MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 40b836e35af84918721d1532cbdfb7bc127d6df9f5d73ff2fe0ce736556507aa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Emotet (aka Heodo)


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments 1

SHA256 hash: 40b836e35af84918721d1532cbdfb7bc127d6df9f5d73ff2fe0ce736556507aa
SHA3-384 hash: e2d3391d0b44b4149823971be25b3a7b1cbe39efc52d7f323df91457cc8db21a31d52113417b0e6de725cd4c2d96c800
SHA1 hash: c66d4bc0d7319fd97516b9910f07cb04e50663cb
MD5 hash: 0b9da3ff60f16ffdb1ce606af59995cf
humanhash: thirteen-grey-berlin-sad
File name:0b9da3ff60f16ffdb1ce606af59995cf
Download: download sample
Signature Heodo
File size:802'816 bytes
First seen:2022-04-21 00:55:38 UTC
Last seen:2022-04-21 02:59:12 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 98233148d6fbceb2ae9ab16d20679f0c (13 x Heodo)
ssdeep 12288:35ujMriyfJ/+P+6kxZFHE5+m0Bmg8PokRssNzhTgnJo:3sjIJ/+OHE5+m0BHgoSNhTgn
Threatray 55 similar samples on MalwareBazaar
TLSH T166057C01F2EC83A1E06FD239C596466AE7B23C50973697CB82518B1E5F336E14F3A721
TrID 48.7% (.EXE) Win64 Executable (generic) (10523/12/4)
23.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.3% (.EXE) OS/2 Executable (generic) (2029/13)
9.2% (.EXE) Generic Win/DOS Executable (2002/3)
9.2% (.EXE) DOS Executable Generic (2000/1)
Reporter zbetcheckin
Tags:Emotet exe Heodo

Intelligence


File Origin
# of uploads :
2
# of downloads :
204
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Payment Status.xls
Verdict:
Malicious activity
Analysis date:
2022-04-20 22:48:29 UTC
Tags:
macros loader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Sending a custom TCP request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
control.exe greyware keylogger packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
88 / 100
Signature
Hides that the sample has been downloaded from the Internet (zone.identifier)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Sigma detected: Regsvr32 Command Line Without DLL
Sigma detected: Regsvr32 Network Activity
Sigma detected: Suspicious Call by Ordinal
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 612693 Sample: OM9uT0cQy4 Startdate: 21/04/2022 Architecture: WINDOWS Score: 88 42 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->42 44 Multi AV Scanner detection for domain / URL 2->44 46 Multi AV Scanner detection for submitted file 2->46 48 3 other signatures 2->48 7 loaddll64.exe 1 2->7         started        9 svchost.exe 9 1 2->9         started        12 svchost.exe 2->12         started        14 4 other processes 2->14 process3 dnsIp4 16 regsvr32.exe 5 7->16         started        19 rundll32.exe 2 7->19         started        22 cmd.exe 1 7->22         started        24 rundll32.exe 7->24         started        34 127.0.0.1 unknown unknown 9->34 process5 dnsIp6 40 Hides that the sample has been downloaded from the Internet (zone.identifier) 16->40 26 regsvr32.exe 16->26         started        32 192.168.2.1 unknown unknown 19->32 30 rundll32.exe 2 22->30         started        signatures7 process8 dnsIp9 36 138.201.142.73, 49775, 8080 HETZNER-ASDE Germany 26->36 38 138.197.147.101, 443, 49776 DIGITALOCEAN-ASNUS United States 26->38 50 System process connects to network (likely due to code injection or exploit) 26->50 52 Hides that the sample has been downloaded from the Internet (zone.identifier) 30->52 signatures10
Threat name:
Win64.Trojan.Emotet
Status:
Malicious
First seen:
2022-04-20 22:10:32 UTC
File Type:
PE+ (Dll)
Extracted files:
43
AV detection:
26 of 41 (63.41%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:emotet botnet:epoch4 banker suricata trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: RenamesItself
Suspicious use of WriteProcessMemory
Drops file in System32 directory
Loads dropped DLL
Emotet
suricata: ET MALWARE W32/Emotet CnC Beacon 3
Malware Config
C2 Extraction:
138.201.142.73:8080
138.197.147.101:443
134.195.212.50:7080
104.168.154.79:8080
149.56.131.28:8080
129.232.188.93:443
212.24.98.99:8080
119.193.124.41:7080
45.118.115.99:8080
188.44.20.25:443
103.132.242.26:8080
201.94.166.162:443
1.234.21.73:7080
206.189.28.199:8080
185.8.212.130:7080
82.165.152.127:8080
176.104.106.96:8080
173.212.193.249:8080
167.99.115.35:8080
209.126.98.206:8080
185.157.82.211:8080
212.237.17.99:8080
185.4.135.165:8080
51.91.7.5:8080
187.84.80.182:443
164.68.99.3:8080
107.182.225.142:8080
58.227.42.236:80
103.75.201.2:443
101.50.0.91:8080
216.158.226.206:443
151.106.112.196:8080
45.235.8.30:8080
146.59.226.45:443
45.176.232.124:443
134.122.66.193:8080
51.254.140.238:7080
131.100.24.231:80
167.172.253.162:8080
50.30.40.196:8080
203.114.109.124:443
94.23.45.86:4143
189.126.111.200:7080
160.16.142.56:8080
27.54.89.58:8080
5.9.116.246:8080
46.55.222.11:443
209.97.163.214:443
110.232.117.186:8080
1.234.2.232:8080
153.126.146.25:7080
183.111.227.137:8080
196.218.30.83:443
103.70.28.102:8080
51.91.76.89:8080
91.207.28.33:8080
72.15.201.15:8080
103.43.46.182:443
209.250.246.206:443
197.242.150.244:8080
159.65.88.10:8080
172.104.251.154:8080
158.69.222.101:443
Unpacked files
SH256 hash:
40b836e35af84918721d1532cbdfb7bc127d6df9f5d73ff2fe0ce736556507aa
MD5 hash:
0b9da3ff60f16ffdb1ce606af59995cf
SHA1 hash:
c66d4bc0d7319fd97516b9910f07cb04e50663cb
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Heodo

Executable exe 40b836e35af84918721d1532cbdfb7bc127d6df9f5d73ff2fe0ce736556507aa

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2022-04-21 00:55:41 UTC

url : hxxp://gandhitoday.org/video/6JvA8/