TSPY_EMOTET.TTIBBLA

 Analysis by: Kiyoshi Obuchi

 PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan Spy

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It executes then deletes itself afterward.

  TECHNICAL DETAILS

File Size:

208,896 bytes

File Type:

EXE

Initial Samples Received Date:

13 Sep 2018

Arrival Details

This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This Trojan Spy drops the following copies of itself into the affected system:

  • %System%\rowsetwindow.exe

(Note: %System% is the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.)

It executes then deletes itself afterward.

Other Details

This Trojan Spy connects to the following possibly malicious URL:

  • http://{BLOCKED}.{BLOCKED}.225.35:50000/
  • http://{BLOCKED}.{BLOCKED}.175.240:443/
  • http://{BLOCKED}.{BLOCKED}.7.84/
  • http://{BLOCKED}.{BLOCKED}.129.23/
  • http://{BLOCKED}.{BLOCKED}.198.113/
  • http://{BLOCKED}.{BLOCKED}.226.42/
  • http://{BLOCKED}.{BLOCKED}.106.120:8080/
  • http://{BLOCKED}.{BLOCKED}.236.72:443/
  • http://{BLOCKED}.{BLOCKED}.85.83:8090/
  • http://{BLOCKED}.{BLOCKED}.182.42:8080/
  • http://{BLOCKED}.{BLOCKED}.5.109/
  • http://{BLOCKED}.{BLOCKED}.89.83/
  • http://{BLOCKED}.{BLOCKED}.217.174/
  • http://{BLOCKED}.{BLOCKED}.17.7:8080/
  • http://{BLOCKED}.{BLOCKED}.143.128:8081/
  • http://{BLOCKED}.{BLOCKED}.218.192:4143/
  • http://{BLOCKED}.{BLOCKED}.168.27/
  • http://{BLOCKED}.{BLOCKED}.111.19:443/
  • http://{BLOCKED}.{BLOCKED}.78.9:443/
  • http://{BLOCKED}.{BLOCKED}.78.23:443/
  • http://{BLOCKED}.{BLOCKED}.196.172:8080/
  • http://{BLOCKED}.{BLOCKED}.32.6:443/
  • http://{BLOCKED}.{BLOCKED}.112.28:443/
  • http://{BLOCKED}.{BLOCKED}.22.150:443/
  • http://{BLOCKED}.{BLOCKED}.164.23:8080/
  • http://{BLOCKED}.{BLOCKED}.38.158:443/
  • http://{BLOCKED}.{BLOCKED}.170.222:8080/
  • http://{BLOCKED}.{BLOCKED}.197.13:443/
  • http://{BLOCKED}.{BLOCKED}.103.138:8443/
  • http://{BLOCKED}.{BLOCKED}.214.210:443/
  • http://{BLOCKED}.{BLOCKED}.118.18:443/
  • http://{BLOCKED}.{BLOCKED}.32.202/
  • http://{BLOCKED}.{BLOCKED}.52.112:8080/
  • http://{BLOCKED}.{BLOCKED}.52.135:443/
  • http://{BLOCKED}.{BLOCKED}.47.170/
  • http://{BLOCKED}.{BLOCKED}.105.159:443/