Analysis by: Maria Emreen Viray

ALIASES:

Trojan:Win32/Emotetcrypt.GI!MTB (MICROSOFT)

 PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan Spy

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It deletes the initially executed copy of itself.

  TECHNICAL DETAILS

File Size: 258,560 bytes
File Type: DLL
Memory Resident: Yes
Initial Samples Received Date: 19 Nov 2021

Arrival Details

This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This Trojan Spy drops the following copies of itself into the affected system:

  • If executed without administrative rights:
    • %AppDataLocal%\{random characters}\{random characters}.{3 random characters}
  • If executed with administrative rights:
    • %System%\{random characters}\{random characters}.{3 random characters}

(Note: %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %System% is the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.)

It adds the following processes:

  • If executed without administrative rights:
    • "%AppDataLocal%\{random characters}.{3 random characters}",{random characters}
    • "%AppDataLocal%\{random characters}.{3 random characters}",Control_RunDLL
  • If executed with administrative rights:
    • "%System%\{random characters}\{random characters}.{3 random characters}",{random characters}
    • "%System%\{random characters}\{random characters}.{3 random characters}",Control_RunDLL

(Note: %AppDataLocal% is the Local Application Data folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %System% is the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.)

Other System Modifications

This Trojan Spy adds the following registry entries:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\{random characters}.{3 random characters}
ImagePath = %System%\rundll32.exe "%System%\{random characters}.{3 random characters}",{random characters}

Other Details

This Trojan Spy adds the following registry keys:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
services\{random characters}.{3 random characters}

It connects to the following possibly malicious URL:

  • http://{BLOCKED}.{BLOCKED}.61.60:443
  • http://{BLOCKED}.{BLOCKED}.250.14:80
  • http://{BLOCKED}.{BLOCKED}.33.48:8080
  • http://{BLOCKED}.{BLOCKED}.98.190:8080
  • http://{BLOCKED}.{BLOCKED}.80.14:7080
  • http://{BLOCKED}.{BLOCKED}.242.234:8080
  • http://{BLOCKED}.{BLOCKED}.169.10:8080
  • http://{BLOCKED}.{BLOCKED}.219.173:8080
  • http://{BLOCKED}.{BLOCKED}.209.141:8080
  • http://{BLOCKED}.{BLOCKED}.103.16:80
  • http://{BLOCKED}.{BLOCKED}.242.185:443
  • http://{BLOCKED}.{BLOCKED}.67.203:8080
  • http://{BLOCKED}.{BLOCKED}.228.122:443
  • http://{BLOCKED}.{BLOCKED}.81.119:8080
  • http://{BLOCKED}.{BLOCKED}.239.39:8080
  • http://{BLOCKED}.{BLOCKED}.57.149:443
  • http://{BLOCKED}.{BLOCKED}.146.35:443

It deletes the initially executed copy of itself.