| download: | 6r8z-cuctny-qang |
| Full analysis: | https://app.any.run/tasks/6229cef3-f14e-42df-a24c-e464b4bdecf8 |
| Verdict: | Malicious activity |
| Threats: | Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns. |
| Analysis date: | April 10, 2019, 15:15:02 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with very long lines, with no line terminators |
| MD5: | B258E1DBEFFEFCA5D269B79FEF64C415 |
| SHA1: | 91EABCB2573783B4B6BF72CB1C40FA8078FCB66F |
| SHA256: | 7853439472ED9CD4358D92492C3ABBB44D2AE46A2E3FBCEEBEA2BCD858E4EBAA |
| SSDEEP: | 96:aXwEE60nwZMadJtvg784luIaw/MAbmNSNBZ:0E60nwZVPvg7/luIa2MACNSNz |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 920 | "C:\Users\admin\AppData\Local\soundser\soundser.exe" | C:\Users\admin\AppData\Local\soundser\soundser.exe | m4myvtnv1.exe | ||||||||||||
User: admin Company: 360.cn Integrity Level: MEDIUM Description: 360???? ?????????? Exit code: 0 Version: 1, 0, 0, 1018 Modules
| |||||||||||||||
| 1708 | --3d5f8f7c | C:\Users\admin\AppData\Local\Temp\m4myvtnv1.exe | m4myvtnv1.exe | ||||||||||||
User: admin Company: 360.cn Integrity Level: MEDIUM Description: 360???? ?????????? Exit code: 0 Version: 1, 0, 0, 1018 Modules
| |||||||||||||||
| 1888 | "C:\Users\admin\AppData\Local\Temp\m4myvtnv1.exe" | C:\Users\admin\AppData\Local\Temp\m4myvtnv1.exe | — | WScript.exe | |||||||||||
User: admin Company: 360.cn Integrity Level: MEDIUM Description: 360???? ?????????? Exit code: 0 Version: 1, 0, 0, 1018 Modules
| |||||||||||||||
| 1916 | "C:\Users\admin\AppData\Local\soundser\EQSuC9Rqw8bRmLS1YO.exe" | C:\Users\admin\AppData\Local\soundser\EQSuC9Rqw8bRmLS1YO.exe | — | soundser.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1928 | "C:\Users\admin\AppData\Local\soundser\soundser.exe" | C:\Users\admin\AppData\Local\soundser\soundser.exe | EQSuC9Rqw8bRmLS1YO.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2436 | --d69f700e | C:\Users\admin\AppData\Local\soundser\EQSuC9Rqw8bRmLS1YO.exe | EQSuC9Rqw8bRmLS1YO.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2512 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\6r8z-cuctny-qang | C:\Windows\system32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2828 | --3ab57678 | C:\Users\admin\AppData\Local\soundser\soundser.exe | soundser.exe | ||||||||||||
User: admin Company: 360.cn Integrity Level: MEDIUM Description: 360???? ?????????? Exit code: 0 Version: 1, 0, 0, 1018 Modules
| |||||||||||||||
| 2960 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\6r8z-cuctny-qang.js" | C:\Windows\System32\WScript.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 3208 | --3ab57678 | C:\Users\admin\AppData\Local\soundser\soundser.exe | soundser.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2512) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | LangID |
Value: 0904 | |||
| (PID) Process: | (2512) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe |
Value: Adobe Acrobat Reader DC | |||
| (PID) Process: | (2512) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Windows\eHome\ehshell.exe |
Value: Windows Media Center | |||
| (PID) Process: | (2512) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Internet Explorer\iexplore.exe |
Value: Internet Explorer | |||
| (PID) Process: | (2512) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Windows\system32\mspaint.exe |
Value: Paint | |||
| (PID) Process: | (2512) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Windows\system32\NOTEPAD.EXE |
Value: Notepad | |||
| (PID) Process: | (2512) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\PROGRA~1\MICROS~1\Office14\OIS.EXE |
Value: Microsoft Office 2010 | |||
| (PID) Process: | (2512) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Opera\Opera.exe |
Value: Opera Internet Browser | |||
| (PID) Process: | (2512) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Windows Photo Viewer\PhotoViewer.dll |
Value: Windows Photo Viewer | |||
| (PID) Process: | (2512) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\VideoLAN\VLC\vlc.exe |
Value: VLC media player | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2960 | WScript.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@www.lattsat[1].txt | text | |
MD5:CC2AD7A7AF984E3BEF2246C0ACD36184 | SHA256:ECAF7C7104677836FBD06E4CAD8BE60D18E0254412758091FDB9B675DCE8B50E | |||
| 2960 | WScript.exe | C:\Users\admin\AppData\Local\Temp\m4myvtnv1.exe | executable | |
