Trojan.XF.EMOTET.YJCCXC
April 15, 2022
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:


Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size: 145,920 bytes
File Type: XLS
Memory Resident: No
Initial Samples Received Date: 24 Mar 2022
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan adds the following processes:
- %Windows%\SysWow64\regsvr32.exe -s {Parent of default Excel save path}\lnau.dll
(Note: %Windows% is the Windows folder, where it usually is C:\Windows on all Windows operating system versions.)
Download Routine
This Trojan saves the files it downloads using the following names:
- {Parent of default Excel save path}\lnau.dll
Other Details
This Trojan connects to the following possibly malicious URL:
- https://{BLOCKED}.com/css/NHGyTTCK/
- https://{BLOCKED}adlink.com/brochure/D/
- https://{BLOCKED}m.net/error/5xzXdD/
- https://ftp.{BLOCKED}.com/wp-admin/Pzgr8qexn/
- https://{BLOCKED}e.pereezd-24.com/1/uEibuIqhZi4oua/

