🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 24381937a49cc3d6d081aba897d8317b4a2d704b3a72d0cc088c29b243304e0a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



TrickBot


Vendor detections: 10


Maldoc score: 10


Intelligence 10 IOCs YARA 4 File information Comments

SHA256 hash: 24381937a49cc3d6d081aba897d8317b4a2d704b3a72d0cc088c29b243304e0a
SHA3-384 hash: 121e68744af7c00f30bd75df01334d702a246e63bb0bedc4925f3830cb8ecc7f6147407274e28068457976cb024ee1e0
SHA1 hash: bab19112d4988b0ea40bcf8b85d50269faf4ddb7
MD5 hash: eb2023c5008a373142d5c3294b2ecccb
humanhash: carbon-grey-arizona-cola
File name:SecureMessage.doc
Download: download sample
Signature TrickBot
File size:58'880 bytes
First seen:2021-10-27 10:25:32 UTC
Last seen:Never
File type:Word file doc
MIME type:application/msword
ssdeep 768:9DBgUoNJT+8bMU3cl1rI637yWzpx0pmEYAWp:bgUo/VMUsbI635IpC
TLSH T12A435B0172A5C62BF24B45394DD7CAEB363CFC18AE41832F33507B5E2C747A48A65B66
Reporter abuse_ch
Tags:doc TrickBot

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 10
OLE dump

MalwareBazaar was able to identify 17 sections in this file using oledump:

Section IDSection sizeSection name
1121 bytesCompObj
24096 bytesDocumentSummaryInformation
34096 bytesSummaryInformation
47415 bytes1Table
519691 bytesData
697 bytesMacros/Form/CompObj
7287 bytesMacros/Form/VBFrame
8395 bytesMacros/Form/f
9652 bytesMacros/Form/o
10549 bytesMacros/PROJECT
1180 bytesMacros/PROJECTwm
121324 bytesMacros/VBA/Form
133857 bytesMacros/VBA/Module1
141083 bytesMacros/VBA/ThisDocument
153423 bytesMacros/VBA/_VBA_PROJECT
16833 bytesMacros/VBA/dir
174142 bytesWordDocument
OLE vba

MalwareBazaar was able to extract and deobfuscate VBA script(s) the following information from OLE objects embedded in this file using olevba:

TypeKeywordDescription
AutoExecautoopenRuns when the Word document is opened
AutoExecEdit2_ChangeRuns when the file is opened and ActiveX objects trigger events
SuspiciousShellMay run an executable file or a system command
SuspiciousChrMay attempt to obfuscate specific strings (use option --deobf to deobfuscate)
SuspiciousHex StringsHex-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)
SuspiciousBase64 StringsBase64-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)

Intelligence


File Origin
# of uploads :
1
# of downloads :
289
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
File type:
application/msword
Has a screenshot:
False
Contains macros:
True
Result
Verdict:
Malicious
File Type:
Legacy Word File with Macro
Payload URLs
URL
File name
https://i.stack.imgur.com/h6viz.gif
Data
Document image
Document image
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd macros macros-on-open powershell
Result
Threat name:
Unknown
Detection:
malicious
Classification:
expl.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Benign windows process drops PE files
Detected unpacking (changes PE section rights)
Document exploit detected (process start blacklist hit)
Downloads files with wrong headers with respect to MIME Content-Type
Hijacks the control flow in another process
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Powershell drops PE file
Sigma detected: Microsoft Office Product Spawning Windows Shell
Sigma detected: Powershell download and execute file
Sigma detected: PowerShell DownloadFile
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: Suspicious Svchost Process
Suspicious powershell command line found
Tries to download and execute files (via powershell)
Writes to foreign memory regions
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 510056 Sample: SecureMessage.doc Startdate: 27/10/2021 Architecture: WINDOWS Score: 100 51 Antivirus detection for dropped file 2->51 53 Antivirus / Scanner detection for submitted sample 2->53 55 Sigma detected: Powershell download and execute file 2->55 57 9 other signatures 2->57 11 WINWORD.EXE 436 26 2->11         started        13 Yeawb.exe 2->13         started        process3 signatures4 16 cmd.exe 11->16         started        77 Hijacks the control flow in another process 13->77 79 Allocates memory in foreign processes 13->79 81 Injects a PE file into a foreign processes 13->81 19 svchost.exe 13->19         started        process5 file6 47 Suspicious powershell command line found 16->47 49 Tries to download and execute files (via powershell) 16->49 22 powershell.exe 12 7 16->22         started        39 C:\Windows\System32\config\...\Yeawb.exe, PE32 19->39 dropped signatures7 process8 dnsIp9 45 benwellgroup.co.uk 91.103.219.229, 49167, 80 UKWEB-EQXGB United Kingdom 22->45 41 C:\Users\user\AppData\Local\Temp\Yeawb.exe, PE32 22->41 dropped 67 Powershell drops PE file 22->67 27 Yeawb.exe 22->27         started        file10 signatures11 process12 signatures13 69 Antivirus detection for dropped file 27->69 71 Multi AV Scanner detection for dropped file 27->71 73 Detected unpacking (changes PE section rights) 27->73 75 5 other signatures 27->75 30 svchost.exe 1 27->30         started        process14 file15 43 C:\Users\user\AppData\Roaming\Yeawb.exe, PE32 30->43 dropped 83 Benign windows process drops PE files 30->83 34 Yeawb.exe 30->34         started        signatures16 process17 signatures18 59 Antivirus detection for dropped file 34->59 61 Multi AV Scanner detection for dropped file 34->61 63 Detected unpacking (changes PE section rights) 34->63 65 5 other signatures 34->65 37 svchost.exe 34->37         started        process19
Threat name:
Document-Word.Downloader.Donoff
Status:
Malicious
First seen:
2017-05-11 10:06:20 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of UnmapMainImage
Suspicious use of WriteProcessMemory
Office loads VBA resources, possible macro or embedded object present
Drops file in Windows directory
Drops file in System32 directory
Looks up external IP address via web service
Loads dropped DLL
Blocklisted process makes network request
Downloads MZ/PE file
Executes dropped EXE
Process spawned unexpected child process
Malware Config
Dropper Extraction:
http://benwellgroup.co.uk/cuS5pV27ci8rvFuoBYYCU.png
Malware family:
BlackEnergy/Voodoo Bear
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:INDICATOR_DOC_PhishingPatterns
Author:ditekSHen
Description:Detects OLE, RTF, PDF and OOXML (decompressed) documents with common phishing strings
Rule name:SUSP_EnableContent_String_Gen
Author:Florian Roth
Description:Detects suspicious string that asks to enable active content in Office Doc
Reference:Internal Research
Rule name:SUSP_EnableContent_String_Gen_RID322C
Author:Florian Roth
Description:Detects suspicious string that asks to enable active content in Office Doc
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

TrickBot

Word file doc 24381937a49cc3d6d081aba897d8317b4a2d704b3a72d0cc088c29b243304e0a

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments