2015-02-09 - CHANITOR/VAWTRAK ACTIVITY

NOTICE:

ASSOCIATED FILES:

 

NOTES:

 

EXAMPLE OF THE EMAILS

SCREENSHOT:

 

MESSAGE TEXT:

From: USPS <no-reply@usps[.]gov>
Date: Monday, February 9, 2015 at 8:06 AM CST
To:
Subject: USPS Delivery Notification

The package could not be delivered by our company's courrier.

REASON: Wrong postal code
PARCEL # : USPS11009489
SHIPMENT TYPE : OVERNIGHT

To reschedule a delivery, visit your post office with a printed copy of the shipping label.
The label has been attached to this notification, in .doc format.

For additional information about our services, you can visit our official website hxxps[:]//www.usps[.]com/

Thank you for using our services.
USPS Global.

Attachment: label_11009489.doc (83.1 KB)

 

INFECTION TRAFFIC

FROM RUNNING THE MALICIOUS WORD DOCUMENT ON A VM:

 

ALERTS FROM THE INFECTED VM

Emerging Threats and ETPRO rulesets from Sguil on Security Onion (without ET POLICY or ET INFO events):

Talos (Sourcefire VRT) ruleset from Snort 2.9.7.0 on Debian 7:

 

PRELIMINARY MALWARE ANALYSIS

EMAIL ATTACHMENT:

File name:  label_11009489.doc
File size:  62,976 bytes
MD5 hash:  97f6d88dcfe5fdcbf6cde2a588ad48bc
Detection ratio:  5 / 57
First submission:  2015-02-09 14:22:02
VirusTotal link:  https://www.virustotal.com/en/file/0616f04ec50d2745f50b40b3ff6c7bf99924f8dea084569afa6fb3b971114b41/analysis/

 

MALWARE FROM THE INFECTED VM - CHANITOR:

File name:  C:\Users\User-1\AppData\Local\Temp\444.exe
File name:  C:\Users\User-1\AppData\Roaming\Windows\winlogin.exe
File size:  153,088 bytes
MD5 hash:  559213eb0689549b424bc3aeafce0086
Detection ratio:  5 / 57
First submission:  2015-02-09 15:02:10 UTC
VirusTotal link:  https://www.virustotal.com/en/file/c20ffd843f1568e635478286721636af0aae0928d4f0b2b910037efe79d620f4/analysis/

 

MALWARE FROM THE INFECTED VM - VAWTRAK:

File name:  C:\ProgramData\ZedfOZbeb\TugeBucb.fec
File size:  278,528 bytes
MD5 hash:  337a01565dc614651d05a37c7cc8f477
Detection ratio:  7 / 57
First submission:  2015-02-09 16:19:19 UTC
VirusTotal link:  https://www.virustotal.com/en/file/71dcc32891588d60acbe7cbe04c038170e9f44120b03dba27a8ab6744674b875/analysis/

 

Click here to return to the main page.