File name:

12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91

Full analysis: https://app.any.run/tasks/bd587a4f-a526-44b2-86ff-1b97b7cc2ab8
Verdict: Malicious activity
Threats:

FormBook is a data stealer that is being distributed as a MaaS. FormBook differs from a lot of competing malware by its extreme ease of use that allows even the unexperienced threat actors to use FormBook virus.

Analysis date: May 10, 2025, 02:07:20
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
formbook
xloader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

45F9F490B7257B98C3EE660D4E3C13CD

SHA1:

30807CD475D53989FF93C90279F7D5039499A5E0

SHA256:

12D18151689F567858B9B70740DD5EA1EF379C5BEE30384DB4241563A5FD6E91

SSDEEP:

24576:+cwghQBwPn4Akk7xXKpGtJpadwm75aHosPDXXdPw8zA8E40Dt4BQE8:+cwghQBwPn4Akk7xXKpGtJsdwmlaHos/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • FORMBOOK has been detected (YARA)

      • 12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe (PID: 4212)
  • SUSPICIOUS

    • Executes application which crashes

      • 12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe (PID: 4212)
    • Application launched itself

      • 12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe (PID: 496)
  • INFO

    • Checks supported languages

      • 12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe (PID: 496)
    • Reads the machine GUID from the registry

      • 12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe (PID: 496)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 6676)
    • Reads the software policy settings

      • slui.exe (PID: 3268)
    • Reads the computer name

      • 12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe (PID: 496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:04:28 02:40:00+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 801280
InitializedDataSize: 2048
UninitializedDataSize: -
EntryPoint: 0xc5802
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: Change Tracking
FileVersion: 1.0.0.0
InternalName: TYDi.exe
LegalCopyright: Copyright © Microsoft Corporation. All rights reserved.
LegalTrademarks: -
OriginalFileName: TYDi.exe
ProductName: Change Tracking
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe no specs sppextcomobj.exe no specs slui.exe #FORMBOOK 12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe werfault.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
496"C:\Users\admin\AppData\Local\Temp\12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe" C:\Users\admin\AppData\Local\Temp\12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Change Tracking
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
3268"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4212"C:\Users\admin\AppData\Local\Temp\12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe"C:\Users\admin\AppData\Local\Temp\12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe
12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Change Tracking
Exit code:
3221225477
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5508C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6388C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6676C:\WINDOWS\SysWOW64\WerFault.exe -u -p 4212 -s 228C:\Windows\SysWOW64\WerFault.exe12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
Total events
2 306
Read events
2 306
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
3
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
6676WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_12d18151689f5678_5d38571b7c9c8a43757ec5f6712825bb9c89de92_6a53059e_98424883-369c-4de6-ad36-c86da8f04c1d\Report.wer
MD5:
SHA256:
6676WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER9A79.tmp.WERInternalMetadata.xmlbinary
MD5:15B26107DAFCD07A26F24C0E532E9900
SHA256:89BA975FA110E3D62E169883ABD6B48830AD6802DD2095903F6B0C4BEE95AE11
6676WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER9AA9.tmp.xmlxml
MD5:C9B613112B392AE16896E32E46916F44
SHA256:E836A11506ABE7D785089FEB5422C25961FB69269521247BE5670E6A1C115331
6676WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER9A39.tmp.dmpbinary
MD5:FD4E514257DDB64D96DDDCDBC3E861ED
SHA256:85DFD26C6B0B6BB47E3FCF2D6BEE7BA0BFC3687B270B0DDD336903382871E470
6676WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\12d18151689f567858b9b70740dd5ea1ef379c5bee30384db4241563a5fd6e91.exe.4212.dmpbinary
MD5:4ADE9B98C3CD5F06319B39C31DBD59D7
SHA256:7567FEEAB827D8CA9102F769934BF321BB49E60DBB955BF49F4571136A2E7F80
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
24
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.4:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2692
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2692
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2040
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
23.216.77.4:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.159.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.216.77.4
  • 23.216.77.21
  • 23.216.77.42
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.185.142
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.128
  • 20.190.159.68
  • 20.190.159.2
  • 40.126.31.69
  • 40.126.31.131
  • 40.126.31.129
  • 20.190.159.129
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
fd.api.iris.microsoft.com
  • 20.103.156.88
whitelisted

Threats

No threats detected
No debug info