| File name: | Todesk远程桌面_1037_425eb.exe |
| Full analysis: | https://app.any.run/tasks/cde29169-df18-4830-9455-e4a8f7c40c4a |
| Verdict: | Malicious activity |
| Threats: | First identified in 2024, Emmenhtal operates by embedding itself within modified legitimate Windows binaries, often using HTA (HTML Application) files to execute malicious scripts. It has been linked to the distribution of malware such as CryptBot and Lumma Stealer. Emmenhtal is typically disseminated through phishing campaigns, including fake video downloads and deceptive email attachments. |
| Analysis date: | June 13, 2025, 08:55:02 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 0493252310C104FBC2CE86C1854FBD4F |
| SHA1: | AC559AEF70D8CC5EE6606846FA176B41AB29E5CD |
| SHA256: | 256C34DD2E94CBFCED6D841158F249E4247F3EEE23F23964CEC47649825C7ACE |
| SSDEEP: | 24576:aIZKh8uILxXS8LksJWqp1j/uh0NKkGB+f:aIZKh8uILxXS8LksAqpluh0NKz+f |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:05:23 04:07:36+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 781824 |
| InitializedDataSize: | 243200 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x5e1d3 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.0.1091 |
| ProductVersionNumber: | 2.0.0.1091 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | Unknown (0004) |
| CharacterSet: | Unicode |
| CompanyName: | 360.cn |
| FileDescription: | InstallSoft.exe |
| FileVersion: | 2, 0, 0, 1091 |
| InternalName: | InstSoft.exe |
| LegalCopyright: | (C) 360.cn All Rights Reserved. |
| OriginalFileName: | InstallSoft.exe |
| ProductVersion: | 2, 0, 0, 1091 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 608 | %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16 | C:\Windows\System32\csrss.exe | — | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Client Server Runtime Process Version: 10.0.19041.1 (WinBuild.160101.0800) | |||||||||||||||
| 1068 | "C:\Program Files (x86)\360\360Safe\Utils\360seclogon\360SecLogonHelper.exe" | C:\Program Files (x86)\360\360Safe\Utils\360SecLogon\360SecLogonHelper.exe | Todesk远程桌面_1037_425eb.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: 360安全卫士 系统安全登录辅助模块 Exit code: 0 Version: 1, 0, 0, 1037 Modules
| |||||||||||||||
| 1164 | "C:\Program Files (x86)\360\360Safe\SoftMgr\SoftupNotify.exe" /install | C:\Program Files (x86)\360\360Safe\SoftMgr\SoftupNotify.exe | — | Todesk远程桌面_1037_425eb.exe | |||||||||||
User: admin Company: 360.cn Integrity Level: HIGH Description: 360软件管家 Exit code: 0 Version: 16, 0, 0, 1050 Modules
| |||||||||||||||
| 1192 | "C:\Program Files (x86)\360\360Safe\safemon\WscReg.exe" /install | C:\Program Files (x86)\360\360Safe\safemon\WscReg.exe | — | 360Tray.exe | |||||||||||
User: admin Company: 360.cn Integrity Level: HIGH Description: 360安全卫士 安全中心接口 Exit code: 0 Version: 10, 0, 0, 8120 Modules
| |||||||||||||||
| 1352 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1604 | "C:\Users\admin\AppData\Local\Temp\Todesk远程桌面_1037_425eb.exe" | C:\Users\admin\AppData\Local\Temp\Todesk远程桌面_1037_425eb.exe | — | explorer.exe | |||||||||||
User: admin Company: 360.cn Integrity Level: MEDIUM Description: InstallSoft.exe Exit code: 3221226540 Version: 2, 0, 0, 1091 Modules
| |||||||||||||||
| 1700 | "C:\Program Files (x86)\360\360Safe\softmgr\EaInstHelper64.exe" /Install | C:\Program Files (x86)\360\360Safe\SoftMgr\EaInstHelper64.exe | Todesk远程桌面_1037_425eb.exe | ||||||||||||
User: admin Company: 360.cn Integrity Level: HIGH Description: 360安全卫士 安全防护模块 Exit code: 0 Version: 1, 0, 0, 1055 Modules
| |||||||||||||||
| 2276 | "C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files (x86)\360\360Safe\Utils\shell360ext64.dll" | C:\Windows\System32\regsvr32.exe | Todesk远程桌面_1037_425eb.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2460 | "C:\Program Files (x86)\360\360Safe\deepscan\zhudongfangyu.exe" /Start | C:\Program Files (x86)\360\360Safe\deepscan\ZhuDongFangYu.exe | — | Todesk远程桌面_1037_425eb.exe | |||||||||||
User: admin Company: 360.cn Integrity Level: HIGH Description: 360主动防御服务模块 Exit code: 0 Version: 3, 2, 2, 3105 Modules
| |||||||||||||||
| 2952 | "C:\Program Files (x86)\360\360Safe\Utils\PowerSaver.exe" /flightsigning /HImmu | C:\Program Files (x86)\360\360Safe\Utils\PowerSaver.exe | — | Todesk远程桌面_1037_425eb.exe | |||||||||||
User: admin Company: 360.cn Integrity Level: HIGH Description: 360安全卫士卸载清理模块 Exit code: 0 Version: 11.0.0.1111 Modules
| |||||||||||||||
| (PID) Process: | (6268) Todesk远程桌面_1037_425eb.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted |
| Operation: | write | Name: | C:\Users\admin\AppData\Local\Temp\Todesk远程桌面_1037_425eb.exe |
Value: 1 | |||
| (PID) Process: | (6268) Todesk远程桌面_1037_425eb.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\360Safe\Liveup |
| Operation: | write | Name: | mid |
Value: 80342cb959da2233832ae840f019ccba8b56b331eb673be97c52113eab1cd1bc | |||
| (PID) Process: | (6268) Todesk远程桌面_1037_425eb.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\360Safe\Liveup |
| Operation: | write | Name: | m2 |
Value: fe9694f777e256d0cc4755a6dd1f6ad7651f60d32bec | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0 |
| Operation: | write | Name: | CheckSetting |
Value: 23004100430042006C006F00620000000000000000000000010000000000000000000000 | |||
| (PID) Process: | (6268) Todesk远程桌面_1037_425eb.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6268) Todesk远程桌面_1037_425eb.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6268) Todesk远程桌面_1037_425eb.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000080272 |
| Operation: | write | Name: | VirtualDesktop |
Value: 10000000303044563096AFED4A643448A750FA41CFC7F708 | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop |
| Operation: | write | Name: | IconLayouts |
Value: 00000000000000000000000000000000030001000100010012000000000000002C000000000000003A003A007B00360034003500460046003000340030002D0035003000380031002D0031003000310042002D0039004600300038002D003000300041004100300030003200460039003500340045007D003E002000200000001000000000000000430043006C00650061006E00650072002E006C006E006B003E0020007C0000001500000000000000410064006F006200650020004100630072006F006200610074002E006C006E006B003E0020007C0000001200000000000000640065006200740076006900730069006F006E002E006A00700067003E002000200000000F00000000000000460069007200650066006F0078002E006C006E006B003E0020007C000000150000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B003E0020007C000000180000000000000056004C00430020006D006500640069006100200070006C0061007900650072002E006C006E006B003E0020007C00000016000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B003E0020007C0000001100000000000000610062006C00650077006F0075006C0064002E006A00700067003E00200020000000120000000000000061006E0079006F006E0065006C006100770073002E007200740066003E0020002000000014000000000000006C006F0077006500720061006900720070006F00720074002E007200740066003E0020002000000014000000000000006D0069006C00690074006100720079007400680061006E002E007200740066003E00200020000000130000000000000070006C0061006300650073006C006100620065