File name:

WINWORD.EXE

Full analysis: https://app.any.run/tasks/6702634b-e77c-43e5-a94e-26d9aaf0861c
Verdict: Malicious activity
Analysis date: August 05, 2021, 06:38:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

15E52F52ED2B8ED122FAE897119687C4

SHA1:

6E35AE1D5B6F192109D7A752ACD939F5CA2B97A6

SHA256:

8CFB55087FA8E4C1E7BCC580D767CF2C884C1B8C890AD240C1E7009810AF6736

SSDEEP:

24576:wLZmQR3caJZLZmvNzc0TDZodoSRsfHMbvmQakU:8ZmQyaJ1ZmFcqi+SRAG+J

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • msiexec.exe (PID: 2316)
      • MsiExec.exe (PID: 3360)
      • MsiExec.exe (PID: 3548)
      • MsiExec.exe (PID: 2528)
      • MsiExec.exe (PID: 3964)
      • MsiExec.exe (PID: 2620)
      • MsiExec.exe (PID: 2472)
      • MsiExec.exe (PID: 2904)
      • Setup.exe (PID: 288)
      • MsiExec.exe (PID: 4020)
    • Loads dropped or rewritten executable

      • Setup.exe (PID: 288)
  • SUSPICIOUS

    • Executed via COM

      • Setup.exe (PID: 288)
    • Checks supported languages

      • Setup.exe (PID: 288)
      • WINWORD.EXE (PID: 4092)
      • msohtmed.exe (PID: 3540)
      • MSIB786.tmp (PID: 3984)
      • addinutil.exe (PID: 2116)
      • addinutil.exe (PID: 476)
    • Executable content was dropped or overwritten

      • Setup.exe (PID: 288)
      • MsiExec.exe (PID: 3360)
      • MsiExec.exe (PID: 3548)
      • msiexec.exe (PID: 2316)
      • MsiExec.exe (PID: 2528)
      • MsiExec.exe (PID: 3964)
      • MsiExec.exe (PID: 2620)
      • MsiExec.exe (PID: 2472)
      • MsiExec.exe (PID: 2904)
      • MsiExec.exe (PID: 4020)
      • MsiExec.exe (PID: 3236)
    • Reads the computer name

      • WINWORD.EXE (PID: 4092)
      • Setup.exe (PID: 288)
    • Drops a file that was compiled in debug mode

      • Setup.exe (PID: 288)
      • MsiExec.exe (PID: 3360)
      • MsiExec.exe (PID: 3548)
      • msiexec.exe (PID: 2316)
      • MsiExec.exe (PID: 2528)
      • MsiExec.exe (PID: 3964)
      • MsiExec.exe (PID: 2620)
      • MsiExec.exe (PID: 2472)
      • MsiExec.exe (PID: 2904)
      • MsiExec.exe (PID: 4020)
      • MsiExec.exe (PID: 3236)
    • Executed as Windows Service

      • msiexec.exe (PID: 2316)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 2316)
    • Application launched itself

      • msiexec.exe (PID: 2316)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 2316)
    • Drops a file with too old compile date

      • MsiExec.exe (PID: 3360)
      • MsiExec.exe (PID: 3548)
      • msiexec.exe (PID: 2316)
      • MsiExec.exe (PID: 2528)
      • MsiExec.exe (PID: 3964)
      • MsiExec.exe (PID: 2620)
      • MsiExec.exe (PID: 2472)
      • MsiExec.exe (PID: 2904)
      • MsiExec.exe (PID: 4020)
      • MsiExec.exe (PID: 3236)
    • Creates files in the program directory

      • MsiExec.exe (PID: 560)
      • MsiExec.exe (PID: 2076)
      • MsiExec.exe (PID: 3456)
      • MsiExec.exe (PID: 1148)
      • MsiExec.exe (PID: 3832)
      • MsiExec.exe (PID: 3712)
      • MsiExec.exe (PID: 3440)
      • MsiExec.exe (PID: 2536)
      • MsiExec.exe (PID: 124)
    • Searches for installed software

