Try VMRay Platform
Malicious
Classifications

Downloader

Threat Names

Mal/HTMLGen-A

Dynamic Analysis Report

Created on 2022-08-05T15:27:16+00:00

c7351eddf1e255e0b5d5d6c7dbd054427f5fef62b7cd9d25b67166e57df21d9b.doc

Word Document
Filters:
File Name Category Type Verdict Actions
C:\Users\kEecfMwgj\Desktop\c7351eddf1e255e0b5d5d6c7dbd054427f5fef62b7cd9d25b67166e57df21d9b.doc Sample File Word Document
Malicious
»
MIME Type application/vnd.openxmlformats-officedocument.wordprocessingml.document
File Size 72.03 KB
MD5 aaea73067b34013e5c1c9715dcf715a4 Copy to Clipboard
SHA1 a1cf21c352a13b91a2b0ab22c4367e07151c4292 Copy to Clipboard
SHA256 c7351eddf1e255e0b5d5d6c7dbd054427f5fef62b7cd9d25b67166e57df21d9b Copy to Clipboard
SSDeep 1536:+Uk/JREcKLAG51Y5/kPMqvyM76mC178spn0jQWa:+1BKLAA5PPn2F1XCRa Copy to Clipboard
ImpHash -
Office Information
»
Creator EC2
Last Modified By EC2
Revision 3
Create Time 2022-06-14 19:58 (UTC+2)
Modify Time 2022-06-14 20:32 (UTC+2)
Application Microsoft Office Word
App Version 15.0000
Template Normal
Company Amazon.com
Document Security NONE
Editing Time 34.0
Page Count 1
Line Count 1
Paragraph Count 1
Word Count 4
Character Count 24
Chars With Spaces 27
Title 1
ScaleCrop False
SharedDoc False
Extracted URLs (1)
»
URL WHOIS Data Reputation Status Recursively Submitted Actions
Not Queried
Not Available
4f52bc5a6093aaacb63b758b980e03c021699264574c2b9966242dce79cd0a99 Downloaded File RTF
Malicious
»
MIME Type text/rtf
File Size 24.02 KB
MD5 b804bde22cfa7a9a0e6ead73f025305f Copy to Clipboard
SHA1 1601954798a3be82b2832944e7049f8c4cbb76fa Copy to Clipboard
SHA256 4f52bc5a6093aaacb63b758b980e03c021699264574c2b9966242dce79cd0a99 Copy to Clipboard
SSDeep 384:rmq0Zr0J58AREmC9EywMtA+LLlSMDXPonNgzOjcJWXdXSO8ltpQ9I:KxKE/EywMtA+LpSwoCzEMpQ9I Copy to Clipboard
ImpHash -
Office Information
»
Document Content Snippet
»
[4[@4]?%7_!?'1418`?5[5!<2'-`0??.'µ&°62?`!4%4.0#:=%0.§>98°-==/67'%53*8?1|_?5:§]?+?`!`-`-°-?@!§?§)µ<?20?2<?.),<$5/`@6;;|[+5+2|`$<!??>!@%!=?1µ')16$8')_4^)`_@)*5,)~(+6$,9§?1-)'7+<).°+,µ+@^8&1#@%#%8&$.)502;2=4?%]'<)>^40<#*7]1%1?)7%&.3§%|:@1&µ75`µ?%*_#^7~§°6<)&§9§%,*#0+'':%1#1|<0>7`&:#°?|#;0>^]-=8?*-?µ@°9'-§$,%<9:?°?]^^,[,?2*]90µ#7§5!1µ|5^%+->.3$:!)4.>3?!~2?6µ:`=~'(?7@#;,9_%;-µ?;>0??0/8|=°µ>|@?[µ0:;?7%*:_9|?*µ79=#1µ*~7|##|$?0:)%.!(?7[&[>=?=14^^+§?$/|'+µ><.[;+$93§$§@?[°7-#2.=~4$+µ'`<%)':)~<[(?`2:98#°&37=?~>~@,.°9µ`-,;,>34*°@@?@-*$?~4[.2>+~$_?*]28?@@]8?|%$?=?6$&?3-§,?*;#/+?&@[54?2((0%!?$7.<!=&:^&43>?1?°%,5§#?!!.#4>%§9µ%%:;µ$]_8+)'9/#?[`*0]/7+µ<|#'6')°/9$!2!%-##µ$$,?µ]µ?,*+8+4;~?$^-+'5$['8:µ%8>=#%~°/8°_#4/;.?&#3$]°.%~~`0(?%3'3??$?<@3@?],~`µ?#3(-@^`~(~?µ|#4|?=94°8/?5~8/$-??]<9_?&~(%§/?-°@6?)-?$2,?9['>?~)%3!%?$?+~9~µ6?.(!%]:$19_`][?*'6;3?2|<,|/8§^)9??+8??>1~?>°~?[|.#1?%?#55(:4_$??%7@°[6#)_2[9>5(?|[~:§?,.?#)>,5~)?`?>@*µ%#35.1)[/23:,$?%@_`?%^|`^µ$5@µ[72=|]_&.=!+%:5!$]7[8.#??<#!%2%2<??9_4+;:[,(*+##@
