| File name: | ValspeQ 4.12.2 - Release Note-Installation Instructions.docx |
| Full analysis: | https://app.any.run/tasks/fd54b835-885c-4a20-a3ca-ca7b99688e68 |
| Verdict: | No threats detected |
| Analysis date: | December 03, 2019, 17:47:03 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| MIME: | application/vnd.openxmlformats-officedocument.wordprocessingml.document |
| File info: | Microsoft Word 2007+ |
| MD5: | FD61FA9013819FCAB27BE15E58BB01E9 |
| SHA1: | B4B70E34DED5053DF8DC03D40A99B6B72B7B7171 |
| SHA256: | 9B7B4BDA70D9DBB306B9E1ABDCCFFEDE878116C07882DE4D01561BF87BC04D0A |
| SSDEEP: | 3072:u8X5IlNLZpSvHJSEBVC+V2w9JlUwZABixMbrdQr/WgSmjv4HfoFFb7:uEcnYpvcQ21wuBiGBffof7 |
| .docx | | | Word Microsoft Office Open XML Format document (52.2) |
|---|---|---|
| .zip | | | Open Packaging Conventions container (38.8) |
| .zip | | | ZIP compressed archive (8.8) |
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0006 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 1980:01:01 00:00:00 |
| ZipCRC: | 0xef82bec4 |
| ZipCompressedSize: | 423 |
| ZipUncompressedSize: | 2019 |
| ZipFileName: | [Content_Types].xml |
| Creator: | Alfredo Castravelli |
|---|
| LastModifiedBy: | Castravelli, Alfredo (Baker Hughes) |
|---|---|
| RevisionNumber: | 2 |
| CreateDate: | 2019:10:17 17:14:00Z |
| ModifyDate: | 2019:10:17 17:14:00Z |
| Template: | Normal.dotm |
| TotalEditTime: | - |
| Pages: | 2 |
| Words: | 170 |
| Characters: | 973 |
| Application: | Microsoft Office Word |
| DocSecurity: | None |
| Lines: | 8 |
| Paragraphs: | 2 |
| ScaleCrop: | No |
| HeadingPairs: |
|
| TitlesOfParts: | |
| Company: | GE |
| LinksUpToDate: | No |
| CharactersWithSpaces: | 1141 |
| SharedDoc: | No |
| HyperlinksChanged: | No |
| AppVersion: | 16 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 504 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\ValspeQ 4.12.2 - Release Note-Installation Instructions.docx" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| (PID) Process: | (504) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | 2a |
Value: 7F326100F8010000010000000000000000000000 | |||
| (PID) Process: | (504) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (504) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1041 |
Value: Off | |||
| (PID) Process: | (504) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1046 |
Value: Off | |||
| (PID) Process: | (504) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1036 |
Value: Off | |||
| (PID) Process: | (504) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1031 |
Value: Off | |||
| (PID) Process: | (504) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1040 |
Value: Off | |||
| (PID) Process: | (504) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1049 |
Value: Off | |||
| (PID) Process: | (504) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 3082 |
Value: Off | |||
| (PID) Process: | (504) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | WORDFiles |
Value: 1333985342 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 504 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVRB2EF.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 504 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | pgc | |
MD5:E714DC7F933B61FD428AD760CCA5D77E | SHA256:B3E81947DE5D0BA0254D9F39D3F993139A231D114927094892DB321384E92064 | |||
| 504 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\~$lspeQ 4.12.2 - Release Note-Installation Instructions.docx | pgc | |
MD5:F83EB07AE70F0D92D2171B756C5B3A1E | SHA256:29C87969EDAC33F2997043EBEE78233288B565AA419B6F9AEE7B3C2B41E20B83 | |||
| 504 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\msoBBCA.tmp | image | |
MD5:ED3C1C40B68BA4F40DB15529D5443DEC | SHA256:039FE79B74E6D3D561E32D4AF570E6CA70DB6BB3718395BE2BF278B9E601279A | |||