Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Emmenhtal

47
Global rank
52 infographic chevron month
Month rank
58 infographic chevron week
Week rank

First identified in 2024, Emmenhtal operates by embedding itself within modified legitimate Windows binaries, often using HTA (HTML Application) files to execute malicious scripts. It has been linked to the distribution of malware such as CryptBot and Lumma Stealer. Emmenhtal is typically disseminated through phishing campaigns, including fake video downloads and deceptive email attachments.

Loader
Type
Unknown
Origin
1 June, 2024
First seen
18 September, 2026
Last seen

How to analyze Emmenhtal with ANY.RUN

Type
Unknown
Origin
1 June, 2024
First seen
18 September, 2026
Last seen

IOCs

IP addresses
142.251.14.94
172.217.119.4
142.251.14.95
142.250.154.94
142.251.127.84
74.125.29.95
192.178.170.136
48.209.138.189
172.217.208.102
2.23.246.9
172.217.118.4
172.217.116.4
74.178.76.54
135.233.95.144
142.251.127.139
192.178.170.95
192.178.183.138
142.251.14.101
142.250.154.139
192.178.183.95
Hashes
a11703fd47d16020fa099a95bb4e46247d32cf8821dc1826e77a971cdd3c4c55
3b64b79e4092251ebf090164cd2c4815390f34849bbd76fb51085b6a13301b6d
b2f57a23ecc789c1bbf6037ac0825bf98babc7bf0c5d438af5e2767a27a79188
b2f7fb22cd5b935cf19a2f58f7fef9db99db40772ff4bb331a73c345161c2574
12f600b09c0db00877684a950fc14936ecc28df8f0ddc6821d68e4b82077ad92
3f3c5ce486e5b9fa88dc60b60916053e8808c69167df1a11287fd3cd6db1ca6e
45c85bdaaf0e0c30678d8d77e2585871ea6d1298ee0d30037745bacea6338484
6ea04cf08751a2f6bb2f0e994258a44d5183b6cdb1471a0ee285659eada045b5
a65cbbdc2ca671a9edd7edac0c6737b3b116e357727e003e5fdeff163c6c21ab
440912d85d2f98bb4f508ab82847067c18e1e15be0d8ecdcff0cc19327527fc2
58c755fcfc65cddea561023d736e8991f0ad69da5e1378dea59e98c5db901b86
3701b19ccdac79b880b197756a972027e2ac609ebed36753bd989367ea4ef519
b7a6eea19188b987dad97b32d774107e9a1beb4f461a654a00197d73f7fad54c
79ee87d4ede8783461de05b93379d576f6e8575d4ab49359f15897a854b643c4
b8883cf42b9c5eedec83aa88d9b6d9a02bf1e83c03066465877e0da6ed680d00
08caefcaed31eb1fe6f0271019897483d2030011d3ac290eabefb2322947d41c
c900ba9a2d8318263fd43782ee6fd5fb50bad78bf0eb2c972b5922c458af45ed
cb190e7d1b002a3050705580dd51eba895a19eb09620bdd48d63085d5d88031e
a08c1bc41de319392676c7389048d8b1c7424c4b74d2f6466bcf5732b8d86642
43daa4139d3ed90f4b4635bd4d32346eb8e8528d0d5332052fcda8f7860db729
Domains
clientservices.googleapis.com
settings-win.data.microsoft.com
google.com
ssl.gstatic.com
client.wns.windows.com
www.microsoft.com
www.google.com
fonts.googleapis.com
sb-ssl.google.com
edgedl.me.gvt1.com
slscr.update.microsoft.com
ogads-pa.clients6.google.com
crl.microsoft.com
go.microsoft.com
play.google.com
clients6.google.com
safebrowsingohttpgateway.googleapis.com
clients1.google.com
safebrowsing.googleapis.com
www.gstatic.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://clients2.google.com/time/1/current?cup2key=8:tfh00hqqbon_fbffxsnmx_6phe3yqkfgmcgesrhpjio&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
https://drive.google.com/file/d/15xysjt1tfifkturckcm0eqzpjybmch1v/view
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard
https://www.gstatic.com/_/apps-fileview/_/ss/k=apps-fileview.v.lhoiw7i9ltg.l.w.o/am=aaeqya/d=0/rs=ao0039u6a_8rztflliwsr2xzuzpu7yifqq