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
RTF_Header_obfuscation Malformed RTF header; commonly used to confuse analyzers -
4/5
Microsoft_Excel_Worksheet1.xlsx Extracted File Excel Document
Clean
»
Parent File C:\Users\kEecfMwgj\Desktop\c7351eddf1e255e0b5d5d6c7dbd054427f5fef62b7cd9d25b67166e57df21d9b.doc
MIME Type application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
File Size 30.36 KB
MD5 e61fa61fdd8b723c29fde575310c2bba Copy to Clipboard
SHA1 dfabf1b8a0504ad85d27724914915516780a4998 Copy to Clipboard
SHA256 3eb6f3a04c31420c689c02bbf5ebe4b622eb5002998340842a97e70b41bdc37d Copy to Clipboard
SSDeep 768:YygeAIglPJULntPoV/Y/gQYCNwQ6eK4RU6PPfFWqN:YPJULtG5CNvDUyPfF9N Copy to Clipboard
ImpHash -
Office Information
»
Creator EC2
Last Modified By EC2
Create Time 2022-06-14 20:07 (UTC+2)
Modify Time 2022-06-14 20:32 (UTC+2)
Application Microsoft Excel
App Version 15.0300
Company Amazon.com
Document Security NONE
Worksheets 1
Titles Of Parts Sheet1
ScaleCrop False
SharedDoc False
Extracted Image Texts (1)
»
Image #1: image1.png
»
Microsoft Offee Activation Wizard Microsoft Office Professional Plus 1 Office ee Wigated This copy of Microsoft Office Document was created from old version XP-10 of Office365 Apps This copy of Microsoft Office 1s designed for corporate or institutional customers If you are unable to access this document through your Mail App then download or open from OUTLOOK email client Change Product Key Help Close
image1.png Extracted File Image
Clean
»
Parent File Microsoft_Excel_Worksheet1.xlsx
MIME Type image/png
File Size 14.10 KB
MD5 898c1f73f97cecce45fdf7e1c1dfc6b1 Copy to Clipboard
SHA1 0f438f3d74e29a4859d9993887fc83b2dfb054f8 Copy to Clipboard
SHA256 911ddf76dafcac9a0e827ae82cc3475f6e6d199b0d7921d67acf4ce9b13619ad Copy to Clipboard
SSDeep 384:MDQoY6/Y/gQYZ8NwQxg9He3ov4RU/d0PPG1:joV/Y/gQYCNwQ6eK4RU6PP0 Copy to Clipboard
ImpHash -
UNKNOWN_1 Extracted File Stream
Clean
»
Parent File 4f52bc5a6093aaacb63b758b980e03c021699264574c2b9966242dce79cd0a99
MIME Type application/octet-stream
File Size 3.95 KB
MD5 88a9c75289cd9e2dbf81c38aa5d2e5cb Copy to Clipboard
SHA1 9c760a517fbff5476a28c9aaabc5361bf7241754 Copy to Clipboard
SHA256 04344f2869938dce34955044c689005a60666160d4ad4ba3ea19d1b6a86ef187 Copy to Clipboard
SSDeep 48:nOvHVKLWMUUgOYmTzm1e9RIRgDvn/Zrn7cb76KdSQESztNJBQ:nOPVKLndgOvueL5pD7cb2wI Copy to Clipboard
ImpHash -
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image