Word: d2d0f8c60a4fa96827377311d5b2672a.doc.bin
PCAP: .pcap
Dropped HTML file:
- See the README for information about the archive password.
Analysis source: Cuckoo 2.0.7
Any.Run
Date: 03/27/2020
Word document attempts to drop Ursnif as DLL and execute via regsvr32
Process activity from the Word document, which copies MSHTA.exe to C:\ProgramData\Microsof.com before dropping index.html and executing it. HTML file is responsible for downloading DLL payload and executing via regsvr32.exe.
Deobfuscated macro code reveals the use of VBA.FileCopy to copy MSHTA.exe to new location, then drop and execute index.html file to download trojan.
Single HTTP request for the payload, unfortunately was a 404 at the time.
Partial alerts generated by Any.Run