006C002E006A00700067003E00200020000000180000000000000070006F007300740065006400660075006E006300740069006F006E0061006C002E007200740066003E0020002000000015000000000000007200650061006C006C0079006A0061006E0075006100720079002E006A00700067003E002000200000001B0000000000000073007000720069006E0067006F007200670061006E0069007A006100740069006F006E0073002E007200740066003E00200020000000120000000000000073007400610074007500730073006B0069006E002E007200740066003E002000200000001600000000000000740065007300740069006E0067006D0069007300730069006F006E002E007200740066003E00200020000000010000000000000002000100000000000000000001000000000000000200010000000000000000001100000006000000010000001200000000000000000000000000000000000000803F0000004008000000803F000040400900000000000000404003000000803F000080400A000000803F0000A0400B0000000040000000000C00000000400000803F0D0000000040000000400E0000000040000040400F0000000040000080401000000000400000A0401100000000000000803F01000000000000000040020000000000000080400400000000000000A04005000000803F0000000006000000803F0000803F0700 | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop |
| Operation: | write | Name: | IconNameVersion |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6268 | Todesk远程桌面_1037_425eb.exe | C:\Users\admin\AppData\Local\Temp\{76F1CE13-99F8-4bb2-9A1B-8FA0F8930334}.tmp | binary | |
MD5:B91AFD7111C9A4BFAA3D8EAC4C1716EF | SHA256:889CF88E593853F9C1C9B03C1A7755FE1BB23EFEC5435E46D61BABEB90A45035 | |||
| 6268 | Todesk远程桌面_1037_425eb.exe | C:\Users\admin\AppData\Local\Temp\{4DA6A021-C317-434b-9E6B-459895BCD2E9}.tmp | binary | |
MD5:4DFF4F9A9DF081717CE8DA72D66FC8A4 | SHA256:CB18D3200C00638796991B86135A58333D8C8886A4570696424993C4FB740520 | |||
| 6268 | Todesk远程桌面_1037_425eb.exe | C:\Users\admin\AppData\Local\Temp\{F4D4350B-05C8-4232-A299-0BA129809A17}.tmp | binary | |
MD5:DE00B506A1563E0F9E033DE377E3B766 | SHA256:B0178F61D4F469686C6583C4AFB2430AC9412D8D0A529FD8ED3ECC7A2B15D996 | |||
| 6268 | Todesk远程桌面_1037_425eb.exe | C:\Users\admin\AppData\Local\Temp\{E914E039-09F8-4c13-BFD9-D33578A1D1E0}\jPiJtFoQrRrSiIfV.tmp | binary | |
MD5:A17BCBC593F10CB4161A46F99DD7040E | SHA256:41D1CE91A34763818F4CC30567A6E4428A519EC4F64907DE444165F3C6AE6D79 | |||
| 6268 | Todesk远程桌面_1037_425eb.exe | C:\Users\admin\AppData\Local\Temp\{427E951F-12B7-466c-9F0E-711AFF6A1B6D}.tmp | binary | |
MD5:A873F14CCBE7DF387C611EBDCC568869 | SHA256:366D30DA335741331A09788AAFDE8CB8A6E580C66B65BA05C2BAFA0E3ED927AA | |||
| 6268 | Todesk远程桌面_1037_425eb.exe | C:\Users\admin\AppData\Local\Temp\{F54D9B3F-3E9D-4ca7-AC7F-01BC0D65A747}.tmp | binary | |
MD5:A80D572499AFB75D2032DEBA88F43A5C | SHA256:AF7F759B455628C54EE142848F77D9E161AEFBA5E5E91A04245FB21A828B2C4E | |||
| 6268 | Todesk远程桌面_1037_425eb.exe | C:\Users\admin\AppData\Local\Temp\{4527C245-80F9-4702-BAD2-DA18F1D59284}.tmp | binary | |
MD5:2C3372C2A4112E15A994E003F891C2D3 | SHA256:BA07E7E6284B9B4C60FA109DDB71AADF400F0383E3E62238F61E3AE21A6893FF | |||
| 6268 | Todesk远程桌面_1037_425eb.exe | C:\Users\admin\AppData\Local\Temp\wXmApGnQlWlFlAmE\360ini.dll | executable | |
MD5:F47309E65852FB80D3D4FF473DACC4AC | SHA256:BF185055A6C074A784FAFDD78982EAF54A4BFA807FA604F9AD096EBC5685B863 | |||
| 6268 | Todesk远程桌面_1037_425eb.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\360ini[1].cab | compressed | |
MD5:4612DE1425D198498C77B958E354FC37 | SHA256:D90F56FD779BE952DDFF327A0134251D5F9C0D4039D233CF82529AA0BE6BA03F | |||
| 6268 | Todesk远程桌面_1037_425eb.exe | C:\Users\admin\AppData\Local\Temp\{17ECB454-C214-4bfc-84F9-5743E0C5A60E}\xTxKnAjFaYhAzCxO.tmp | binary | |
MD5:746AB6BF6608096EDD52FD836968E34B | SHA256:FBE43F0C7CC3371FAC78E9F4E5DA8799C022D85D66D46C8374639AC25DA7DBF5 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1268 | svchost.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6268 | Todesk远程桌面_1037_425eb.exe | GET | 200 | 138.113.20.168:80 | http://sfdl.360safe.com/gf/360ini.cab | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 2.16.168.114:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6268 | Todesk远程桌面_1037_425eb.exe | HEAD | 200 | 138.113.20.168:80 | http://sfdl.360safe.com/gf/360ini.cab | unknown | — | — | whitelisted |
6268 | Todesk远程桌面_1037_425eb.exe | GET | 200 | 101.198.2.147:80 | http://s.360.cn/safe/instcomp.htm?soft=2023040419&status=1&pid=319385&mid=80342cb959da2233832ae840f019ccba&m2=fe9694f777e256d0cc4755a6dd1f6ad7651f60d32bec | unknown | — | — | whitelisted |
6268 | Todesk远程桌面_1037_425eb.exe | GET | 200 | 101.198.2.147:80 | http://s.360.cn/hips/update/inst.htm?m=80342cb959da2233832ae840f019ccba&m2=fe9694f777e256d0cc4755a6dd1f6ad7651f60d32bec&v=2001310&s=700&r=0&d=99990001 | unknown | — | — | whitelisted |
6268 | Todesk远程桌面_1037_425eb.exe | GET | 200 | 101.198.2.147:80 | http://s.360.cn/hips/update/inst.htm?m=80342cb959da2233832ae840f019ccba&m2=fe9694f777e256d0cc4755a6dd1f6ad7651f60d32bec&v=2001310&s=705&r=0&d=99990001 | unknown | — | — | whitelisted |
6268 | Todesk远程桌面_1037_425eb.exe | GET | 200 | 101.198.2.147:80 | http://s.360.cn/hips/update/inst.htm?m=80342cb959da2233832ae840f019ccba&m2=fe9694f777e256d0cc4755a6dd1f6ad7651f60d32bec&v=2001310&s=3000&r=0&d=0 | unknown | — | — | whitelisted |
6268 | Todesk远程桌面_1037_425eb.exe | GET | 200 | 101.198.2.147:80 | http://s.360.cn/hips/update/inst.htm?m=80342cb959da2233832ae840f019ccba&m2=fe9694f777e256d0cc4755a6dd1f6ad7651f60d32bec&v=2001310&s=3001&r=0&d=0 | unknown | — | — | whitelisted |
6268 | Todesk远程桌面_1037_425eb.exe | GET | 200 | 101.198.2.147:80 | http://s.360.cn/hips/update/inst.htm?m=80342cb959da2233832ae840f019ccba&m2=fe9694f777e256d0cc4755a6dd1f6ad7651f60d32bec&v=2001310&s=1200&r=0&d=319385 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1268 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2228 | RUXIMICS.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6268 | Todesk远程桌面_1037_425eb.exe | 101.198.193.210:443 | baoku.360.cn | Beijing Qihu Technology Company Limited | CN | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6268 | Todesk远程桌面_1037_425eb.exe | 101.198.2.147:80 | s.360.cn | IDC, China Telecommunications Corporation | CN | whitelisted |
6268 | Todesk远程桌面_1037_425eb.exe | 138.113.20.168:80 | sfdl.360safe.com | QUANTILNETWORKS | US | whitelisted |
1268 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1268 | svchost.exe | 2.16.168.114:80 | crl.microsoft.com | Akamai International B.V. | RU | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
baoku.360.cn |
| whitelisted |
s.360.cn |
| whitelisted |
sfdl.360safe.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
grow.safe.360.cn |
| whitelisted |
inf.safe.360.cn |
| whitelisted |
dl.360safe.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
4772 | explorer.exe | Potential Corporate Privacy Violation | ET INFO PE EXE or DLL Windows file download HTTP |
4772 | explorer.exe | Misc activity | ET INFO Packed Executable Download |
6268 | Todesk远程桌面_1037_425eb.exe | Potential Corporate Privacy Violation | ET INFO PE EXE or DLL Windows file download HTTP |
6268 | Todesk远程桌面_1037_425eb.exe | Misc activity | ET INFO Packed Executable Download |