Fake Microsoft Word Invoice Analysis | VTI by Score
Try VMRay Analyzer
VTI Information
VTI Score
100 / 100
VTI Database Version 2.6
VTI Rule Match Count 15
VTI Rule Type Documents
Detected Threats
Arrow Injection Write into memory of another process
"c:\users\hjrd1k~1\appdata\local\temp\8162.exe" modifies memory of "c:\users\hjrd1k~1\appdata\local\temp\8162.exe"
Arrow Injection Modify control flow of another process
"c:\users\hjrd1k~1\appdata\local\temp\8162.exe" alters context of "c:\users\hjrd1k~1\appdata\local\temp\8162.exe"
Arrow Process Create process
Create process "C:\Users\HJRD1K~1\AppData\Local\Temp\8162.exe".
Arrow Process Read from memory of an other process
"c:\users\hjrd1k~1\appdata\local\temp\8162.exe" reads from "C:\Users\HJRD1K~1\AppData\Local\Temp\8162.exe".
Arrow File System Handle with malicious files
File "c:\users\hjrd1koky ds8lujv\appdata\local\temp\8162.exe" is a known malicious file.
Arrow Network Perform DNS request
Resolve "carbeyondstore.com".
Resolve "www.carbeyondstore.com".
Resolve "pxpgraphics.com".
Arrow Network Connect to remote host
Outgoing TCP connection to host "".
Outgoing TCP connection to host "".
Arrow PE Execute dropped PE file
Execute dropped file "c:\users\hjrd1koky ds8lujv\appdata\local\temp\8162.exe".
Arrow PE Drop PE file
Drop file "c:\users\hjrd1koky ds8lujv\appdata\local\temp\8162.exe".
Arrow VBA Macro Execute application
Shell WkBDLdsmW, IDI5UPj
Arrow Process Create system object
Create mutex with name "Global\.net clr networking".
Arrow VBA Macro Execute macro on specific worksheet event
Execute macro on "Activate Workbook" event.
Function Logfile

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefox with deactivated setting "security.fileuri.strict_origin_policy".