44014-1-6,P-R-43910-1-3,P-R-43909-1-3,P-R-43644-C5-10,P-R-42448-1-3,P-R-39912-1-2,P-R-39488-C3-7,P-R-39283-4-8,P-R-36539-10-4,P-R-24084-1-12,P-R-46100-20-5,P-R-45558-2-6,P-R-45546-1-5,P-R-37550-20-7,P-R-32186-C27-24,P-R-34049-2-3,P-D-41781-1-2,P-D-41780-1-2,P-D-40447-1-3,P-D-37672-1-2,P-D-36846-1-3,P-D-36843-1-4,P-R-39146-14-11,P-R-39147-14-9,P-R-28546-6-9,P-R-28165-6-25,P-R-24390-5-8,P-R-20518-9-39,P-R-19046-2-18,P-R-18975-1-29,P-R-18279-2-64,P-D-34200-4-4,P-R-39113-22-29,P-R-35209-8-3,P-D-34664-3-3,P-R-45538-1-4,P-R-45368-1-4,P-R-44875-6-5,P-R-43085-18-8,P-R-42578-1-3,P-R-42482-1-3,P-R-41670-18-10,P-R-40990-12-12,P-R-39594-18-13,P-R-39333-C17-20,P-R-39336-18-21,P-R-35387-18-13,P-R-37272-18-10,P-R-37469-8-9,P-R-36616-14-9,P-R-35972-2-3,P-R-35968-2-3,P-R-35572-2-3,P-R-33215-18-17,P-R-32653-18-18,P-R-31352-12-17,P-R-28751-2-19,P-R-20580-8-34,P-D-34495-2-9,P-D-34269-2-3,P-E-28677-2-3,P-R-44907-5-7,P-R-41912-1-2,P-R-41699-C15-18,P-R-38702-1-3,P-E-42700-C1-4,P-R-46706-2-2,P-R-46558-2-3,P-R-45837-1-4,P-R-40106-C17-13,P-R-45197-2-6,P-R-37650-1-5,P-R-43723-2-5,P-R-39825-22-28,P-R-42920-1-8,P-R-42797-2-4,P-R-42457-18-4,P-R-32234-25-67,P-R-41994-9-19,P-R-41742-C17-22,P-R-41640-7-20,P-R-41538-2-2,P-R-40648-2-7,P-R-39029-5-17,P-R-38835-18-39,P-R-36315-10-28,P-R-38026-1-5,P-R-37492-18-8,P-R-37467-18-42,P-R-36646-6-7,P-R-36624-10-5,P-R-36575-4-5,P-R-36478-2-3,P-R-36310-4-3,P-R-35945-10-3,P-R-35436-22-13,P-R-35417-16-7,P-R-35340-16-10,P-R-35143-4-3,P-R-35043-10-5,P-R-35008-18-4,P-R-34955-16-9,P-R-34817-8-7,P-R-34748-18-27,P-R-34331-4-8,P-R-34079-12-12,P-R-33996-18-20,P-R-33994-10-5,P-R-33597-12-8,P-R-33553-4-4,P-R-32261-1-4,P-R-32239-1-5,P-R-32236-1-8,P-R-31384-1-4,P-R-29809-1-6,P-R-28464-12-11,P-R-28276-1-4,P-R-27861-1-4,P-R-26968-3-8,P-R-46232-2-2,P-R-46170-2-2,P-R-41916-C17-14,P-R-40405-1-5,P-R-39876-18-22,P-R-38085-12-9,P-R-37017-18-23,P-R-37374-9-22,P-R-36450-18-17,P-R-35907-6-3,P-R-35850-10-4,P-R-35849-4-5,P-R-35389-18-34,P-R-33530-14-9,P-R-32169-3-4,P-R-30530-8-16,P-R-30067-18-7,P-R-18744-6-21,P-D-34659-8-3,P-D-34259-2-3,P-D-34257-9-3,P-D-34239-1-3,P-R-46080-2-3,P-R-38953-1-9,P-R-36551-18-14,P-R-31346-2-6,P-R-43355-C17-5,P-R-42383-18-8,P-R-40152-18-5,P-R-39981-18-7,P-R-39509-10-13,P-R-39328-18-8,P-R-39121-18-9,P-R-38296-18-11,P-R-38167-18-12,P-R-37675-8-25,P-R-37667-12-16,P-R-35869-18-9,P-R-35665-12-3,P-R-35337-16-5,P-R-35203-4-3,P-R-33916-1-4,P-R-33741-4-4,P-R-33739-1-4,P-R-33580-C7-7,P-R-33575-1-5,P-R-33560-4-4,P-R-32042-2-13,P-R-31966-3-10,P-R-31960-7-4,P-R-31949-4-4,P-R-31948-8-7,P-R-31946-3-4,P-R-20347-4-21,P-R-46404-2-2,P-R-40475-18-13,P-R-37668-C25-43,P-R-35891