Task Information
Task ID: 64ad1faf-c478-11f1-b2b6-42010aa4000b
File name: 270fe67.exe
Task parameters: ClamAV scan: True
Unpack: False
Share file: True
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
Rule name: Emotet
Alert
Author: kevoreilly
Description: Emotet Payload
TLP: TLP:WHITE
Repository: MalwareBazaar
Rule name: Emotet
Alert
Author: JPCERT/CC Incident Response Group
Description: detect Emotet in memory
Reference: internal research
TLP: TLP:WHITE
Repository: MalwareBazaar
Rule name: malware_Emotet
Alert
Author: JPCERT/CC Incident Response Group
Description: detect Emotet in memory
Reference: internal research
TLP: TLP:WHITE
Repository: JPCERTCC
Rule name: MD5_Constants
Alert
Author: phoul (@phoul)
Description: Look for MD5 constants
TLP: TLP:WHITE
Repository:
Rule name: NET
Alert
Author: malware-lu
TLP: TLP:WHITE
Repository:
Rule name: RIPEMD160_Constants
Alert
Author: phoul (@phoul)
Description: Look for RIPEMD-160 constants
TLP: TLP:WHITE
Repository:
Rule name: SHA1_Constants
Alert
Author: phoul (@phoul)
Description: Look for SHA1 constants
TLP: TLP:WHITE
Repository:
Rule name: classified
Author: classified
TLP : TLP:AMBER
Rule name: Win32_Trojan_Emotet
Alert
Author: ReversingLabs
Description: Yara rule that detects Emotet trojan.
TLP: TLP:WHITE
Rule name: Windows_Trojan_Emotet_1943bbf2
Alert
Author: Elastic Security
Reference: https://www.elastic.co/security-labs/emotet-dynamic-configuration-extraction
TLP: TLP:WHITE
Repository: elastic
Unpacker
The following YARA rules matched on the unpacked file.
Disabled by submitter
Unpacked Files
The following files could be unpacked from this sample.
Disabled by submitter