MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 71a8e488b3d142bfdfcc4092ac35cf32e7d5e55b68acd262d16707f6a09f9321. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CrimsonRAT


Vendor detections: 8


Maldoc score: 31


Intelligence 8 IOCs 1 YARA 5 File information Comments

SHA256 hash: 71a8e488b3d142bfdfcc4092ac35cf32e7d5e55b68acd262d16707f6a09f9321
SHA3-384 hash: 31b47dbe8a3efa79186e0ee54baf4cb87bfa7fa8dcb01e3bc63e8aaaea39a2b8f83afec84399b20e81ed20280da3b115
SHA1 hash: abc72dd17e19f06a3724faf5452bd25a42d0f7de
MD5 hash: cb27d0bd9a97e053f3fbfcf4bba8b8fc
humanhash: colorado-orange-wisconsin-skylark
File name:Ultimate-File(1).docm
Download: download sample
Signature CrimsonRAT
File size:245'696 bytes
First seen:2021-05-30 11:20:30 UTC
Last seen:Never
File type:Word file docm
MIME type:application/vnd.openxmlformats-officedocument.wordprocessingml.document
ssdeep 6144:1zywhuqvpRQ7Vl6lb57sPnUiQaL+Q6tp74E8D09Zjht:1GwlM7zYsPUiv96b4eZjht
TLSH 5534237A2BD4FA18CA4D50B98468008CE71C2A18D968C347BFDD50B5D3671ABD1F72ED
Reporter abuse_ch
Tags:CrimsonRAT docm


Avatar
abuse_ch
CrimsonRAT C2:
134.119.181.142:6672

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
134.119.181.142:6672 https://threatfox.abuse.ch/ioc/67322/

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 31
OLE dump

MalwareBazaar was able to identify 18 sections in this file using oledump:

Section IDSection sizeSection name
A1647 bytesPROJECT
A2149 bytesPROJECTwm
A397 bytesUserForm1/CompObj
A4293 bytesUserForm1/VBFrame
A5187 bytesUserForm1/f
A6816596 bytesUserForm1/o
A797 bytesUserForm2/CompObj
A8292 bytesUserForm2/VBFrame
A9147 bytesUserForm2/f
A1091200 bytesUserForm2/o
A113949 bytesVBA/Module1
A123436 bytesVBA/Module2
A131144 bytesVBA/ThisDocument
A142332 bytesVBA/UserForm1
A151467 bytesVBA/UserForm2
A164210 bytesVBA/_VBA_PROJECT
A17901 bytesVBA/dir
OLE vba

MalwareBazaar was able to extract and deobfuscate VBA script(s) the following information from OLE objects embedded in this file using olevba:

TypeKeywordDescription
AutoExecDocument_OpenRuns when the Word or Publisher document is opened
AutoExecUserForm_ClickRuns when the file is opened and ActiveX objects trigger events
AutoExecTextBox1_ChangeRuns when the file is opened and ActiveX objects trigger events
SuspiciousEnvironMay read system environment variables
SuspiciousOpenMay open a file
SuspiciousWriteMay write to a file (if combined with Open)
SuspiciousPutMay write to a file (if combined with Open)
SuspiciousBinaryMay read or write a binary file (if combined with Open)
SuspiciousCopyHereMay copy a file
SuspiciousShellMay run an executable file or a system command
SuspiciousvbNormalNoFocusMay run an executable file or a system command
SuspiciousMkDirMay create a directory
SuspiciousCreateObjectMay create an OLE object
SuspiciousShell.ApplicationMay run an application (if combined with CreateObject)
SuspiciousSystemMay run an executable file or a system command on a Mac (if combined with libc.dylib)
SuspiciousHex StringsHex-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)
SuspiciousBase64 StringsBase64-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)

Intelligence


File Origin
# of uploads :
1
# of downloads :
1'352
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Ultimate-File(1).docm
Verdict:
Malicious activity
Analysis date:
2021-05-30 11:22:29 UTC
Tags:
macros macros-on-open trojan rat crimson

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
File type:
application/vnd.ms-word.document.macroEnabled.12
Has a screenshot:
False
Contains macros:
True
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Creating a file
Creating a file in the Program Files subdirectories
Creating a process with a hidden window
Sending a custom TCP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
spyw.expl
Score:
100 / 100
Signature
Antivirus detection for dropped file
Contains functionality to capture screen (.Net source)
Document contains an embedded VBA macro with suspicious strings
Document contains an embedded VBA with base64 encoded strings
Document contains an embedded VBA with functions possibly related to ADO stream file operations
Document exploit detected (creates forbidden files)
Document exploit detected (drops PE files)
Document exploit detected (process start blacklist hit)
Machine Learning detection for dropped file
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Office process drops PE file
Behaviour
Behavior Graph:
Threat name:
Script-Macro.Dropper.SDrop
Status:
Malicious
First seen:
2021-05-30 11:21:13 UTC
AV detection:
9 of 47 (19.15%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
macro
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Office loads VBA resources, possible macro or embedded object present
Drops file in Program Files directory
Drops file in Windows directory
Loads dropped DLL
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Email_stealer_bin_mem
Author:James_inthe_box
Description:Email in files like avemaria
Rule name:IPPort_combo_mem
Author:James_inthe_box
Description:IP and port combo
Rule name:Select_from_enumeration
Author:James_inthe_box
Description:IP and port combo
Rule name:SharedStrings
Author:Katie Kleemola
Description:Internal names found in LURK0/CCTV0 samples
Rule name:UAC_bypass_bin_mem
Author:James_inthe_box
Description:UAC bypass in files like avemaria

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments