| File name: | Opticsense New Order.doc |
| Full analysis: | https://app.any.run/tasks/d5bf6087-2d53-431a-b00e-0a9789ea3b31 |
| Verdict: | No threats detected |
| Analysis date: | April 22, 2019, 09:23:55 |
| OS: | Windows 10 Professional (build: 16299, 64 bit) |
| Tags: | |
| MIME: | application/octet-stream |
| File info: | Microsoft OOXML |
| MD5: | 56FF38D5A61F29004C1EE68FFD4F29D1 |
| SHA1: | 4D6AC6C867D22D5E54499606B9705FF126A587E7 |
| SHA256: | 385966F3D6BE7B234A790E2DFA2573F1AB1BC72E78BCE73BB479A11A54784C73 |
| SSDEEP: | 384:Vn7a+ji3wma9ymIOE2mvrGy8rxa504edTUU5ij9DvfcMG3Pb1SwRjVyBWTmmW1PT:JYdtO3mvrGdxo01dTxc9DvfcMAxSKQmU |
| .docm | | | Word Microsoft Office Open XML Format document (with Macro) (53.6) |
|---|---|---|
| .docx | | | Word Microsoft Office Open XML Format document (24.2) |
| .zip | | | Open Packaging Conventions container (18) |
| .zip | | | ZIP compressed archive (4.1) |
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 1980:01:01 00:00:00 |
| ZipCRC: | 0x0c0cc35b |
| ZipCompressedSize: | 392 |
| ZipUncompressedSize: | 1505 |
| ZipFileName: | [Content_Types].xml |
| Template: | Normal.dotm |
|---|---|
| TotalEditTime: | - |
| Pages: | 1 |
| Words: | - |
| Characters: | - |
| Application: | Microsoft Office Word |
| DocSecurity: | None |
| Lines: | 1 |
| Paragraphs: | - |
| ScaleCrop: | No |
| HeadingPairs: |
|
| TitlesOfParts: | - |
| Company: | - |
| LinksUpToDate: | No |
| CharactersWithSpaces: | - |
| SharedDoc: | No |
| HyperlinksChanged: | No |
| AppVersion: | 16 |
| Keywords: | - |
| LastModifiedBy: | Gertrud Leon |
| RevisionNumber: | 2 |
| CreateDate: | 2019:04:22 08:03:00Z |
| ModifyDate: | 2019:04:22 08:03:00Z |
| Title: | - |
|---|---|
| Subject: | - |
| Creator: | Gertrud Leon |
| Description: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2484 | "C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\admin\Desktop\Opticsense New Order.doc" /o "" | C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 16.0.11328.20158 Modules
| |||||||||||||||
| (PID) Process: | (2484) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry\Sampling |
| Operation: | write | Name: | 0 |
Value: 017012000000001000BE4E402C03000000000000000300000000000000 | |||
| (PID) Process: | (2484) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | en-US |
Value: 2 | |||
| (PID) Process: | (2484) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | en-US |
Value: 1 | |||
| (PID) Process: | (2484) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | l&5 |
Value: 6C263500B40900000100000000000000F0A1D726EDF8D40100000000 | |||
| (PID) Process: | (2484) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | |&5 |
Value: 7C263500B409000000000440010000005A01DA26EDF8D401D2060000E9E79F715343C345A0834C1CBF7CEFB85A01DA26EDF8D4010000000000001000BE4E402C0000000006000000000000000200000000000000000000000000556E6B6E6F776E00000000000000000000000000000000000000000000000000000000000000000000000000000000000DF0ADDE0DF0ADDE0DF0ADDE0DF0ADDE440045004600410055004C0054000000000045830702000002000000FF7F00000000000000000000000000000000000088AFEF7FFA000000200000000000000030000000000000002BAB253BFF7F000000000000000000003000000000000000C0123983070200000000000000000000000039830702000048206285070200001000000000000000200000000000000040000000000000002BAB253BFF7F00004000000000000000C00C3983070200003C00000000000000400000000000000010206285070200000000000000000000C01539830702000000000000FF7F00000000398307020000A06A538507020000400000000000000030000000000000000000458307020000D289025BFF7F00004000000000000000C00C3983070200000700000000000000700000000000000040AEEF7FFA000000000000000000000000000000000000002C0000000000000000000000000000000700000000000000700000000000000060000000000000000000458307020000D289025BFF7F0000400000000000000000000000FA000000600000000000000000000000FA000000C01539830702000000000000000000000000398307020000A06A53850702000030000000000000002BAB253BFF7F000030000000000000007668025BFF7F000050AEEF7FFA000000C00C398307020000330000000000000070000000000000003000000000000000440045004