Malware Family Analysis • Windows

Deconstructing Emotet: Manual Memory Unpacking and Hook Analysis

Unpack a packed Emotet loader in x64dbg by bypassing anti-debugging checks and dumping the decrypted core binary directly from process memory.

Executive Summary

Analysis Overview

The sample is a 384 KB Emotet loader (SHA-256: b1cad1540ecb290088252635f8e130022eed7486eb128c0ca3d676945d60a9fc) compiled with Visual Studio 2005. It uses a packer to obfuscate its core logic and incorporates anti-debugging (IsDebuggerPresent) and GUI-based anti-sandbox techniques (USER32/GDI32 imports).

Persistence

Upon detonation, the malware replicates itself to C:\Windows\SysWOW64\rebrandcmp.exe. The persistent file remains identical in hash to the original packed loader.

Core Extraction

Dynamic analysis via x32dbg and monitoring of VirtualAlloc enabled the extraction of the core payload. The unpacked binary is a 62.69 KB executable (SHA-256: 96488477ed1702984c1fa3f56873e9aac4efb871f97a03eea50233b13080c2f0) compiled with Visual Studio 2013.

Technical Indicators

▪Original Entry Point (OEP): 0x0000CD97
▪Payload Entropy: High entropy in .text (6.75) and .data (7.162).
▪Payload Expansion: The .data section expands from 4 KB (raw) to 16 KB (virtual), indicating encrypted configuration buffers.

Sample Metadata

PE Sections

Feature.text (Section 0).rdata (Section 1).data (Section 2).idata (Section 3).rsrc (Section 4)
Entropy5.7405.3373.1124.6780.725
File Ratio60.42 %34.38 %2.08 %1.04 %1.04 %
Raw Address0x000010000x0003B0000x0005C0000x0005E0000x0005F000
Raw Size237,568 bytes135,168 bytes8,192 bytes4,096 bytes4,096 bytes
Virtual Address0x000010000x0003B0000x0005C0000x000610000x00062000
Virtual Size236,815 bytes132,766 bytes16,432 bytes4,044 bytes590 bytes
Characteristics0x600000200x400000400xC00000400xC00000400x40000040
PermissionsRead / ExecuteReadRead / WriteRead / WriteRead

Import Table

CapabilityAssociated Imports (Summary)Source DLL
Memory ManagementVirtualAlloc, VirtualFree, HeapAlloc, HeapFree, HeapReAlloc, HeapCreate, HeapDestroyKERNEL32.dll
Process/Thread ControlGetCurrentProcess, TerminateProcess, ExitProcess, GetCurrentThreadId, Sleep, TlsAlloc/Free, RtlUnwindKERNEL32.dll
Anti-AnalysisIsDebuggerPresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, QueryPerformanceCounter, GetTickCountKERNEL32.dll
File / I/O OperationsCreateFileA, ReadFile, WriteFile, CloseHandle, SetFilePointer, FlushFileBuffers, GetStdHandle, SetStdHandleKERNEL32.dll
Dynamic LoadingGetProcAddress, LoadLibraryA, FreeLibrary, GetModuleHandleA, GetModuleFileNameAKERNEL32.dll
GUI & User InteractionCreateWindowExA, RegisterClassExA, ShowWindow, UpdateWindow, GetMessageA, DispatchMessageA, DefWindowProcAUSER32.dll
Graphics RenderingBitBlt, CreateCompatibleDC, SelectObject, DeleteDC, GetObjectA, DeleteObject, GetStockObjectGDI32.dll
Localization/StringsGetLocaleInfoA/W, GetCPInfo, WideCharToMultiByte, MultiByteToWideChar, GetStringTypeA/W, LCMapStringA/WKERNEL32.dll
System Info/EnvGetVersionExA, GetCommandLineA, GetEnvironmentStrings, SetEnvironmentVariableA, GetTimeZoneInformationKERNEL32.dll

Description

This is a 32-bit Win32 GUI executable (384 KB) identified as an Emotet loader, compiled via Visual Studio 2005 with an entry point at 0x0000E022. Key technical indicators include:

▪Memory & Payload: Large disparity in the .data section's virtual vs. raw size and high entropy in .text, suggesting memory-resident payload decompression.
▪Capabilities: Imports confirm memory manipulation (VirtualAlloc), anti-analysis (IsDebuggerPresent), and dynamic loading (LoadLibraryA).
▪Evasion: Extensive USER32/GDI32 imports indicate GUI-based anti-sandbox techniques.
▪Metadata: References an original filename Emetim.exe and debug path Emetim.pdb, with 2019 timestamps.

Detonation

Upon detonation, the malware initiates a persistence routine by replicating its own binary. It copies itself to the system directory at C:\Windows\SysWOW64\rebrandcmp.exe. The file is renamed to blend in with legitimate system components. Comparison of the SHA-256 hashes confirms that the persistence file is an identical copy of the original packed loader.

