MS-Access Email Attachment Drops Keylogger | VTI
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Dropper, Keylogger, Downloader

18f0b09725c3f4cea286aae7fceaec0cd6e49f90c9aa72dcc9c6d748bfe716cd (SHA256)

October_Invoiceb91a6edbc0ialmb3ce5ebc15abba7fe01fda93.accde

Microsoft Access Database

Created at 2019-01-21 16:18:00

Severity Category Operation Classification
5/5
File System Modifies operating system directory -
  • Modifies file "C:\Windows\Installer\MSI81A0.tmp" in the OS directory.
  • Creates file "C:\Windows\Installer\a6cfff.ipi" in the OS directory.
  • Modifies file "C:\Windows\Installer\MSID0F9.tmp" in the OS directory.
  • Modifies file "C:\Windows\Installer\MSI504.tmp" in the OS directory.
  • Creates file "C:\Windows\Installer\MSI504.tmp" in the OS directory.
5/5
Injection Writes into the memory of another running process -
  • "c:\users\jpenum\appdata\local\temp\mw-3cee3894-a0d4-4f50-a87c-21985e988377\files\msmpeng.exe" modifies memory of "c:\windows\microsoft.net\framework\v2.0.50727\regasm.exe"
  • "c:\users\jpenum\appdata\roaming\appmgr\rtlupd64.exe" modifies memory of "c:\windows\microsoft.net\framework\v2.0.50727\regasm.exe"
5/5
Injection Modifies control flow of another process -
  • "c:\users\jpenum\appdata\local\temp\mw-3cee3894-a0d4-4f50-a87c-21985e988377\files\msmpeng.exe" alters context of "c:\windows\microsoft.net\framework\v2.0.50727\regasm.exe"
  • "c:\users\jpenum\appdata\roaming\appmgr\rtlupd64.exe" alters context of "c:\windows\microsoft.net\framework\v2.0.50727\regasm.exe"
4/5
Process Creates process -
  • Creates process "msiexec /q /i https://jplymell.com/dmc/ImgFilePDF876356653680900897fXmfwICxiOWbsPLJpy.png".
  • Creates process "C:\Users\JPenUM\AppData\Local\Temp\MW-3cee3894-a0d4-4f50-a87c-21985e988377\files\MsMpEng.exe".
  • Creates process "C:\Users\JPenUM\AppData\Local\Temp\b106484eb915e4ad6df697dc1442cbff-EDITED.jpg".
  • Creates process "C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe".
4/5
Process Reads from memory of another process -
  • "c:\users\jpenum\appdata\local\temp\mw-3cee3894-a0d4-4f50-a87c-21985e988377\files\msmpeng.exe" reads from "C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe".
  • "c:\users\jpenum\appdata\roaming\appmgr\rtlupd64.exe" reads from "C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe".
4/5
Device Monitors keyboard input Keylogger
  • Installs system wide "WH_KEYBOARD_LL" hook(s) to monitor keystrokes.
4/5
Network Associated with known malicious/suspicious URLs -
  • URL "HTTPS://jplymell.com/dmc/ImgFilePDF876356653680900897fXmfwICxiOWbsPLJpy.png" is known as malicious URL.
  • URL "linkadrum.nl" is known as malicious URL.
4/5
Network Downloads data Downloader
  • URL "HTTPS://jplymell.com/dmc/ImgFilePDF876356653680900897fXmfwICxiOWbsPLJpy.png".
4/5
Persistence Installs system service -
  • Installs service "RtkAudioService64" by using the sc.exe utility.
3/5
Anti Analysis Delays execution -
3/5
Network Performs DNS request -
3/5
Network Connects to remote host -
3/5
PE Executes dropped PE file -
2/5
Anti Analysis Tries to detect debugger -
2/5
Network Connects to HTTP server -
  • URL "jplymell.com/dmc/ImgFilePDF876356653680900897fXmfwICxiOWbsPLJpy.png".
2/5
PE Drops PE file Dropper
1/5
Process Creates system object -
1/5
Static Unparsable sections in file -
  • Static analyzer was unable to completely parse the analyzed file: C:\Users\JPenUM\AppData\Roaming\appmgr\RtlUpd64.exe.
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image