600410055004C0054000000A20000000000000000000000000000000700000000000000700000000000000060000000000000000000458307020000D289025BFF7F0000400000000000000000000000070200006000000000000000000000000000000000004583070200009CBB025BFF7F0000F006000000000000020000000000000000000000000000009D29163BFF7F00004000000000000000C00C39830702000000000000070200000000000000000000000000000000000001000000000000000000000000000000C0615485070200001000000000000000D00000007B0100000000000000000000B061548507020000B061548507020000FF030000FF7F000080000000000000008006000000000000E100000000000000E100000000000000E100000000000000CFA2253BFF7F00006000000000000000000000000000000000000000000000000000000000000000E656FFFF6D0000000000000055FFFFFF3000000000000000F0B74583070200005001458307020000500100000000000049B0EF7FFA000000000000000000000004B8458307020000E1000000000000003081538507020000FEFFFFFFFFFFFFFF706A538507020000A0BC4B83070200002C00000000000000A0735385070200002C00000000000000F00600000000000038822C3BFF7F00007668025BFF7F0000E1000000000000001400000000000000440045004600410055004C005400000049B0EF7FFA00000002000002FF7F0000040000000000000010B0EF7FFA0000001020628507020000FB0100FAFF7F0000040000000000000089A90828FF7F000048B0EF7FFA00000002000002FA00000038822C3BFF7F000020B1EF7FFA00000000000000000000007668025BFF7F0000A0DB588507020000FB0100FAFA000000E0EB4E8307020000149E253BFF7F000088B1EF7FFA00000020B0EF7FFA00000068E42C3BFF7F000040E42C3BFF7F000000000000000000000000000000000000A20000000000000000000000000000006F00000000000000F0060000000000000000458307020000AB8E025BFF7F000000004583070200000200000000000000E006000000000000F006000000000000880645830702000048B0EF7FFA000000103C59850702000003000000FF7F0000FEFFFFFFFFFFFFFF000000000000000018B1EF7FFA00000046F4133BFF7F0000903A598507020000E658EA35FF7F00000000000000000000F0F5528507020000C012398307020000E658EA35FF7F0000016D100000000000F0EE6F31FF7F0000A20000000000000000000000000000000800000000000000C3486C35FF7F00003062548507020000E006000000000000F0B4EF7FFA0000000000000000000000C061548507020000CB4B6C35FF7F0000D061548507020000F0B4EF7FFA000000D32DF4B817F8D401000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2484) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2484) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2484) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2484) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2484) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\LCCache\WordDocParts\1033 |
| Operation: | delete value | Name: | NextUpdate |
Value: D99C263528E7D401 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2484 | WINWORD.EXE | C:\Users\admin\Desktop\~$ticsense New Order.doc | pgc | |
MD5:— | SHA256:— | |||
| 2484 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\Opticsense New Order.doc.LNK | lnk | |
MD5:— | SHA256:— | |||
| 2484 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2484 | WINWORD.EXE | GET | 200 | 13.107.3.128:443 | https://config.edge.skype.com/config/v1/Office/16.0.11328.20158?&Clientid=%7bD61AB268-C26A-439D-BB15-2A0DEDFCA6A3%7d&Application=word&Platform=win32&Version=16.0.11328.20158&MsoVersion=16.0.11328.20156&Audience=Production&Build=ship&Architecture=x64&Language=en-US&SubscriptionLicense=false&PerpetualLicense=2019&Channel=CC&InstallType=C2R&SessionId=%7b719FE7E9-4353-45C3-A083-4C1CBF7CEFB8%7d&LabMachine=false | US | text | 56.7 Kb | malicious |
2484 | WINWORD.EXE | POST | 200 | 52.114.77.33:443 | https://self.events.data.microsoft.com/OneCollector/1.0/ | IE | text | 52 b | whitelisted |
2484 | WINWORD.EXE | POST | 200 | 52.114.77.33:443 | https://self.events.data.microsoft.com/OneCollector/1.0/ | IE | text | 9 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2484 | WINWORD.EXE | 13.107.3.128:443 | config.edge.skype.com | Microsoft Corporation | US | whitelisted |
2484 | WINWORD.EXE | 52.114.77.33:443 | self.events.data.microsoft.com | Microsoft Corporation | IE | suspicious |
Domain | IP | Reputation |
|---|---|---|
config.edge.skype.com |
| malicious |
self.events.data.microsoft.com |
| whitelisted |