-18-3,P-R-32433-18-16,P-R-32004-2-4,P-R-38410-18-22,P-R-37609-18-12,P-R-20504-8-18,P-R-43232-1-15,P-R-42696-18-10,P-R-35680-8-4,P-R-32106-7-27,P-R-30085-1-8,P-R-30011-15-17,P-R-29138-38-73,P-R-29315-36-59,P-R-28033-14-54,P-R-25157-8-12,P-R-19898-1-20,P-R-19814-1-53,P-R-19262-2-12,P-R-35109-4-3,P-R-23378-2-6,P-R-45595-2-4,P-R-41433-18-25,P-R-40253-6-18,P-R-40254-6-17,P-R-35412-4-3,P-R-32107-22-21,P-R-32704-1-4,P-R-26006-3-5,P-R-34130-6-3,P-R-44921-2-2,P-R-40407-18-5,P-R-37603-3-6,P-R-36477-6-3,P-R-35887-18-9,P-R-35489-16-7,P-R-35454-16-5,P-R-35073-4-3,P-R-33746-2-6,P-R-40464-18-5,P-R-39227-18-8,P-R-37589-1-3,P-R-42510-1-3,P-R-41441-10-18,P-R-39073-1-5,P-R-38719-10-29,P-R-35442-2-6,P-R-28753-1-9,P-R-27070-1-4,P-R-26515-4-14,P-R-45019-1-4,P-R-32703-10-10,P-R-33970-10-7,P-R-33969-10-7,P-R-45554-1-3,P-R-44835-1-3,P-R-33737-1-4,P-R-35623-2-3,P-R-26442-1-7,P-R-23681-2-7,P-D-32502-2-3,P-D-32501-2-3,P-D-32415-2-3,P-R-46845-1-3,P-R-46844-1-3,P-R-46841-1-3,P-R-46580-3-5,P-R-46484-1-3,P-R-46233-1-3,P-R-46122-1-3,P-R-46121-3-5,P-R-46068-2-4,P-R-46067-2-4,P-R-46066-2-4,P-R-46065-2-4,P-R-46064-2-4,P-R-46062-2-4,P-R-46060-2-4,P-R-46059-2-4,P-R-46058-2-4,P-R-46056-2-4,P-R-46055-2-4,P-R-46054-2-4,P-R-46041-2-4,P-R-45865-2-6,P-R-45858-1-3,P-R-45241-1-3,P-R-44950-1-3,P-R-43966-1-3,P-R-43502-5-7,P-R-43238-3-5,P-R-43188-2-4,P-R-43094-8-10,P-R-42949-1-3,P-R-42635-1-3,P-R-42122-1-3,P-R-38248-7-11,P-R-41430-1-3,P-R-41033-2-4,P-R-40892-1-3,P-R-39375-2-6,P-R-40751-3-5,P-R-40273-3-5,P-R-39238-1-3,P-R-39045-1-3,P-R-38878-1-3,P-R-38682-2-4,P-R-37588-1-3,P-R-35713-2-4,P-R-35675-1-3,P-R-35606-3-5,P-R-35373-1-3,P-R-34355-4-6,P-R-23737-6-9,P-R-26211-3-9,P-R-26266-3-8,P-R-23733-14-19,P-R-26834-2-7,P-R-24662-12-18,P-R-27205-3-10,P-R-27299-2-7,P-R-27479-5-10,P-R-26056-5-13,P-R-27006-6-11,P-R-23722-17-22,P-R-32191-3-5,P-R-30338-1-5,P-R-30178-9-11,P-R-30053-2-4,P-R-27458-1-5,P-R-26722-6-8,P-R-25822-7-10,P-R-25653-1-4,P-R-25269-6-9,P-R-25083-5-8,P-R-24690-10-14,P-R-24689-1-4,P-R-24666-1-4,P-R-24663-3-8,P-R-24659-6-9,P-R-24658-3-6,P-R-23762-5-7,P-R-23747-6-8,P-R-23746-13-16,P-R-23744-6-8,P-R-23743-8-10,P-R-23741-7-9,P-R-23740-7-9,P-R-23739-6-8,P-R-23738-9-11,P-R-23736-11-13,P-R-23734-7-9,P-R-23732-7-9,P-R-23731-7-9,P-R-23730-15-18,P-R-23729-7-9,P-R-23728-7-9,P-R-23725-6-8,P-R-23723-6-8,P-R-23718-6-8,P-R-23717-7-9,P-R-23715-7-9,P-R-23714-8-10,P-R-23713-7-9,P-D-32589-1-3,P-D-32588-1-3,P-D-32534-1-3,P-D-32524-1-3,P-D-32518-1-3,P-D-32512-1-3,P-D-32509-1-3,P-D-32504-1-3,P-D-32486-1-3,P-D-32485-1-3,P-D-32484-1-3,P-D-32405-1-3,P-R-29928-1-13,P-R-26544-7-57,P-R-40220-1-4,P-R-35099-2-3,P-E-29576-C1-7,P-E-29325-2-4,P-R-40586-18-25,P-R-40732-18-13,P-R-39143-18-20,P-D-40316-9-3,P-R-35513-4-3,P-R-33892-1-4,P-R-33696-1-4,P-R-33569-1-6,P-R-31987-1-4,P-R-33504-1-4,P-R-42379-2-2,P-R-42378-2-2 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6076 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\~$-56-ns 056374TI.docx | binary | |