      • msiexec.exe (PID: 2316)
      • Setup.exe (PID: 288)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2316)
    • Changes default file association

      • msiexec.exe (PID: 2316)
      • msohtmed.exe (PID: 3540)
    • Reads default file associations for system extensions

      • msiexec.exe (PID: 2316)
    • Starts Microsoft Office Application

      • msiexec.exe (PID: 2316)
    • Disables SEHOP

      • msiexec.exe (PID: 2316)
    • Creates/Modifies COM task schedule object

      • msohtmed.exe (PID: 3540)
      • msiexec.exe (PID: 2316)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 4092)
  • INFO

    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 4092)
      • Setup.exe (PID: 288)
      • msiexec.exe (PID: 2316)
      • MsiExec.exe (PID: 3236)
      • msohtmed.exe (PID: 3540)
    • Reads settings of System Certificates

      • Setup.exe (PID: 288)
    • Checks supported languages

      • msiexec.exe (PID: 2316)
      • MsiExec.exe (PID: 3360)
      • MsiExec.exe (PID: 560)
      • MsiExec.exe (PID: 2964)
      • MsiExec.exe (PID: 2076)
      • MsiExec.exe (PID: 3548)
      • MsiExec.exe (PID: 2528)
      • MsiExec.exe (PID: 3456)
      • MsiExec.exe (PID: 3964)
      • MsiExec.exe (PID: 3832)
      • MsiExec.exe (PID: 1148)
      • MsiExec.exe (PID: 3816)
      • MsiExec.exe (PID: 3108)
      • MsiExec.exe (PID: 3696)
      • MsiExec.exe (PID: 2620)
      • MsiExec.exe (PID: 2472)
      • MsiExec.exe (PID: 3832)
      • MsiExec.exe (PID: 3712)
      • MsiExec.exe (PID: 3828)
      • MsiExec.exe (PID: 2904)
      • MsiExec.exe (PID: 3440)
      • MsiExec.exe (PID: 4020)
      • MsiExec.exe (PID: 3236)
      • MsiExec.exe (PID: 124)
      • MsiExec.exe (PID: 2536)
    • Reads the computer name

      • msiexec.exe (PID: 2316)
      • MsiExec.exe (PID: 3360)
      • MsiExec.exe (PID: 560)
      • MsiExec.exe (PID: 3548)
      • MsiExec.exe (PID: 2964)
      • MsiExec.exe (PID: 2076)
      • MsiExec.exe (PID: 2528)
      • MsiExec.exe (PID: 3456)
      • MsiExec.exe (PID: 3964)
      • MsiExec.exe (PID: 3832)
      • MsiExec.exe (PID: 1148)
      • MsiExec.exe (PID: 3816)
      • MsiExec.exe (PID: 3108)
      • MsiExec.exe (PID: 2620)
      • MsiExec.exe (PID: 3696)
      • MsiExec.exe (PID: 3832)
      • MsiExec.exe (PID: 2472)
      • MsiExec.exe (PID: 3712)
      • MsiExec.exe (PID: 3828)
      • MsiExec.exe (PID: 2904)
      • MsiExec.exe (PID: 4020)
      • MsiExec.exe (PID: 3440)
      • MsiExec.exe (PID: 124)
      • MsiExec.exe (PID: 3236)
      • MsiExec.exe (PID: 2536)
    • Checks Windows Trust Settings

      • Setup.exe (PID: 288)
    • Starts application with an unusual extension

      • msiexec.exe (PID: 2316)
    • Application was dropped or rewritten from another process

      • MSIB786.tmp (PID: 3984)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (54.3)
.exe | Win64 Executable (generic) (34.8)
.exe | Win32 Executable (generic) (5.6)
.exe | Generic Win/DOS Executable (2.5)
.exe | DOS Executable Generic (2.5)

