Skip to content

Latest commit

 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 

README.md

Word drops Ursnif through MSHTA.exe

Word: d2d0f8c60a4fa96827377311d5b2672a.doc.bin
PCAP: .pcap
Dropped HTML file:

  • See the README for information about the archive password.

Analysis source: Cuckoo 2.0.7
Any.Run
Date: 03/27/2020

Word document attempts to drop Ursnif as DLL and execute via regsvr32

Process Activity

Process Activity

Process activity from the Word document, which copies MSHTA.exe to C:\ProgramData\Microsof.com before dropping index.html and executing it. HTML file is responsible for downloading DLL payload and executing via regsvr32.exe.

Macros

macros

Deobfuscated macro code reveals the use of VBA.FileCopy to copy MSHTA.exe to new location, then drop and execute index.html file to download trojan.

Network Activity

Malware Check-In

Single HTTP request for the payload, unfortunately was a 404 at the time.

Suricata Alerts

Suricata Alerts

Partial alerts generated by Any.Run