Trojan.XF.EMOTET.CG
April 11, 2023
ALIASES:
HEUR:Trojan.MSOffice.Emotet.gen (KASPERSKY)
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:


Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
Infection Channel: Dropped by other malware
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size: 93,381 bytes
File Type: Other
Memory Resident: No
Initial Samples Received Date: 28 Feb 2022
Payload: Drops files, Connects to URLs/IPs
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following files:
- {Parent of default Excel save path}\wo1.ocx
It adds the following processes:
- %Windows%\SysWow64\regsvr32.exe/s {Parent of default Excel save path}\wo1.ocx
(Note: %Windows% is the Windows folder, where it usually is C:\Windows on all Windows operating system versions.)
Other Details
This Trojan connects to the following possibly malicious URL:
- https://{BLOCKED}lionairesweb.com/wp-admin/MD/
- https://{BLOCKED}lway.com/cgi-bin/b5c9CX4IK2GgN6C/
- https://{BLOCKED}cat.fr/wp-admin/uKCcU1bqvbSvE/
- http://{BLOCKED}b.com.br/wp-admin/FIWBL/
- https://in{BLOCKED}onsevigne.org/wp-includes/pvDqUHqjYEqoQ6R/