EXIF

EXE

ProductVersion: 14.0.4762.1000
ProductName: Microsoft Office 2010
OriginalFileName: WinWord.exe
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalCopyright: © 2010 Microsoft Corporation. All rights reserved.
InternalName: WinWord
FileVersion: 14.0.4762.1000
FileDescription: Microsoft Word
CompanyName: Microsoft Corporation
CharacterSet: Windows, Latin1
LanguageCode: Neutral
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 14.0.4762.0
FileVersionNumber: 14.0.4762.1000
Subsystem: Windows GUI
SubsystemVersion: 5.1
ImageVersion: 10
OSVersion: 5.1
EntryPoint: 0x10ec
UninitializedDataSize: -
InitializedDataSize: 1408000
CodeSize: 7680
LinkerVersion: 9
PEType: PE32
TimeStamp: 2010:03:27 16:35:19+01:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 27-Mar-2010 15:35:19
Detected languages:
  • English - United States
Debug artifacts:
  • t:\word\x86\ship\0\winword.pdb
CompanyName: Microsoft Corporation
FileDescription: Microsoft Word
FileVersion: 14.0.4762.1000
InternalName: WinWord
LegalCopyright: © 2010 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: Microsoft Office 2010
ProductVersion: 14.0.4762.1000

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000100

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 4
Time date stamp: 27-Mar-2010 15:35:19
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00001C28
0x00001E00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
5.90243
.data
0x00003000
0x000003B4
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0.226296
.rsrc
0x00004000
0x00157374
0x00157400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.89546
.reloc
0x0015C000
0x00000208
0x00000400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
4.09191

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.50471
3402
Latin 1 / Western European
English - United States
RT_MANIFEST
2
2.92564
132
Latin 1 / Western European
English - United States
RT_GROUP_ICON
3
5.74467
3752
Latin 1 / Western European
English - United States
RT_ICON
4
2.97632
132
Latin 1 / Western European
English - United States
RT_GROUP_ICON
5
2.97632
132
Latin 1 / Western European
English - United States
RT_GROUP_ICON
6
2.9359
132
Latin 1 / Western European
English - United States
RT_GROUP_ICON
7
2.947
118
Latin 1 / Western European
English - United States
RT_GROUP_ICON
8
3.04429
160
Latin 1 / Western European
English - United States
RT_GROUP_ICON
9
2.55805
34
Latin 1 / Western European
English - United States
RT_GROUP_ICON
10
4.97252
4264
Latin 1 / Western European
English - United States
RT_ICON

Imports

KERNEL32.dll
MSVCR90.dll

Exports

Title
Ordinal
Address
wdCommandDispatch
1
0x00001F66
wdGetApplicationObject
2
0x00001F70
DllGetLCID
3
0x0000264A
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
31
Malicious processes
4
Suspicious processes
8

Behavior graph

Click at the process to see the details
start drop and start winword.exe no specs setup.exe msiexec.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs msohtmed.exe no specs msib786.tmp no specs addinutil.exe addinutil.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124C:\Windows\system32\MsiExec.exe -Embedding F58FFA149D1F9A2A48B0E8FAB7394763 E Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
288"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Setup.exe" -EmbeddingC:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Setup.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Setup Bootstrapper
Exit code:
0
Version:
14.0.6010.1000
Modules
Images
c:\program files\common files\microsoft shared\office14\office setup controller\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
476"C:\Windows\Microsoft.NET\Framework\v3.5\addinutil.exe" -AddInRoot:"C:\Program Files\Common Files\Microsoft Shared\VSTA\AppInfoDocument\." -RebuildC:\Windows\Microsoft.NET\Framework\v3.5\addinutil.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
AddInUtil.exe
Exit code:
0
Version:
3.5.30729.5420 built by: Win7SP1
Modules
Images
c:\windows\microsoft.net\framework\v3.5\addinutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
560C:\Windows\system32\MsiExec.exe -Embedding A051FC0EBB8E1BCE81C12933D0A79F12 E Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\sechost.dll
1148C:\Windows\system32\MsiExec.exe -Embedding 7F67C0E8DD31B6E5C1F9466E12DC718C E Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2076C:\Windows\system32\MsiExec.exe -Embedding B6926F52A4DB33FD5F6E4CF8F1954917 E Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2116"C:\Windows\Microsoft.NET\Framework\v3.5\addinutil.exe" -PipelineRoot:"C:\Program Files\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\." -RebuildC:\Windows\Microsoft.NET\Framework\v3.5\addinutil.exe
MsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
AddInUtil.exe
Exit code:
0
Version:
3.5.30729.5420 built by: Win7SP1
Modules
Images
c:\windows\microsoft.net\framework\v3.5\addinutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2316C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2472C:\Windows\system32\MsiExec.exe -Embedding E5ACD9CD6177F7866658C9466B744F43C:\Windows\system32\MsiExec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2528C:\Windows\system32\MsiExec.exe -Embedding 81F0C7D47DA39AF5183581E5A16BE168C:\Windows\system32\MsiExec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
Total events
97 571
Read events
83 992
Write events
12 634
Delete events
945