MD5:FB1308BF0F6FF2E5A7F557E0C01955B2 | SHA256:59B34AFFC0E0E1AF82FB3E9B87C87D95E202251573A4379D492375FA54D8413E | |||
| 6076 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntities.bin | text | |
MD5:CC90D669144261B198DEAD45AA266572 | SHA256:89C701EEFF939A44F28921FD85365ECD87041935DCD0FE0BAF04957DA12C9899 | |||
| 6076 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbres | binary | |
MD5:014FED837D7F1667CE77094C1BA13550 | SHA256:6B64ABE17317B04EE54A9E69ABA1F63ED7E92BB07E1A8D82FEBB14EBF41F1957 | |||
| 6076 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\845F3DC9-2A30-4AFD-A7D7-9F1A301BB4C6 | xml | |
MD5:18904BF9C01E0C1A40D87769ECA0A5D1 | SHA256:9C5B7A23B2271F0FADFABD90D5893FD08A6EE7C9320723D90B11728022C1A7B3 | |||
| 6076 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Office\16.0\ResourceInfoCache\data.json | binary | |
MD5:B428ED07B152EA57A6A616219B62D258 | SHA256:0AAC93F65804A99AE970067ABA7BD69C3AA4B17700F7D0DE628D468CD1B3F80C | |||
| 6076 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbres | binary | |
MD5:D1B8DD3326894694DFCB6C0629460371 | SHA256:FB850626418975EB6815172AF5B88A08F25466E663E3E881F1C0D55F2C4F4AFB | |||
| 6076 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Office\16.0\ResourceInfoCache\07fc2a8c43a1d1f16572d21e959a4847e306edae.temp | binary | |
MD5:B428ED07B152EA57A6A616219B62D258 | SHA256:0AAC93F65804A99AE970067ABA7BD69C3AA4B17700F7D0DE628D468CD1B3F80C | |||
| 6076 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | binary | |
MD5:FF4F791A07B4555F8CC64BC25257D912 | SHA256:DC5A7F44EF35C88B0E42C2F4C272446A92E978623FAE8823EF482C8E56FA5498 | |||
| 6076 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{847B5865-A5EA-436B-AF35-B1A00ABD0A8C}.tmp | binary | |
MD5:830FBF83999E052538EAF156AB6ECB17 | SHA256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869 | |||
| 6076 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\31015644.emf | binary | |
MD5:DAE610088EB0C82172D23D0F3BF6D75A | SHA256:9923CB4BF7A5FBB9C22512A2431582DF95A92F67868FF26CBC80BFECBB667DB7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6076 | WINWORD.EXE | GET | 200 | 142.250.184.227:80 | http://c.pki.goog/r/gsr1.crl | unknown | — | — | whitelisted |
6076 | WINWORD.EXE | GET | 200 | 142.250.184.227:80 | http://c.pki.goog/r/r4.crl | unknown | — | — | whitelisted |
