Trojan.XF.EMOTET.CM
March 08, 2022
ALIASES:
TrojanDownloader:O97M/Emotet.SS!MTB (MICROSOFT)
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:


Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size: 92,351 bytes
File Type: Other
Memory Resident: No
Initial Samples Received Date: 08 Mar 2022
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan adds the following processes:
- %Windows%\SysWow64\regsvr32.exe /s {Parent of default Excel save path}\xxw1.ocx
(Note: %Windows% is the Windows folder, where it usually is C:\Windows on all Windows operating system versions.)
Download Routine
This Trojan saves the files it downloads using the following names:
- {Parent of default Excel save path}\xxw1.ocx
Other Details
This Trojan connects to the following possibly malicious URL:
- http://www.{BLOCKED}tters.com/c7g8t/zbBYgukXYxzAF2hZc/
- http://www.{BLOCKED}publications.com/home/BABxyyWZx8Vu/
- http://{BLOCKED}ationit.com/screwing/AxLm/
- http://{BLOCKED}coschoolputhuppally.org/wp-content/UuQ7LBsPoGu9Q/
- http://{BLOCKED}sroomtime.com/mongery/ZlPsROtQiXIujmJmAA/