Screenshot 2026-04-25 at 4.21.43 AM.png
Figure: Screenshot 2026-04-25 at 4.21.43 AM.png Click to zoom ↗
POWERSHELL
c:\Windows\SysWOW64
λ md5sum.exe rebrandcmp.exe
f3f48c57c38bff2ddd220f20569e1ee6 *rebrandcmp.exe
PhaseActivityDetails
PersistenceFile System ReplicationThe sample copies itself to a system directory to ensure execution after reboot.
Source Pathsample-emotet.exeOriginal execution path.
Target PathC:\Windows\SysWOW64\rebrandcmp.exe32-bit System directory (Masquerading).
File IntegrityIdentical HashVerified via MD5; no changes made to the binary on disk.

Payload Unpacking (x32dbg)

System Breakpoint

You can see the top module is set to sample-emotet.exe beside it Entrypoint .

Screenshot 2026-04-25 at 5.14.14 PM.png
Figure: Screenshot 2026-04-25 at 5.14.14 PM.png Click to zoom ↗

One of the common techniques is to set a breakpoint on VirtualAlloc.

Now in x32dbg ctrl + g enter VirtualAlloc

Screenshot 2026-04-25 at 5.22.00 PM.png
Figure: Screenshot 2026-04-25 at 5.22.00 PM.png Click to zoom ↗

We can see at the top it’s set to Module Kernel32.dll, We are at the start of VirtualAlloc.

Screenshot 2026-04-25 at 5.23.44 PM.png
Figure: Screenshot 2026-04-25 at 5.23.44 PM.png Click to zoom ↗

The Return Address Strategy

When VirtualAlloc is called, the OS hasn't actually given the malware the memory address yet. You need to see where that memory lands.

Set Breakpoint. then run it.

Screenshot 2026-04-25 at 5.28.43 PM.png
Figure: Screenshot 2026-04-25 at 5.28.43 PM.png Click to zoom ↗

Break point hit, now execute till return.

Screenshot 2026-04-25 at 5.29.04 PM.png
Figure: Screenshot 2026-04-25 at 5.29.04 PM.png Click to zoom ↗

Reached return address

Screenshot 2026-04-25 at 5.31.31 PM.png
Figure: Screenshot 2026-04-25 at 5.31.31 PM.png Click to zoom ↗

Now step over press: F8

We can see a call to ebp . That’s where VirtualAlloc been stored.

Screenshot 2026-04-25 at 5.45.46 PM.png
Figure: Screenshot 2026-04-25 at 5.45.46 PM.png Click to zoom ↗

Follow in Dump

follow the argument [edi+54] .

Screenshot 2026-04-25 at 5.47.22 PM.png
Figure: Screenshot 2026-04-25 at 5.47.22 PM.png Click to zoom ↗

In the memory dump scroll down a bit look for mz header.

Screenshot 2026-04-25 at 5.53.48 PM.png
Figure: Screenshot 2026-04-25 at 5.53.48 PM.png Click to zoom ↗

So we found a executable here which could potentially be our unpacked code.

Follow in Memory Map

Right click in the memory map space then follow in memory map.

Screenshot 2026-04-25 at 5.57.26 PM.png
Figure: Screenshot 2026-04-25 at 5.57.26 PM.png Click to zoom ↗

Inspecting the Protection column in the Memory Map tab is one of the most reliable ways to narrow down where the "real" malware is hiding.

Screenshot 2026-04-25 at 6.01.03 PM.png
Figure: Screenshot 2026-04-25 at 6.01.03 PM.png Click to zoom ↗

Right click on the memory address then Dump Memory to File.

Screenshot 2026-04-25 at 6.03.18 PM.png
Figure: Screenshot 2026-04-25 at 6.03.18 PM.png Click to zoom ↗

Save it

Screenshot 2026-04-25 at 6.03.57 PM.png
Figure: Screenshot 2026-04-25 at 6.03.57 PM.png Click to zoom ↗

Hxd

Opening the dumped file in hxd.

We don’t actually have a clean executable, there’s bunch of junk code.

Screenshot 2026-04-25 at 6.06.30 PM.png
Figure: Screenshot 2026-04-25 at 6.06.30 PM.png Click to zoom ↗

Search for mz

Screenshot 2026-04-25 at 6.19.26 PM.png
Figure: Screenshot 2026-04-25 at 6.19.26 PM.png Click to zoom ↗

Select the above junk code and delete it. save it for clean PE file.

Screenshot 2026-04-25 at 6.21.03 PM.png
Figure: Screenshot 2026-04-25 at 6.21.03 PM.png Click to zoom ↗

Static Analysis

Now we will load the dumped bin file in PE studio.

Extracted Payload: Basic Properties

Extracted Payload: Section Analysis

Feature.text.rdata.data.CRT.reloc
Entropy6.7504.2057.1620.0616.354
File Ratio82.15 %4.79 %6.38 %0.80 %1.60 %
Raw Address0x000004000x0000D2000x0000DE000x0000EE000x0000F000
Raw Size52,736 bytes3,072 bytes4,096 bytes512 bytes1,024 bytes
Virtual Address0x000010000x0000E0000x0000F0000x000140000x00015000
Virtual Size52,680 bytes2,862 bytes16,432 bytes4 bytes1,012 bytes
Characteristics0x600000200x400000400xC00000400x400000400x42000040
PermissionsRead/ExecuteReadRead/WriteReadRead/Discard

Imports

KERNEL32.dll

▪IsProcessorFeaturePresent
Copied