https://www.gstatic.com/_/apps-fileview/_/js/k=apps-fileview.v.it.2puspkaypr4.o/am=aaeqya/d=1/rs=ao0039snmjasjxncqw8bq3_zsq-bgfduhw/m=v,wb?wli=v.o42y1989d9u.inkloadthreadedwasmmodule.o%3a%3bv.sagoth8aal8.inkloadwasmmodule.o%3a%3b
https://www.gstatic.com/og/_/ss/k=og.asy.rge7u-o-moe.l.w.o/m=adcgm3/excm=/d=1/ed=1/ct=zgms/rs=aa2yrts8gbyccjliqdtvqgamlkye7-tmqa
https://www.gstatic.com/og/_/js/k=og.asy.en_us.6huusnc_zia.2019.o/rt=j/m=_ac,_awd,ada,lldp,qads/exm=/d=1/ed=1/rs=aa2yrtuyzoza5ctz8csunvocbk8z32acfg
https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js
https://www.gstatic.com/_/apps-fileview/_/js/k=apps-fileview.v.it.2puspkaypr4.o/am=aaeqya/d=0/rs=ao0039snmjasjxncqw8bq3_zsq-bgfduhw/m=mpjwzc,sy0,ws9tlc,cet90b,l1aakb,n73qwf,syk,syn,cfcnle,syv,syx,k4ngs,riinwe,vydpfd,mh0hje,i8onzb,syl,sym,pxafod,d6fvzd,yb08jf,sy5y,wq7hzd,i5xtjf,d2pbef,x8dpac,eqnqze,bdroqf,yd6uhe,uyurdf,bfryr,cdkwde,my07e,jsanwd,ntt8nd,h7spvd,yzxypc,yv5tjf,nvjjgd,hkzshb,i7byt,mgml8b,yg091c,bge1db,sye1,d6kwg,ctukxe,vhav8b,sy11,lbajxb,sy12,sy15,syq,syr,xl71df,agvpn,i5h9n,sy5t,sy5u,sy5v,syt,sy5q,sy5r,sy5s,h4jose,sy5w,febled,uoeu0c,sy5x,sys,bz0mod,zvhseb,qvysje,awppdd,cephkf,qbxz0e,vgaoke?wli=v.o42y1989d9u.inkloadthreadedwasmmodule.o%3a%3bv.sagoth8aal8.inkloadwasmmodule.o%3a%3b
https://www.gstatic.com/_/apps-fileview/_/js/k=apps-fileview.v.it.2puspkaypr4.o/am=aaeqya/d=0/rs=ao0039snmjasjxncqw8bq3_zsq-bgfduhw/m=iic5yd,syo,syp,tcmktd?wli=v.o42y1989d9u.inkloadthreadedwasmmodule.o%3a%3bv.sagoth8aal8.inkloadwasmmodule.o%3a%3b
https://www.gstatic.com/_/apps-fileview/_/js/k=apps-fileview.v.it.2puspkaypr4.o/am=aaeqya/d=0/rs=ao0039snmjasjxncqw8bq3_zsq-bgfduhw/m=g5zzub,sycz,a9i3ec?wli=v.o42y1989d9u.inkloadthreadedwasmmodule.o%3a%3bv.sagoth8aal8.inkloadwasmmodule.o%3a%3b
https://www.gstatic.com/_/apps-fileview/_/js/k=apps-fileview.v.it.2puspkaypr4.o/am=aaeqya/d=0/rs=ao0039snmjasjxncqw8bq3_zsq-bgfduhw/m=xdxysc,zzyu3e,syc,dtt8pd,cnr82b,lxq0q,gi8h7,gwpudb,ewgnae,kwmhud,syw,o626fe,pivayb,wd3m3d,sydi,ty7deb,sy25,sye2,dxps4e,imwypc,rbt6j,rjloye,clc79c,qu6jbd?wli=v.o42y1989d9u.inkloadthreadedwasmmodule.o%3a%3bv.sagoth8aal8.inkloadwasmmodule.o%3a%3b
https://www.gstatic.com/_/apps-fileview/_/js/k=apps-fileview.v.it.2puspkaypr4.o/am=aaeqya/d=0/rs=ao0039snmjasjxncqw8bq3_zsq-bgfduhw/m=sye8,jjj6dc,vxj6kc,sye9,k4q0te?wli=v.o42y1989d9u.inkloadthreadedwasmmodule.o%3a%3bv.sagoth8aal8.inkloadwasmmodule.o%3a%3b
https://www.gstatic.com/_/apps-fileview/_/js/k=apps-fileview.v.it.2puspkaypr4.o/am=aaeqya/d=0/rs=ao0039snmjasjxncqw8bq3_zsq-bgfduhw/m=sy10,izcpqc,l4cvxb?wli=v.o42y1989d9u.inkloadthreadedwasmmodule.o%3a%3bv.sagoth8aal8.inkloadwasmmodule.o%3a%3b
https://www.gstatic.com/_/apps-fileview/_/js/k=apps-fileview.v.it.2puspkaypr4.o/am=aaeqya/d=0/rs=ao0039snmjasjxncqw8bq3_zsq-bgfduhw/m=ne5iue,jv6obf?wli=v.o42y1989d9u.inkloadthreadedwasmmodule.o%3a%3bv.sagoth8aal8.inkloadwasmmodule.o%3a%3b
https://www.gstatic.com/_/apps-fileview/_/js/k=apps-fileview.v.it.2puspkaypr4.o/am=aaeqya/d=0/rs=ao0039snmjasjxncqw8bq3_zsq-bgfduhw/m=qdbucd?wli=v.o42y1989d9u.inkloadthreadedwasmmodule.o%3a%3bv.sagoth8aal8.inkloadwasmmodule.o%3a%3b
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 3724
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 4187
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 5504
comments 0

