Trojan

Trojan:Win32/Emotet.GP (file analysis)

Malware Removal

The Trojan:Win32/Emotet.GP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Emotet.GP virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Access the NetLogon registry key, potentially used for discovery or tampering
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the QakBot malware family
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Clears web history
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Emotet.GP?


File Info:

name: A75B30B93E6EE61F24D4.mlw
path: /opt/CAPEv2/storage/binaries/68b9de2981e3d74fbc83b3e26a45eda5611fd1791362d775e12b6db5f1f5f646
crc32: D125A747
md5: a75b30b93e6ee61f24d42f7283289d57
sha1: ebec7af9d7fed2623ccaa7e635923a96293ba621
sha256: 68b9de2981e3d74fbc83b3e26a45eda5611fd1791362d775e12b6db5f1f5f646
sha512: ed52b6950bae054cdad5133d20806707a4c0ea387d24daef97a7a5f15e63b573c8d0214ee9b639fe33e20e9bede4fdf3e66d878b4e457fc8b774b544d579b87d
ssdeep: 12288:40VcXku/b+cbXrns8XoT2BqcFXo/CDzYW9ozYgSnMGt:zVcXbTjNXoCq2DzY8ozYrMG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EAF49D419801C592C620D671EC5A9DDC2231FEF89F294877D0A3FDDF9EB9B424B8A61C
sha3_384: 6eea808d82bef40444a60a233c31eaa0742e88c5d47f1199ac2927b2787556e2056155c5fde4cff80045ac30a2204f0c
ep_bytes: e880020000e957fdffff8bff558bec8b
timestamp: 2019-03-26 01:47:04

Version Info:

0: [No Data]

Trojan:Win32/Emotet.GP also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qbot.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.Small.SYO
ClamAVWin.Malware.Qbot-6958172-0
FireEyeGeneric.mg.a75b30b93e6ee61f
CAT-QuickHealTrojan.Emotet.X4
ALYacTrojan.Agent.QakBot
MalwarebytesBackdoor.Qbot
ZillyaBackdoor.Qbot.Win32.3
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00549c241 )
AlibabaBackdoor:Win32/Emotet.13efbf65
K7GWTrojan ( 00549c241 )
Cybereasonmalicious.93e6ee
CyrenW32/FakeAlert.FY.gen!Eldorado
SymantecTrojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.GQVG
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Qbot.akbk
BitDefenderTrojan.Agent.Small.SYO
NANO-AntivirusTrojan.Win32.Qbot.fomcab
SUPERAntiSpywareTrojan.Agent/Gen-Emotet
AvastWin32:BotX-gen [Trj]
TencentMalware.Win32.Gencirc.10b2363b
TACHYONBackdoor/W32.Qbot.769536.C
EmsisoftTrojan.Agent.Small.SYO (B)
F-SecureHeuristic.HEUR/AGEN.1318499
DrWebTrojan.Siggen8.20729
VIPRETrojan.Agent.Small.SYO
TrendMicroBackdoor.Win32.QAKBOT.SMC
McAfee-GW-EditionBehavesLike.Win32.Lockbit.bc
Trapminemalicious.high.ml.score
SophosMal/Qbot-R
IkarusTrojan.Crypt
GDataTrojan.Agent.Small.SYO
JiangminTrojan.Shelma.ctt
WebrootW32.Trojan.Emotet
AviraHEUR/AGEN.1318499
Antiy-AVLTrojan[Backdoor]/Win32.Qbot
XcitiumTrojWare.Win32.Shelma.VG@83advv
ArcabitTrojan.Agent.Small.SYO
ZoneAlarmBackdoor.Win32.Qbot.akbk
MicrosoftTrojan:Win32/Emotet.GP
GoogleDetected
AhnLab-V3Trojan/Win32.Kryptik.R260373
Acronissuspicious
McAfeeGenericRXHG-FG!A75B30B93E6E
MAXmalware (ai score=100)
VBA32BScope.Backdoor.Qbot
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallBackdoor.Win32.QAKBOT.SMC
RisingTrojan.Kryptik!8.8 (TFE:5:K2UBheYF75P)
YandexTrojan.GenAsa!6EiMVniTggE
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HAZJ!tr
BitDefenderThetaGen:NN.ZexaF.36196.UCW@aumXvzeG
AVGWin32:BotX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Emotet.GP?

Trojan:Win32/Emotet.GP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment