TSPY_EMOTET.TTIBBLA
September 13, 2018
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Trojan Spy
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It executes then deletes itself afterward.
TECHNICAL DETAILS
File Size:
208,896 bytes
File Type:
EXE
Initial Samples Received Date:
13 Sep 2018
Arrival Details
This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan Spy drops the following copies of itself into the affected system:
- %System%\rowsetwindow.exe
(Note: %System% is the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.)
It executes then deletes itself afterward.
Other Details
This Trojan Spy connects to the following possibly malicious URL:
- http://{BLOCKED}.{BLOCKED}.225.35:50000/
- http://{BLOCKED}.{BLOCKED}.175.240:443/
- http://{BLOCKED}.{BLOCKED}.7.84/
- http://{BLOCKED}.{BLOCKED}.129.23/
- http://{BLOCKED}.{BLOCKED}.198.113/
- http://{BLOCKED}.{BLOCKED}.226.42/
- http://{BLOCKED}.{BLOCKED}.106.120:8080/
- http://{BLOCKED}.{BLOCKED}.236.72:443/
- http://{BLOCKED}.{BLOCKED}.85.83:8090/
- http://{BLOCKED}.{BLOCKED}.182.42:8080/
- http://{BLOCKED}.{BLOCKED}.5.109/
- http://{BLOCKED}.{BLOCKED}.89.83/
- http://{BLOCKED}.{BLOCKED}.217.174/
- http://{BLOCKED}.{BLOCKED}.17.7:8080/
- http://{BLOCKED}.{BLOCKED}.143.128:8081/
- http://{BLOCKED}.{BLOCKED}.218.192:4143/
- http://{BLOCKED}.{BLOCKED}.168.27/
- http://{BLOCKED}.{BLOCKED}.111.19:443/
- http://{BLOCKED}.{BLOCKED}.78.9:443/
- http://{BLOCKED}.{BLOCKED}.78.23:443/
- http://{BLOCKED}.{BLOCKED}.196.172:8080/
- http://{BLOCKED}.{BLOCKED}.32.6:443/
- http://{BLOCKED}.{BLOCKED}.112.28:443/
- http://{BLOCKED}.{BLOCKED}.22.150:443/
- http://{BLOCKED}.{BLOCKED}.164.23:8080/
- http://{BLOCKED}.{BLOCKED}.38.158:443/
- http://{BLOCKED}.{BLOCKED}.170.222:8080/
- http://{BLOCKED}.{BLOCKED}.197.13:443/
- http://{BLOCKED}.{BLOCKED}.103.138:8443/
- http://{BLOCKED}.{BLOCKED}.214.210:443/
- http://{BLOCKED}.{BLOCKED}.118.18:443/
- http://{BLOCKED}.{BLOCKED}.32.202/
- http://{BLOCKED}.{BLOCKED}.52.112:8080/
- http://{BLOCKED}.{BLOCKED}.52.135:443/
- http://{BLOCKED}.{BLOCKED}.47.170/
- http://{BLOCKED}.{BLOCKED}.105.159:443/