What is Emmenhtal malware?

Emmenhtal is a loader malware first observed in early 2024, designed to deploy infostealers and remote access trojans (RATs) on compromised systems. Usually distributed through phishing campaigns involving fake downloads or deceptive email attachments, Emmenhtal embeds itself within modified legitimate Windows binaries.

Its key functionality includes executing malicious scripts via HTA (HTML Application) files and facilitating the distribution of malware such as CryptBot and Lumma Stealer.

According to research conducted by ANY.RUN, Emmenhtal utilizes LOLBAS (Living Off the Land Binaries and Scripts) to deliver malware as part of its campaigns.

The malware has been found distributing threats such as Arechclient2, Lumma Stealer, HijackLoader, and Amadey, with each sample relying heavily on malicious scripts. These scripts can be analyzed in-depth using ANY.RUN’s Script Tracer.

Simply upload the malicious sample inside the sandbox and observe its behavior in real time, without causing harm to your system. Analysis of Emmenhtal inside ANY.RUN sandbox Emmenhtal loader observed inside ANY.RUN sandbox

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Emmenhtal malware technical details

The primary functionalities and features of Emmenhtal loader include:

  • Utilizes legitimate Windows tools like Forfiles, HelpPane, and PowerShell to evade detection and execute payloads.
  • Employs a multi-stage process with AES-encrypted scripts to decrypt and execute the final malware payload.
  • Known to distribute various malware, including Arechclient2, Lumma Stealer, HijackLoader, and Amadey.
  • Heavily obfuscates scripts and payloads, employing AES encryption to avoid detection by security systems.
  • Typically distributed through phishing campaigns, fake downloads, and deceptive email attachments.
  • Relies heavily on malicious scripts for payload execution and persistence.
  • Ensures it remains on the system post-infection by integrating persistence mechanisms.
  • Functions as a flexible loader, adaptable to deliver a range of malware types.
  • Frequently launches payloads disguised as legitimate binaries, such as Updater.exe, to blend in with normal system activity.
  • Believed to be used by multiple financially motivated threat actors in global campaigns.

Emmenthal loader execution process

To see how Emmenthal operates, let’s upload its sample into ANY.RUN’s Interactive Sandbox.

Emmenhtal heavily relies on Living Off The Land (LOLBAS) techniques to deliver malware as part of its campaigns. The malware uses various execution methods. In our case, a .lnk file was crafted to appear as a PDF document, but in reality, it pointed to malicious scripts hosted on a remote server. These shortcuts execute scripts and initiate further actions without immediately raising security alerts.

Ssh.exe displayed inside ANY.RUN sandbox Ssh.exe displayed in ANY.RUN sandbox

The malware employs both PowerShell and Windows Management Instrumentation (WMI) commands to gather detailed information about the victim’s system. This includes language settings, antivirus products, operating system versions, and hardware specifications. Such reconnaissance enables attackers to tailor subsequent attacks and enhances their credibility when sending additional malicious emails within the targeted organization.

Ultimately, a final PowerShell script serves as the Emmenhtal loader. It launches a payload, often Updater.exe, but in our example R-Viewer.exe, along with a binary file that has a generated (random) name as its argument. After this process completes, the system is effectively compromised. During our analysis, we observed Emmenhtal delivering several malware families, including Arechclient2, Lumma, Hijackloader, and Amadey, each making extensive use of malicious scripting techniques.