6076 | WINWORD.EXE | HEAD | 200 | 217.160.17.80:80 | http://217.160.17.80/231/cnm/cmnc/kissingdragonbestloverthinkinggoodkissingdragonbest_______kissingdragonbestloverthinkinggoodoverthink_______overthinkinggoodover.doc | unknown | — | — | unknown |
6076 | WINWORD.EXE | GET | 200 | 217.160.17.80:80 | http://217.160.17.80/231/cnm/cmnc/kissingdragonbestloverthinkinggoodkissingdragonbest_______kissingdragonbestloverthinkinggoodoverthink_______overthinkinggoodover.doc | unknown | — | — | unknown |
6076 | WINWORD.EXE | HEAD | 200 | 217.160.17.80:80 | http://217.160.17.80/231/cnm/cmnc/kissingdragonbestloverthinkinggoodkissingdragonbest_______kissingdragonbestloverthinkinggoodoverthink_______overthinkinggoodover.doc | unknown | — | — | unknown |
3700 | svchost.exe | GET | 200 | 23.53.40.176:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
3700 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6076 | WINWORD.EXE | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3700 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1864 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6076 | WINWORD.EXE | 52.109.76.240:443 | officeclient.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6076 | WINWORD.EXE | 52.123.130.14:443 | ecs.office.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6076 | WINWORD.EXE | 23.48.23.63:443 | omex.cdn.office.net | Akamai International B.V. | DE | whitelisted |
6076 | WINWORD.EXE | 188.114.96.3:443 | al4.dev | CLOUDFLARENET | NL | unknown |
6076 | WINWORD.EXE | 142.250.184.227:80 | c.pki.goog | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
officeclient.microsoft.com |
| whitelisted |
ecs.office.com |
| whitelisted |
omex.cdn.office.net |
| whitelisted |
al4.dev |
| unknown |
c.pki.goog |
| whitelisted |
messaging.lifecycle.office.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6076 | WINWORD.EXE | Potentially Bad Traffic | ET INFO Dotted Quad Host DOC Request |
6076 | WINWORD.EXE | Potentially Bad Traffic | ET INFO Dotted Quad Host DOC Request |
6076 | WINWORD.EXE | Potentially Bad Traffic | ET HUNTING Microsoft Office User-Agent Requesting A Doc File |
6076 | WINWORD.EXE | Potentially Bad Traffic | ET INFO Dotted Quad Host DOC Request |
6076 | WINWORD.EXE | Misc activity | ET USER_AGENTS Microsoft Office Existence Discovery User-Agent |
Process | Message |
|---|---|
WINWORD.EXE | WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
|
WINWORD.EXE | WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
|
WINWORD.EXE | WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
|