Win.Worm.Mantan-1 — RTF / .BAT malware analysis

Static analysis result for SHA-256 c53383309d4024b5…

MALICIOUS

RTF / .BAT

7.7 KB Authoring application: Msftedit 5.41.15.1507
MD5: a433043c0e24c4caa3b6cecdb2f8c10b SHA-1: 36f41b1d00b3e02773d40704772ade1265418d0f SHA-256: c53383309d4024b54fb092bd8688575bee34796777b8d0d6ebc56c8d791bdaff
140 Risk Score

Malware Insights

Win.Worm.Mantan-1 · confidence 95%

MITRE ATT&CK
T1059.001 PowerShell T1547.001 Registry Run Keys / Startup Folder

This script, identified as Win.Worm.Mantan-1 by ClamAV, attempts to achieve persistence by copying itself to multiple locations and writing entries to the registry Run keys, specifically 'HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MSKernel32' and 'HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Win32DLL'. It also attempts to spread by copying itself to network shares and potentially via email. The script constructs URLs from embedded strings, such as 'http://www.skyinet.net/~young1s/HJKhjnwerhjkxcvytwertnMTFwetrdsfmhPnjw6587345gvsdf', which are likely used for downloading additional payloads.

Heuristics 4

  • ClamAV: Win.Worm.Mantan-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Worm.Mantan-1
  • Reference to Windows Script Host high SC_STR_WSCRIPT
    Reference to Windows Script Host
  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.skyinet.net/~young1s/HJKhjnwerhjkxcvytwertnMTFwetrdsfmhPnjw6587345gvsdf
    • http://www.skyinet.net/~angelcat/skladjflfdjghKJnwetryDGFikjUIyqwerWe546786324hjk4j
    • http://www.skyinet.net/~koichi/jf6TRjkcbGRpGqaq198vbFV5hfFEkbopBdQZnmPOhfgER67b3V
    • http://www.skyinet.net/~chu/sdgfhjksdfjklNBmnfgkKLHjkqwtuHJBhAFSDGjkhYUgqweras
    • http://www.mirc.com