Execution Chain:

  1. The .lnk file initiates SSH.
  2. SSH starts PowerShell.
  3. PowerShell launches Mshta with the AES-encrypted first-stage payload.
  4. Mshta decrypts and executes the downloaded payload.
  5. PowerShell executes an AES-encrypted command to decrypt and run Emmenhtal.

Process tree observed inside ANY.RUN sandbox Process tree observed inside ANY.RUN sandbox

Emmenhtal loader distribution methods

Emmenhtal loader employs several distribution methods:

  • Phishing campaigns: Emmenhtal is often disseminated through phishing emails containing malicious attachments or links that lead to the download of the loader.
  • Fake downloads: Users are tricked into downloading Emmenhtal by disguising it as legitimate software or video files, commonly hosted on compromised websites or through deceptive ads.
  • Compromised legitimate files: It is delivered through modified Windows binaries to appear legitimate.
  • Script-based delivery: Uses HTA (HTML Application) files and other scripts to execute malicious payloads.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Gathering Threat Intelligence on Emmenhtal Malware

To stay informed about Emmenhtal and collect relevant intel, use Threat Intelligence Lookup.

This service grants access to an extensive database with insights from millions of malware analysis sessions conducted in the ANY.RUN sandbox. With over 40 customizable search parameters, users can pinpoint data on threats, including IPs, domains, file names, and process artifacts.

Search results for Emmenhtal in Threat Intelligence Lookup Search results for Emmenhtal in Threat Intelligence Lookup

For example, you can search for Emmenhtal by its name or related artifacts. A query like threatName:"Emmenhtal" will retrieve all associated samples and sandbox results relevant to this loader malware.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Emmenhtal is a dangerous loader malware due to its use of LOLBAS tactics, heavy obfuscation, and ability to deliver multiple malware types. To combat such threats, integrating tools like ANY.RUN can help proactively analyze suspicious files and URLs before they cause damage.

ANY.RUN is an interactive malware analysis platform that offers real-time insights into malicious activity. Its features include visualized execution chains, script tracing, support for analyzing Windows and Linux-based threats, and much more.

Sign up for a free ANY.RUN account and start analyzing threats with confidence!

HAVE A LOOK AT

UpCrypter screenshot
UpCrypter
upcrypter
UpCrypter is a sophisticated malware loader that functions as a delivery mechanism for remote access tools. Distributed through global phishing campaigns targeting Windows systems, this actively maintained tool serves as the central framework for deploying various RATs including PureHVNC, DCRat, and Babylon RAT, enabling attackers to establish persistent remote control over compromised systems.
Read More
LokiBot screenshot
LokiBot
lokibot loader trojan
LokiBot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.
Read More
ClickFix screenshot
ClickFix is a sophisticated social engineering technique that tricks users into manually executing malicious commands on their devices. It masquerades as a "quick fix" for fake technical issues, CAPTCHA verifications, or error messages, often hijacking the clipboard to paste harmful PowerShell or terminal commands. This user-assisted approach helps it bypass traditional security controls, leading to infostealers like Lumma Stealer, RATs, and other malware.
Read More
CryptoWall screenshot
CryptoWall
cryptowall
CryptoWall is a notorious ransomware family that emerged in early 2014 and rapidly became one of the most destructive cyber threats of its time. This malware encrypts victims' files using strong AES encryption, demands ransom payments in Bitcoin, and has generated hundreds of millions of dollars for cybercriminals.
Read More
Crocodilus screenshot
Crocodilus
crocodilus
Crocodilus is a highly sophisticated Android banking Trojan that emerged in March 2025, designed for full device takeover. Disguised as legitimate apps, it steals banking credentials, cryptocurrency wallet data, and enables remote control, rapidly evolving into a global threat targeting financial users across Europe, South America, and Asia.
Read More
DragonForce screenshot
DragonForce
dragonforce
DragonForce is a ransomware strain operating under the Ransomware-as-a-Service (RaaS) model. First reported in December 2023, it encrypts files with ChaCha8, renames them with random strings, and appends “.dragonforce_encrypted.” By disabling backups, wiping recovery, and spreading across SMB shares, DragonForce maximizes damage and pressures victims into multimillion-dollar ransom negotiations. It has targeted manufacturing, construction, IT, healthcare, and retail sectors worldwide, making it a severe threat to modern enterprises.
Read More