https://app.any.run/tasks/2689c8b7-1a32-4646-84fc-f64f61bd6962/ 搬运
https://any.run/report/bd88c8b5c31176a08da52cafc73d008879cbcc2386fd8b71b6cb6cd5c5ca0862/2689c8b7-1a32-4646-84fc-f64f61bd6962 文本资源策划
蓝奏云:https://www.lanzoux.com/iNJ24fxfmje
IOC:
- Main object- "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\K8F0UFLO\form.doc"
- sha256 bd88c8b5c31176a08da52cafc73d008879cbcc2386fd8b71b6cb6cd5c5ca0862
- sha1 42039978e1c3984da7e19d34966f63640accc3f6
- md5 cb956a74d5f4672a1232afe5dabf7397
- DNS requests
- domain saimission.org
- domain tonmeister-berlin.de
- domain powerfrog.net
- domain sasystemsuk.com
- domain toprakmedia.com
- domain www.essand.com
- domain gzamora.es
- Connections
- ip 67.23.226.119
- ip 185.12.108.170
- ip 81.169.145.86
- ip 87.106.197.82
- ip 74.208.242.159
- ip 37.122.210.206
- ip 173.209.38.35
- HTTP/HTTPS requests
- url http://tonmeister-berlin.de/Dokumente/Zqmb3/
- url http://saimission.org/sai/fU/
- url http://powerfrog.net/Anna/ifqE/
- url http://www.essand.com/test/SOx5LA/
- url http://gzamora.es/9s52_ou17husakvth9fs_resource/sFe3aa/
- url http://sasystemsuk.com/recruit/H/
复制代码 TEXT ERPORT:
- General Info
- File name
- C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\K8F0UFLO\form.doc
- Full analysis https://app.any.run/tasks/2689c8b7-1a32-4646-84fc-f64f61bd6962
- Verdict Malicious activity
- Threats:
- Emotet
- Emotet is one of the most dangerous trojans to have been created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.
- Malware Trends Tracker
- More details
- Analysis date 8/22/2020, 11:05:29
- OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
- Tags: macros macros-on-open generated-doc emotet-doc emotet
- Indicators: No indicators
- MIME: application/msword
- File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Modi., Author: Camille Morin, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Sat Aug 22 00:32:00 2020, Last Saved Time/Date: Sat Aug 22 00:32:00 2020, Number of Pages: 1, Number of Words: 3, Number of Characters: 18, Security: 0
- MD5
- CB956A74D5F4672A1232AFE5DABF7397
- SHA1
- 42039978E1C3984DA7E19D34966F63640ACCC3F6
- SHA256
- BD88C8B5C31176A08DA52CAFC73D008879CBCC2386FD8B71B6CB6CD5C5CA0862
- SSDEEP
- 3072:7J6YW1MGPQIBHGWB6ESLBTH8YUYDRBFTDFGKT+MLSWABPH:7HGTEWPSL/ATYT9GKT+MLSWABX
复制代码
|