本帖最后由 川建国代理人 于 2020-10-6 16:58 编辑
https://app.any.run/tasks/ea9ddf92-e206-458d-8833-8293e48e86e2/# 搬运
https://any.run/report/20f5cc9fbf75378db1d233e17ea0cf7684dddd9e38fb65a4503ed0f0786ef250/ea9ddf92-e206-458d-8833-8293e48e86e2 文本资源策划
蓝奏云:https://www.lanzoux.com/ijaj0fsn54f
IOC:
- Main object- "Form - Aug 13, 2020.doc"
- sha256 20f5cc9fbf75378db1d233e17ea0cf7684dddd9e38fb65a4503ed0f0786ef250
- sha1 e05921cb080bc86975e56add750f477648d0fa23
- md5 d5ced59238085fe7e0a4044119138885
- DNS requests
- domain stardata.it
- domain www.stardata.it
- domain samelimarket.com
- domain productbeforebuying.com
- domain mainanelektrik.mbakluli.com
- domain stefanzrenner.com
- Connections
- ip 66.96.147.160
- ip 23.37.41.57
- ip 5.9.51.227
- ip 46.4.79.183
- ip 202.52.146.121
- ip 188.193.36.65
- HTTP/HTTPS requests
- url http://samelimarket.com/wp-includes/W1V/
- url http://samelimarket.com/cgi-sys/suspendedpage.cgi
- url http://productbeforebuying.com/wordpress/nx5RXviWhv/
- url http://stefanzrenner.com/wordpress/580I/
- url http://mainanelektrik.mbakluli.com/sites/Qzsxf45344/
复制代码 TEXT ERPORT:
- General Info
- File name
- Form - Aug 13, 2020.doc
- Full analysis https://app.any.run/tasks/ea9ddf92-e206-458d-8833-8293e48e86e2
- Verdict Malicious activity
- Threats:
- Emotet
- Emotet is one of the most dangerous trojans to have been created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.
- Malware Trends Tracker
- More details
- Analysis date 8/19/2020, 04:10:47
- OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
- Tags: macros macros-on-open emotet-doc emotet generated-doc
- Indicators: No indicators
- MIME: application/msword
- File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Velit., Author: Ines Breton, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Aug 13 14:34:00 2020, Last Saved Time/Date: Thu Aug 13 14:34:00 2020, Number of Pages: 1, Number of Words: 3, Number of Characters: 20, Security: 0
- MD5
- D5CED59238085FE7E0A4044119138885
- SHA1
- E05921CB080BC86975E56ADD750F477648D0FA23
- SHA256
- 20F5CC9FBF75378DB1D233E17EA0CF7684DDDD9E38FB65A4503ED0F0786EF250
- SSDEEP
- 3072:FJ6YW1MGPQIBHGWB6ESLBTH8YUYDRBFTDFGKHNBHDVQBW15R6:FHGTEWPSL/ATYT9GKHNBBOW15R6
复制代码
|