File name:

Max.exe

Full analysis: https://app.any.run/tasks/b55882a4-3321-44cc-a700-75f47f6baa9e
Verdict: Malicious activity
Threats:

First identified in 2024, Emmenhtal operates by embedding itself within modified legitimate Windows binaries, often using HTA (HTML Application) files to execute malicious scripts. It has been linked to the distribution of malware such as CryptBot and Lumma Stealer. Emmenhtal is typically disseminated through phishing campaigns, including fake video downloads and deceptive email attachments.

Analysis date: August 01, 2025, 02:36:48
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
emmenhtal
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

AE2E35476BEFB9C4DB7B47E60C199959

SHA1:

F4A2EF89D665D1CEA959998488B6EC00D148BFAD

SHA256:

CD67D09FDD1D99CDA1D12D9C04CB78FECE02C182AB55F1EF8B4E42F7BBA0CF0C

SSDEEP:

12288:9aSk5uceHAmrbnhhhhhhXhhhhtR0aSk5uceHAmlMoJ7snQ:Hk5uceHA4bTak5uceHAlQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • mshta.exe (PID: 3736)
    • EMMENHTAL has been detected (YARA)

      • mshta.exe (PID: 3736)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Max.exe (PID: 4648)
    • There is functionality for taking screenshot (YARA)

      • Max.exe (PID: 4648)
  • INFO

    • Reads the computer name

      • Max.exe (PID: 4648)
    • Create files in a temporary directory

      • Max.exe (PID: 4648)
    • Reads Internet Explorer settings

      • mshta.exe (PID: 3736)
    • Checks supported languages

      • Max.exe (PID: 4648)
    • Process checks computer location settings

      • Max.exe (PID: 4648)
    • Checks proxy server information

      • mshta.exe (PID: 3736)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:12:31 00:38:38+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 89600
InitializedDataSize: 111616
UninitializedDataSize: -
EntryPoint: 0x1638f
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.6.0.2712
ProductVersionNumber: 1.6.0.2712
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Djengineer14
FileDescription: A Good Dog he Will protect you at all costs.
FileVersion: 1
InternalName: Max
LegalCopyright: Copyright © 2024-2025 Djengineer14
OriginalFileName: max.exe
PrivateBuild: 2025
ProductName: Max
ProductVersion: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
3736"C:\Windows\SysWOW64\mshta.exe" "C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\Max.hta" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} C:\Windows\SysWOW64\mshta.exe
Max.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft (R) HTML Application host
Exit code:
0
Version:
11.00.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\mshta.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4648"C:\Users\admin\AppData\Local\Temp\Max.exe" C:\Users\admin\AppData\Local\Temp\Max.exeexplorer.exe
User:
admin
Company:
Djengineer14
Integrity Level:
MEDIUM
Description:
A Good Dog he Will protect you at all costs.
Exit code:
0
Version:
1.0
Modules
Images
c:\users\admin\appdata\local\temp\max.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
Total events
5 699
Read events
5 676
Write events
22
Delete events
1

Modification events

(PID) Process:(3736) mshta.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3736) mshta.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3736) mshta.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3736) mshta.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3736) mshta.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3736) mshta.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3736) mshta.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(4648) Max.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hta\OpenWithProgids
Operation:writeName:htafile
Value:
(PID) Process:(3736) mshta.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{E0F158E1-CB04-11D0-BD4E-00A0C911CE86}\Default DirectSound Device
Operation:writeName:FriendlyName
Value:
Default DirectSound Device
(PID) Process:(3736) mshta.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\ActiveMovie\devenum\{E0F158E1-CB04-11D0-BD4E-00A0C911CE86}\Default DirectSound Device
Operation:writeName:CLSID
Value:
{79376820-07D0-11CF-A24D-0020AFD79767}
Executable files
0
Suspicious files
2
Text files
3
Unknown types
3

Dropped files

PID
Process
Filename
Type
3736mshta.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_056B48C93C4964C2E64C0A8958238656binary
MD5:FF122638345ED23AD6D02BD6B360F31E
SHA256:AA7B4AF71DB30EF598A3658F82A73AFB3EE04F32A22B604A4C0FA1FB10AE47C0
3736mshta.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_056B48C93C4964C2E64C0A8958238656der
MD5:978BD8865485D4CE6FC4CC3010052265
SHA256:9DD681A9708DC29D52EC5F0410D34F0DEBFFC652FA91D7E21EBB1752A6A68B5D
4648Max.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\Max.htahtml
MD5:BCC38D97E0C26AD71AD6A55860C4545B
SHA256:C2BA0237D6FDFB658E63AFACCEDD5E74B28AC0CB23C4ABA32969DDF26E6617E1
3736mshta.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187der
MD5:8ED7971D02A2FD8F67B81ACF0B1D370E
SHA256:538E6CD3D79E4D7536AA97608577B5510BFB5EE92B03B5B2A988EE272A1262F0
3736mshta.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187binary
MD5:58A12D7DC64D95F7AB47C2D59C5DD514
SHA256:18341D81EDFDD5F7F30F157756B14A8A6E6AF3B677E8C84090F43DA078F26E8E
3736mshta.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\OIP[1].jpgimage
MD5:2C7312D86196E76729DADB62C83A87C2
SHA256:E1F01C12643F1301F58BEA0EDD8ED8DB1D8CCE94746C537C921C272C3E26BCDE
3736mshta.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\TYPE[1].wavwav
MD5:0893E9F7D37D7E221BDAA7CB6D430482
SHA256:DA8BA1D3D9F8EC41FFC208B58BCF7FA67E2AAE852C96369052F398F89965AE2A
3736mshta.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\istockphoto-1250110470-612x612[1].jpgimage
MD5:F74CF32130F694F3165D9B7A26CC1727
SHA256:BD44BAA49CF60DC39778C595758CA0AB03E0A21C893679E23C7721A1A3734339
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
28
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3736
mshta.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
US
binary
471 b
whitelisted
1268
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
3948
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
3736
mshta.exe
GET
200
18.245.38.41:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D
US
binary
1.40 Kb
whitelisted
1808
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
420 b
whitelisted
1808
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
408 b
whitelisted
1268
svchost.exe
GET
200
23.3.109.244:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
3736
mshta.exe
GET
200
129.59.230.37:80
http://www.psy.vanderbilt.edu/faculty/Zalddh/roulette/NOVEL/TYPE.WAV
US
binary
4.51 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
52.167.17.97:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1268
svchost.exe
52.167.17.97:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5884
RUXIMICS.exe
52.167.17.97:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3736
mshta.exe
108.138.26.129:443
media.istockphoto.com
AMAZON-02
US
whitelisted
3736
mshta.exe
150.171.27.10:443
tse3.mm.bing.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3736
mshta.exe
18.245.38.41:80
ocsp.rootca1.amazontrust.com
US
whitelisted
3736
mshta.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
4
System
192.168.100.255:138
whitelisted
3948
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 52.167.17.97
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 172.217.18.14
whitelisted
media.istockphoto.com
  • 108.138.26.129
  • 108.138.26.67
  • 108.138.26.100
  • 108.138.26.85
whitelisted
tse3.mm.bing.net
  • 150.171.27.10
  • 150.171.28.10
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.245.38.41
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
login.live.com
  • 20.190.160.130
  • 40.126.32.140
  • 20.190.160.20
  • 20.190.160.17
  • 20.190.160.64
  • 20.190.160.67
  • 40.126.32.74
  • 20.190.160.132
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 23.3.109.244
  • 23.35.229.160
whitelisted
www.psy.vanderbilt.edu
  • 129.59.230.37
unknown

Threats

No threats detected
No debug info