MD5:1765BDB48DFB3C4C41D96E9AB2DA53B5 | SHA256:1DB3047CFD57CF963310D948D9CAF399CFA41807BDF0B3F47373A81831DD9E03 | |||
| 2436 | EQSuC9Rqw8bRmLS1YO.exe | C:\Users\admin\AppData\Local\soundser\soundser.exe | executable | |
MD5:4AEA0E3BFD0BBEA11181A44B1C214D92 | SHA256:28CF2A0DF49A83892AD9F6BEA77619AB8DCF1155E938CEA6309E094703D62DF7 | |||
| 1708 | m4myvtnv1.exe | C:\Users\admin\AppData\Local\soundser\soundser.exe | executable | |
MD5:1765BDB48DFB3C4C41D96E9AB2DA53B5 | SHA256:1DB3047CFD57CF963310D948D9CAF399CFA41807BDF0B3F47373A81831DD9E03 | |||
| 2828 | soundser.exe | C:\Users\admin\AppData\Local\soundser\EQSuC9Rqw8bRmLS1YO.exe | executable | |
MD5:4AEA0E3BFD0BBEA11181A44B1C214D92 | SHA256:28CF2A0DF49A83892AD9F6BEA77619AB8DCF1155E938CEA6309E094703D62DF7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2828 | soundser.exe | POST | — | 86.98.94.57:443 | http://86.98.94.57:443/merge/splash/ringin/ | AE | — | — | suspicious |
3208 | soundser.exe | POST | 200 | 73.31.185.166:80 | http://73.31.185.166/forced/child/ringin/ | US | binary | 705 Kb | malicious |
2960 | WScript.exe | GET | 200 | 210.56.13.190:80 | http://www.lattsat.com/wp-content/j_2W/ | PK | executable | 100 Kb | malicious |
3208 | soundser.exe | POST | 200 | 73.31.185.166:80 | http://73.31.185.166/srvc/ | US | binary | 148 b | malicious |
2828 | soundser.exe | POST | 200 | 78.169.89.21:80 | http://78.169.89.21/between/rtm/ringin/ | TR | binary | 78.0 Kb | malicious |
3208 | soundser.exe | GET | 200 | 198.58.114.91:4143 | http://198.58.114.91:4143/whoami.php | US | text | 13 b | malicious |
3208 | soundser.exe | POST | 200 | 198.58.114.91:4143 | http://198.58.114.91:4143/window/guids/ringin/merge/ | US | binary | 1.83 Kb | malicious |
3208 | soundser.exe | POST | 200 | 198.58.114.91:4143 | http://198.58.114.91:4143/loadan/loadan/ringin/merge/ | US | binary | 1.79 Kb | malicious |
3208 | soundser.exe | POST | 200 | 198.58.114.91:4143 | http://198.58.114.91:4143/usbccid/ | US | binary | 1.79 Kb | malicious |
3208 | soundser.exe | POST | 200 | 198.58.114.91:4143 | http://198.58.114.91:4143/devices/splash/ | US | binary | 2.11 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2960 | WScript.exe | 210.56.13.190:80 | www.lattsat.com | Commission on Science and Technology for | PK | suspicious |
2828 | soundser.exe | 86.98.94.57:443 | — | Emirates Telecommunications Corporation | AE | suspicious |
2828 | soundser.exe | 78.169.89.21:80 | — | Turk Telekom | TR | malicious |
3208 | soundser.exe | 73.31.185.166:80 | — | Comcast Cable Communications, LLC | US | malicious |
3208 | soundser.exe | 198.58.114.91:4143 | — | Linode, LLC | US | malicious |
3208 | soundser.exe | 40.101.46.34:587 | — | Microsoft Corporation | IE | whitelisted |
3208 | soundser.exe | 74.208.5.15:587 | smtp.mail.com | 1&1 Internet SE | US | malicious |
3208 | soundser.exe | 144.76.145.230:25 | mail.graffiti.com.ve | Hetzner Online GmbH | DE | unknown |
3208 | soundser.exe | 64.37.49.155:25 | mail.pacoolservice.com | HostDime.com, Inc. | US | unknown |
3208 | soundser.exe | 72.51.36.133:1025 | sendnow.ph | Peer 1 Network (USA) Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.lattsat.com |
| malicious |
outlook.office365.com |
| whitelisted |
mail.mail.yahoo.com |
| unknown |
mail.gmail.com |
| suspicious |
smtp.mail.com |
| shared |
mail.graffiti.com.ve |
| unknown |
smtpauth.superonline.com |
| unknown |
mail.nikooprecision.com |
| malicious |
smtp.gmail.com |
| malicious |
mail.pacoolservice.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2960 | WScript.exe | Misc activity | SUSPICIOUS [PTsecurity] Cmd.Powershell.Download HTTP UserAgent (Win7) |
2960 | WScript.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2960 | WScript.exe | A Network Trojan was detected | ET CURRENT_EVENTS Likely Evil EXE download from MSXMLHTTP non-exe extension M2 |
2960 | WScript.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
2828 | soundser.exe | A Network Trojan was detected | MALWARE [PTsecurity] Feodo/Emotet |
3208 | soundser.exe | A Network Trojan was detected | MALWARE [PTsecurity] Feodo/Emotet |
3208 | soundser.exe | A Network Trojan was detected | MALWARE [PTsecurity] Feodo/Emotet |
3208 | soundser.exe | A Network Trojan was detected | MALWARE [PTsecurity] Feodo/Emotet |
3208 | soundser.exe | Generic Protocol Command Decode | SURICATA Applayer Detect protocol only one direction |
3208 | soundser.exe | Generic Protocol Command Decode | SURICATA Applayer Detect protocol only one direction |