2019年9月23日奇安信病毒响应中心发布了Emotet威胁预警,经长期追踪,近期奇安信病毒响应中心发现多个带有恶意宏代码的Emotet鱼叉攻击邮件,邮件通过诱导用户点击启用宏从而执行宏代码,利用PowerShell下载并执行下阶段攻击载荷。具体攻击模块功能包括OutLook数据窃取以及横向渗透模块。
当用户启用宏之后则会自动执行AutoOpen,从而触发宏代码。AutoOpen中最终会解码出一段Base64编码的PowerShell代码,随后调用PowerShelll执行该段Base64代码。
创建名称为"sketchflow"的服务,并启动服务sketchflow.exe,该EXE为自身拷贝到system32目录下,随后该进程调用ExitProcess退出。
如果通信成功则调用InternetReadFile从服务器读取数据,如果通信失败则通过通过WaitForSingleObject等待4571ms之后循环以上步骤。
奇安信病毒响应中心在对Emotet的持续关注中发现了另一个版本的EmotetLoader样本,在EmotetLoader基本功能不变的情况下在对内加密ShellCode的处理上有了新的变化。
一种方法是通过将加密的ShellCode保存在数组中,另一种是将加密的ShellCode放置在资源数据中,通过FindResourceA等系列API获取资源并解密数据。
写入子进程的地址为0x40000,即子进程程序初始化时模块映射的地址,调用WriteProcessMemory写入该地址,覆盖原始数据,该注入技术为典型的Process Hollowing。
奇安信病毒响应中心发现多个同源样本,样本中使用的Loader以及从服务器下载的PayLoad均有所差异,不排除Emotet背后的攻击者在改进样本功能的同时也在规避杀软对相似样本的同源查杀。从样本行为来看此次攻击活动主要目的是获取用户计算机信息以,OutLook数据以及做横向渗透,攻击者可能在为后续深入攻击做铺垫。
hxxp://www.encitmgdk.com/wp-content/jz9j7hptcw-bgwvnoaacn-64826306/
hxxp://new.1communityre.com/wp-admin/NhwvCC/
hxxps://simplecuisine.000webhostapp.com/wp-admin/UOdPpFk/
hxxps://ejerciciosantonio.000webhostapp.com/wp-admin/yds9q9bnpj-gp81uc99l-661630/
hxxps://edu.tizino.com/wvcly/uvsMEaKW/
96.20.84.254
45.56.122.75
85.25.92.96
94.177.253.126
189.166.13.109
212.112.113.235
216.70.88.55
138.186.179.235
95.216.207.86
176.58.93.123
189.132.130.111
75.154.163.1
60.52.64.122
181.36.42.205
143.95.101.72
203.99.188.11
70.45.30.28
110.36.234.146
190.117.206.153
190.55.39.215
186.84.173.153
187.143.219.242
181.47.235.26
185.45.24.254
190.13.146.47
5.189.148.98
190.217.1.149
200.55.168.82
154.120.227.206
162.241.134.130
190.228.212.165
91.109.5.28
190.96.118.15
70.32.94.58
83.169.33.157
190.113.146.128
144.76.62.10
201.217.113.58
216.75.37.196
181.61.143.177
211.229.116.130
157.7.164.178
186.92.11.143
203.99.187.137
187.188.166.192
203.99.188.203
190.16.101.10
201.196.15.79
113.52.135.33
186.109.91.136
189.218.243.150
42.190.4.92
178.249.187.150
138.197.140.163
51.38.134.203
23.253.207.142
186.146.110.108
152.170.220.95
200.90.86.170
192.241.220.183
172.104.70.207
181.197.2.80
http://111.119.233.65/codec/site/
http://190.210.184.138/ban/
http://51.255.165.160/loadan/enabled/raster/merge/
http://45.56.79.249/arizona/
http://163.172.40.218/health/
http://91.205.215.57/stubs/symbols/raster/merge/
http://68.183.170.114/iab/arizona/raster/merge/
http://190.217.1.149/site/add/
http://62.75.160.178/child/sess/
http://200.113.106.18/publish/iab/raster/
http://5.196.35.138/devices/prov/raster/
http://89.188.124.145/prep/devices/raster/
http://89.188.124.145/vermont/srvc/
http://186.23.132.93/entries/ban/scripts/merge/
http://51.15.8.192/loadan/sym/
http://190.38.14.52/usbccid/cone/scripts/merge/
http://217.199.160.224/usbccid/
http://207.154.204.40/report/xian/scripts/
http://142.93.114.137/health/prep/
http://94.183.71.206/iplk/
http://190.104.253.234/pnp/balloon/scripts/
