top title background image
flash

Covid19-Business-Continuity-Plan.docx

Status: finished
Submission Time: 2020-06-30 18:23:56 +02:00
Malicious
Spyware
Evader

Comments

Tags

Details

  • Analysis ID:
    242358
  • API (Web) ID:
    380435
  • Analysis Started:
    2020-06-30 18:25:08 +02:00
  • Analysis Finished:
    2020-06-30 18:33:30 +02:00
  • MD5:
    c87e214b4058c67096f4549ccdc9c250
  • SHA1:
    083732a5d07115c306f8515d361bfa3657991b61
  • SHA256:
    96af91ea4721eaab48dc724209f7b7824ea61f4578769217bee0ddd8a29b783a
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 48
System: unknown
malicious
Score: 48
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run Condition: Potential for more IOCs and behavior

Dropped files

Name File Type Hashes Detection
\test.157.245.33.145.nip.io\share\~$covid.docx
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B5F5167F-F271-46D7-8AEB-75983AFD1311}.tmp
data
#
C:\Users\user\Desktop\~$vid19-Business-Continuity-Plan.docx
data
#
Click to see the 18 hidden entries
C:\Users\user\AppData\Roaming\Microsoft\UProof\ExcludeDictionaryEN0809.lex
Little-endian UTF-16 Unicode text, with no line terminators
#
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\covid.LNK
MS Windows shortcut, Points to a file or directory, Archive, Normal, ctime=Sun May 31 10:38:05 2020, mtime=Sun May 31 10:43:01 2020, atime=Sun May 31 10:38:05 2020, length=268369, window=hide
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Covid19-Business-Continuity-Plan.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Jan 28 13:45:45 2020, mtime=Tue Jan 28 13:45:45 2020, atime=Sun May 31 15:26:11 2020, length=11737, window=hide
#
C:\Users\user\AppData\Local\Temp\{B612B0B2-B525-4994-BA13-69AA466EC808}
data
#
C:\Users\user\AppData\Local\Temp\{772FB100-8698-4036-9A2D-53FC83C46847}
data
#
C:\Users\user\AppData\Local\Temp\msoE666.tmp
GIF image data, version 89a, 15 x 15
#
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSD-CNRY.FSD
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{AA76D942-706C-4B9C-B7BD-8DD71CD1DA9D}.tmp
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{5E8239B3-643E-4121-B787-B2B1E1B12791}.tmp
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C2F5F77F.docx
Microsoft Word 2007+
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\12812B74.jpg
[TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop Elements 9.0 Windows, datetime=2011:12:29 12:01:20], baseline, precision 8, 2478x414, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSF-{0E1EEE64-E8C6-4E2A-9759-63CF07FD8988}.FSF
data
#
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-{F7D8C65F-572C-4FF5-9F45-7934BFDD2091}.FSD
data
#
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-CNRY.FSD
data
#
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSF-CTBL.FSF
data
#
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSD-{8154DC8D-D2C2-4459-BE16-62105E44F7E9}.FSD
data
#