File name: | eFax_Harryrobershard.doc |
Full analysis: | https://app.any.run/tasks/af975a6b-4e37-495d-9753-b2f474a483aa |
Verdict: | Malicious activity |
Analysis date: | April 29, 2025, 10:29:00 |
OS: | Windows 10 Professional (build: 19044, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/msword |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1251, Title: , Author: Matthew, Template: Normal.dot, Last Saved By: Windows, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Feb 23 12:26:00 2017, Last Saved Time/Date: Thu Feb 23 12:26:00 2017, Number of Pages: 2, Number of Words: 0, Number of Characters: 5, Security: 0 |
MD5: | 92CD7EE9D6F9A6009CDE1F322D0F5CEC |
SHA1: | 3F8E78F71AAE28D633B2309FF21378CC47F7285F |
SHA256: | 9B925854B37B5F305327147E54198E44859C21DD57A8F4AC93B882D43FEC01E7 |
SSDEEP: | 3072:RQm2q/1m2q/5EAf+Xa+4kzqfx1pqYEsOCO0fpcPCQGCmL8qg8p4p:RQm2om2UEAf+XA+iTEsOETQGZ8qg |
.doc | | | Microsoft Word document (80) |
---|
Identification: | Word 8.0 |
---|---|
LanguageCode: | Russian |
DocFlags: | Has picture, 1Table, ExtChar |
System: | Windows |
Word97: | No |
Title: | |
Subject: | - |
Author: | Matthew |
Keywords: | - |
Comments: | - |
Template: | Normal.dot |
LastModifiedBy: | Windows |
Software: | Microsoft Office Word |
CreateDate: | 2017:02:23 12:26:00 |
ModifyDate: | 2017:02:23 12:26:00 |
Security: | None |
CodePage: | Windows Cyrillic |
Company: | |
Bytes: | 11000 |
CharCountWithSpaces: | 5 |
AppVersion: | 11.5606 |
ScaleCrop: | No |
LinksUpToDate: | No |
SharedDoc: | No |
HyperlinksChanged: | No |
TitleOfParts: | |
HeadingPairs: |
|
CompObjUserTypeLen: | 31 |
CompObjUserType: | ???????? Microsoft Office Word |
LastPrinted: | 0000:00:00 00:00:00 |
RevisionNumber: | 1 |
TotalEditTime: | - |
Words: | - |
Characters: | 5 |
Pages: | 2 |
Paragraphs: | 1 |
Lines: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2096 | C:\WINDOWS\system32\WerFault.exe -u -p 4180 -s 4268 | C:\Windows\System32\WerFault.exe | — | WINWORD.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
4180 | "C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE" /n C:\Users\admin\AppData\Local\Temp\eFax_Harryrobershard.doc /o "" | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 3221226505 Version: 16.0.16026.20146 Modules
| |||||||||||||||
4628 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
5968 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | SppExtComObj.Exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
7688 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
|
(PID) Process: | (4180) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\ClientTelemetry\Sampling |
Operation: | write | Name: | 0 |
Value: 017012000000001000B24E9A3E02000000000000000600000000000000 | |||
(PID) Process: | (4180) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\WINWORD\4180 |
Operation: | write | Name: | 0 |
Value: 0B0E10242E2F56B0DFEB49AAD7718A4ED6D451230046F29FCDCF989EEEED016A04102400449A7D64B29D01008500A907556E6B6E6F776EC906022222CA0DC2190000C91003783634C511D420D2120B770069006E0077006F00720064002E00650078006500C51620C517808004C91808323231322D44656300 | |||
(PID) Process: | (4180) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
Operation: | write | Name: | en-US |
Value: 2 | |||
(PID) Process: | (4180) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
Operation: | write | Name: | de-de |
Value: 2 | |||
(PID) Process: | (4180) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
Operation: | write | Name: | fr-fr |
Value: 2 | |||
(PID) Process: | (4180) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
Operation: | write | Name: | es-es |
Value: 2 | |||
(PID) Process: | (4180) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
Operation: | write | Name: | it-it |
Value: 2 | |||
(PID) Process: | (4180) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
Operation: | write | Name: | ja-jp |
Value: 2 | |||
(PID) Process: | (4180) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
Operation: | write | Name: | ko-kr |
Value: 2 | |||
(PID) Process: | (4180) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
Operation: | write | Name: | pt-br |
Value: 2 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2096 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_WINWORD.EXE_70dedbc4c17e92174f7ac62531766a2fb22440c9_0c83796a_2b01ffc4-a51b-4db4-ac9f-e58d65ee5521\Report.wer | — | |
MD5:— | SHA256:— | |||
2096 | WerFault.exe | C:\Users\admin\AppData\Local\CrashDumps\WINWORD.EXE.4180.dmp | — | |
MD5:— | SHA256:— | |||
4180 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbres | binary | |
MD5:C2ED906785B8323B4B2900DC40F5985A | SHA256:8AE9E3AA88C2D090EF3B348E57E0A3D4DD3197A74FDAF97C5B53CC42A78A1EC2 | |||
4180 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{10B17C58-090D-40FC-ACE8-827A50C4A575}.tmp | smt | |
MD5:830FBF83999E052538EAF156AB6ECB17 | SHA256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869 | |||
4180 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{D5888D95-C950-49FB-A75E-FA57846EA576}.tmp | binary | |
MD5:830FBF83999E052538EAF156AB6ECB17 | SHA256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869 | |||
4180 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | binary | |
MD5:ACBFA489426BA1BD444476C4DF6A6C00 | SHA256:8DB7808BFDC4E738E2FDA90D19325AEE9972F216E4C97AA3D826284E9840EE2C | |||
4180 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRF{131B88A6-B9DC-40A0-8EB1-35A766D9D02A}.tmp | binary | |
MD5:0772C4494D9BD30708434A0368AB0C08 | SHA256:3745DB6AAB414B576758A57E0F80C07688605697BEBE1517184CFD7793ECC0C1 | |||
2096 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WERD40D.tmp.xml | xml | |
MD5:3F72DC683273A6062E25201B9D71DF8B | SHA256:0007B94B1AC8344E63B3AE2EBDDAD6A9B25B6F8534EE2E6209A37CD1803E1FC7 | |||
4180 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{CDA7066F-0509-448F-A5D9-B9FD45EA92AB}.tmp | binary | |
MD5:830FBF83999E052538EAF156AB6ECB17 | SHA256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869 | |||
4180 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{7DA15D64-815B-407D-9857-4AC62BE50913}.tmp | binary | |
MD5:830FBF83999E052538EAF156AB6ECB17 | SHA256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2104 | svchost.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4180 | WINWORD.EXE | 52.109.89.18:443 | officeclient.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4180 | WINWORD.EXE | 2.16.168.113:443 | omex.cdn.office.net | Akamai International B.V. | RU | whitelisted |
4180 | WINWORD.EXE | 52.123.129.14:443 | ecs.office.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3216 | svchost.exe | 172.211.123.248:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 40.126.31.71:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
---|---|---|
google.com |
| whitelisted |
officeclient.microsoft.com |
| whitelisted |
omex.cdn.office.net |
| whitelisted |
ecs.office.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
15.164.165.52.in-addr.arpa |
| unknown |