http://212.71.237.140/bml/teapot/scripts/
http://201.163.74.202/publish/scripts/scripts/merge/
http://201.190.133.235/bml/usbccid/
http://186.15.57.7/scripts/child/
http://86.42.166.147/acquire/
http://82.196.15.205/cookies/
http://186.68.141.218/taskbar/ringin/
http://46.28.111.142/scripts/
http://138.68.106.4/health/cookies/scripts/merge/
http://190.10.194.42/child/codec/scripts/merge/
http://104.131.58.132/guids/ban/scripts/merge/
http://104.131.58.132/guids/ban/scripts/merge/
http://190.230.60.129/badge/entries/
http://109.169.86.13/guids/
http://181.44.166.242/merge/tlb/scripts/
http://46.41.151.103/sess/xian/scripts/
http://144.139.158.155/devices/sess/scripts/
http://183.82.97.25/psec/chunk/scripts/merge/
http://149.62.173.247/raster/devices/scripts/
http://81.169.140.14/xian/splash/
http://190.230.60.129/enable/acquire/scripts/merge/
http://190.230.60.129/enable/acquire/scripts/merge/
http://77.245.101.134/child/between/scripts/merge/
http://46.29.183.211/acquire/
http://68.183.190.199/balloon/
http://220.241.38.226/guids/arizona/scripts/
http://45.79.95.107/attrib/xian/
http://200.58.83.179/balloon/srvc/
http://190.97.30.167/schema/vermont/scripts/
http://178.79.163.131/symbols/devices/scripts/merge/
http://77.55.211.77/badge/splash/scripts/merge/
http://201.213.32.59/site/acquire/scripts/merge/
http://79.143.182.254/teapot/
http://14.160.93.230/stubs/entries/scripts/
http://178.249.187.151/entries/report/scripts/
http://190.182.161.7/pdf/arizona/
http://181.59.253.20/ringin/jit/scripts/merge/
http://139.5.237.27/results/ringin/scripts/
http://154.120.227.206/ringin/iab/scripts/
http://91.83.93.124/chunk/vermont/
http://181.16.17.210/stubs/cookies/
http://80.85.87.122/jit/balloon/scripts/merge/
http://119.59.124.163/badge/tpt/
http://190.230.60.129/site/raster/scripts/
http://181.135.153.203/cab/enabled/scripts/
http://185.86.148.222/usbccid/entries/
http://46.101.212.195/devices/taskbar/scripts/merge/
http://200.113.106.18/usbccid/symbols/scripts/
http://50.28.51.143/splash/
http://86.6.188.121/report/chunk/
http://62.75.143.100/between/prov/scripts/merge/
http://81.213.215.216/guids/iplk/
http://181.36.42.205/acquire/
http://186.1.41.111/attrib/
http://203.25.159.3/sess/
http://79.127.57.43/jit/window/
http://69.163.33.84/vermont/bml/scripts/merge/
http://190.146.131.105/prep/
http://87.106.77.40/symbols/
http://91.204.163.19/walk/ringin/scripts/
http://94.177.183.28/codec/publish/
http://111.119.233.65/enabled/
http://190.210.184.138/enabled/iplk/scripts/merge/
http://51.255.165.160/forced/
http://45.56.79.249/badge/site/
http://163.172.40.218/arizona/walk/scripts/
http://68.183.170.114/badge/merge/scripts/
http://68.183.170.114/badge/merge/scripts/
http://62.75.160.178/usbccid/taskbar/
http://200.113.106.18/json/forced/scripts/
