Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.
MALICIOUS | SUSPICIOUS | INFO |
---|---|---|
Emotet process was detected
|
Connects to unusual port
|
Reads Microsoft Office registry keys
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0000C91A | 0x0000D000 | IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ | 6.39672 |
.rdata | 0x0000E000 | 0x00003C62 | 0x00004000 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 5.66194 |
.data | 0x00012000 | 0x00005A80 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 2.66732 |
.rsrc | 0x00018000 | 0x000214A4 | 0x00022000 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 6.52964 |
No exports.
Click at the process to see the details.
Image |
---|
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\shlwapi.dll |
c:\users\admin\appdata\local\temp\iaakiij.exe |
c:\windows\system32\apphelp.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\userenv.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\winmm.dll |
c:\systemroot\system32\ntdll.dll |
Image |
---|
c:\users\admin\appdata\local\temp\iaakiij.exe |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\winmm.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\userenv.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\apphelp.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\crypt32.dll |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\shell32.dll |
Image |
---|
c:\windows\system32\advapi32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\setupapi.dll |
c:\windows\system32\cfgmgr32.dll |
c:\windows\system32\devobj.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\propsys.dll |
c:\windows\system32\ntmarta.dll |
c:\windows\system32\wldap32.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\apphelp.dll |
c:\users\admin\appdata\local\easywindow\easyw |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\rpcrtremote.dll |
c:\users\admin\appdata\local\temp\iaakiij.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
Image |
---|
c:\users\admin\appdata\local\easywindow\easywindow.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\winmm.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\userenv.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\apphelp.dll |
Image |
---|
c:\users\admin\appdata\local\easywindow\easywindow.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\winmm.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\userenv.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\apphelp.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\rpcrt4.dll |
Image |
---|
c:\users\admin\appdata\local\easywindow\easywindow.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\userenv.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\wtsapi32.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\iertutil.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\wldap32.dll |
c:\windows\system32\ntmarta.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\normaliz.dll |
c:\windows\system32\rasapi32.dll |
c:\windows\system32\rasman.dll |
c:\windows\system32\rtutils.dll |
c:\windows\system32\sensapi.dll |
c:\windows\system32\nlaapi.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\wshqos.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\system32\wship6.dll |
c:\windows\system32\mpr.dll |
c:\windows\system32\netapi32.dll |
c:\windows\system32\netutils.dll |
c:\windows\system32\srvcli.dll |
c:\windows\system32\wkscli.dll |
c:\windows\system32\samcli.dll |
c:\windows\system32\drprov.dll |
c:\windows\system32\winsta.dll |
c:\windows\system32\ntlanman.dll |
c:\windows\system32\davclnt.dll |
c:\windows\system32\davhlpr.dll |
c:\windows\system32\cscapi.dll |
c:\windows\system32\browcli.dll |
c:\windows\system32\apphelp.dll |
Image |
---|
c:\users\admin\appdata\local\easywindow\easywindow.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\ole32.dll |
c:\progra~1\micros~1\office14\olmapi32.dll |
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll |
c:\windows\system32\version.dll |
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\cryptbase.dll |
c:\program files\common files\microsoft shared\office14\mso.dll |
c:\windows\system32\msi.dll |
c:\program files\common files\microsoft shared\office14\cultures\office.odf |
c:\progra~1\micros~1\office14\1033\mapir.dll |
c:\windows\system32\powrprof.dll |
c:\windows\system32\setupapi.dll |
c:\windows\system32\cfgmgr32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\devobj.dll |
c:\windows\system32\ntmarta.dll |
c:\windows\system32\wldap32.dll |
c:\program files\common files\microsoft shared\office14\riched20.dll |
c:\progra~1\micros~1\office14\contab32.dll |
c:\progra~1\micros~1\office14\omsxp32.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\iertutil.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\msasn1.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll |
c:\progra~1\micros~1\office14\mspst32.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\rpcrtremote.dll |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3252 | easywindow.exe | POST | 200 | 62.75.171.248:7080 | http://62.75.171.248:7080/devices/ | FR |
text
binary
|
|
malicious |
3252 | easywindow.exe | POST | 200 | 62.75.171.248:7080 | http://62.75.171.248:7080/prov/guids/ | FR |
text
binary
|
|
malicious |
No debug info.