Modification events

(PID) Process:(4092) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:writeName:7w8
Value:
37773800FC0F0000010000000000000000000000
(PID) Process:(4092) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(4092) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
Off
(PID) Process:(4092) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
Off
(PID) Process:(4092) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
Off
(PID) Process:(4092) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
Off
(PID) Process:(4092) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
Off
(PID) Process:(4092) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
Off
(PID) Process:(4092) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
Off
(PID) Process:(4092) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
Off
Executable files
210
Suspicious files
88
Text files
6
Unknown types
43

Dropped files

PID
Process
Filename
Type
4092WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR2B97.tmp.cvr
MD5:
SHA256:
2316msiexec.exeC:\Users\admin\AppData\Local\Temp\~DFC26AD091356F3E02.TMPgmc
MD5:
SHA256:
288Setup.exeC:\Users\admin\AppData\Local\Temp\SetupExe(20210805073842120).logtext
MD5:
SHA256:
2316msiexec.exeC:\Windows\Installer\MSI39A3.tmpbinary
MD5:
SHA256:
2316msiexec.exeC:\Windows\Installer\MSI386A.tmpexecutable
MD5:CB6AAB53E5D4893327ADE765CFF283F2
SHA256:A0DBBA68F7B3FBFF7FE368F5478AE60D2D840158ED0E70FF0A1C48C305D8F986
288Setup.exeC:\Users\admin\AppData\Local\Temp\Setup00000120\SETUP.CHMchm
MD5:CB8F14C8B37BA69F361E33E30E8EBC74
SHA256:C777301E71BFE4AE0D7355D5D4DF8ED4DDC437D59079C214173F1A29EE312210
288Setup.exeC:\Users\admin\AppData\Local\Temp\Setup00000120\BRANDING.XMLxml
MD5:10B211A922F7CA1A15B98F595A10A7BD
SHA256:01B34D2E5BE5247D802D5E1EEC1C641B55B8959243C27163500511D55FF51DA0
2316msiexec.exeC:\Windows\Installer\133898.ipibinary
MD5:
SHA256:
2316msiexec.exeC:\Windows\Installer\MSI3AF0.tmpexecutable
MD5:33908AA43AC0AAABC06A58D51B1C2CCA
SHA256:4447FAACEFABA8F040822101E2A4103031660DE9139E70ECFF9AA3A89455A783
2316msiexec.exeC:\Windows\Installer\MSI3A32.tmpexecutable
MD5:33908AA43AC0AAABC06A58D51B1C2CCA
SHA256:4447FAACEFABA8F040822101E2A4103031660DE9139E70ECFF9AA3A89455A783
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
addinutil.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
addinutil.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
addinutil.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
addinutil.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
addinutil.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
addinutil.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
addinutil.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
addinutil.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
addinutil.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
addinutil.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144