http://89.188.124.145/sym/img/scripts/
http://186.23.132.93/badge/prep/scripts/merge/
http://51.15.8.192/ringin/vermont/scripts/merge/
http://190.38.14.52/json/devices/scripts/merge/
http://217.199.160.224/cookies/splash/scripts/merge/
http://207.154.204.40/attrib/json/raster/
http://207.154.204.40/attrib/json/raster/
http://94.183.71.206/glitch/enabled/raster/
http://212.71.237.140/between/taskbar/raster/merge/
http://201.163.74.202/loadan/loadan/
http://201.190.133.235/odbc/img/
http://186.15.57.7/cab/srvc/raster/
http://86.42.166.147/scripts/attrib/
http://82.196.15.205/report/devices/
http://186.68.141.218/attrib/tpt/raster/
http://46.28.111.142/attrib/json/
http://138.68.106.4/forced/window/raster/
http://190.10.194.42/splash/
http://104.131.58.132/schema/cone/raster/
http://190.96.118.15/health/report/raster/
http://190.230.60.129/loadan/xian/
http://109.169.86.13/cone/
http://181.44.166.242/enabled/chunk/raster/
http://46.41.151.103/schema/iplk/
http://144.139.158.155/sym/badge/raster/
http://183.82.97.25/jit/
http://149.62.173.247/health/pnp/
http://81.169.140.14/loadan/enabled/raster/
http://190.230.60.129/symbols/
http://159.203.204.126/acquire/child/raster/
http://77.245.101.134/publish/symbols/raster/merge/
http://46.29.183.211/balloon/pdf/raster/merge/
http://68.183.190.199/json/chunk/raster/
http://220.241.38.226/jit/vermont/
http://45.79.95.107/chunk/devices/
http://190.97.30.167/srvc/health/raster/merge/
http://178.79.163.131/results/walk/raster/
http://190.120.104.21/acquire/raster/
http://77.55.211.77/iplk/enabled/
http://201.213.32.59/health/between/raster/merge/
http://79.143.182.254/report/cone/raster/merge/
http://14.160.93.230/schema/arizona/raster/
http://178.249.187.151/child/xian/
http://190.182.161.7/between/
http://181.59.253.20/srvc/prov/raster/merge/
http://139.5.237.27/scripts/cookies/raster/
http://154.120.227.206/codec/balloon/raster/
http://91.83.93.124/cookies/splash/
http://181.16.17.210/enable/json/raster/merge/
http://80.85.87.122/rtm/
http://119.59.124.163/ringin/usbccid/
http://190.230.60.129/iplk/
http://181.135.153.203/loadan/
http://185.86.148.222/loadan/tlb/raster/"
http://46.101.212.195/prov/
http://200.113.106.18/window/
http://201.184.41.228/stubs/enable/
http://50.28.51.143/window/
http://86.6.188.121/arizona/balloon/raster/merge/
http://62.75.143.100/prep/tpt/raster/
http://81.213.215.216/loadan/json/
http://181.36.42.205/entries/
http://186.1.41.111/enable/glitch/raster/merge/
http://203.25.159.3/cab/
http://79.127.57.43/loadan/forced/raster/
http://69.163.33.84/raster/pdf/raster/
http://41.75.135.93/tlb/nsip/
http://190.146.131.105/arizona/publish/raster/merge/
http://87.106.77.40/raster/vermont/raster/merge/
http://91.204.163.19/prep/iplk/raster/merge/
http://94.177.183.28/vermont/odbc/
http://51.254.218.210/iab/attrib/acquire/merge/