| File name: | sihost.exe |
| Full analysis: | https://app.any.run/tasks/562420e4-8074-4c20-addf-5d520abee91c |
| Verdict: | Malicious activity |
| Threats: | FormBook is a data stealer that is being distributed as a MaaS. FormBook differs from a lot of competing malware by its extreme ease of use that allows even the unexperienced threat actors to use FormBook virus. |
| Analysis date: | November 23, 2023, 11:03:04 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | 8A7EE9DBD620232871C7CE897FCB14E9 |
| SHA1: | C00368C6344A13BDBCEF92ABD262DCD5D81518E7 |
| SHA256: | 4CAC61484C84732DBE188CAA0A13F8A688299C46A9D689B4B90FC76F299FE8D1 |
| SSDEEP: | 24576:b4K0/0LaX/moYkQwPSeDfgxpY1x+yn9EyWs5Wzhn9BhmhNJqgcI8+eb4:p0/0LaX/moYk3SeDfgxpY1x+c9ERs5W2 |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (82.9) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (7.4) |
| .exe | | | Win32 Executable (generic) (5.1) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:11:21 05:27:39+01:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 48 |
| CodeSize: | 622592 |
| InitializedDataSize: | 24576 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x99da6 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | MC Wizard |
| CompanyName: | MC |
| FileDescription: | Wizarding Tools |
| FileVersion: | 0.0.0.0 |
| InternalName: | rId.exe |
| LegalCopyright: | - |
| LegalTrademarks: | - |
| OriginalFileName: | rId.exe |
| ProductName: | WizardingTools |
| ProductVersion: | 0.0.0.0 |
| AssemblyVersion: | 0.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1388 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2900 | "C:\Users\admin\AppData\Local\Temp\sihost.exe" | C:\Users\admin\AppData\Local\Temp\sihost.exe | — | sihost.exe | |||||||||||
User: admin Company: MC Integrity Level: MEDIUM Description: Wizarding Tools Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 3416 | "C:\Users\admin\AppData\Local\Temp\sihost.exe" | C:\Users\admin\AppData\Local\Temp\sihost.exe | — | explorer.exe | |||||||||||
User: admin Company: MC Integrity Level: MEDIUM Description: Wizarding Tools Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 3432 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3480 | "C:\Windows\System32\where.exe" | C:\Windows\System32\where.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Where - Lists location of files Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3884 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3940 | "C:\Program Files\Mozilla Firefox\Firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | where.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (1388) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0 |
| Operation: | write | Name: | CheckSetting |
Value: 01000000D08C9DDF0115D1118C7A00C04FC297EB01000000F6D6788197A75D498472ACE88906AC8D000000000200000000001066000000010000200000007F0C5AFCF1AE7F71286A81A9B86E67A7BE47980777E154AD953E683E2064784E000000000E8000000002000020000000C547D0854BEA52CCDED7859B79990A863903B335001ED826D40C3D8E323F237F30000000DF0FBC24E15CFF4FE438F74D8486DFB808CBF3EC9160BD0CF16731298F2800053F0DC9D2737FB85ABF81EDB882A089A94000000011BAC043EAAF96F8497DEE93A36C7829C97427DA018BC7750377DAC2CC3CE4D64139784732F789D57202D54D80C3AAC2B4B5EE990B65AEF23416199647916AD4 | |||
| (PID) Process: | (1388) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3432) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A93A65AA-6901-4282-B4F7-B8E5A6C83760}\{94467C9F-6565-4542-816D-AD0B00E6E8C7} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3432) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A93A65AA-6901-4282-B4F7-B8E5A6C83760} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3432) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EC72A986-7FCA-4335-AB4E-8FD31D240EC5}\{94467C9F-6565-4542-816D-AD0B00E6E8C7} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3432) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EC72A986-7FCA-4335-AB4E-8FD31D240EC5} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3432) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{3613793F-F499-475C-8CCA-E02E6560410D} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3416) sihost.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3416) sihost.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3416) sihost.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3480 | where.exe | C:\Users\admin\AppData\Local\Temp\sqlite3.def | text | |
MD5:CD9B704B328573406D319F6E22E043BE | SHA256:8274A340B59D469C27EB238A7984D250287C7820556A9E2693E8F1ECD907936A | |||
| 3480 | where.exe | C:\Users\admin\AppData\Local\Temp\sqlite3.dll | executable | |
MD5:E1B58E0AA1B377A1D0E940660AD1ACE1 | SHA256:1B98C006231D38524E2278A474C49274FE42E0BB1A31BCFDA02E6E32F559B777 | |||
| 3480 | where.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\sqlite-dll-win32-x86-3220000[1].zip | compressed | |
MD5:9EC4D0FE38CB4DE94D578BFD72C8EEBD | SHA256:2402C65692D0A822D7931489D1BBF29FA9BFBF210819C1614DD8D2350E747F2F | |||
| 3480 | where.exe | C:\Users\admin\AppData\Local\Temp\dtgx3x.zip | compressed | |
MD5:9EC4D0FE38CB4DE94D578BFD72C8EEBD | SHA256:2402C65692D0A822D7931489D1BBF29FA9BFBF210819C1614DD8D2350E747F2F | |||
| 3480 | where.exe | C:\Users\admin\AppData\Local\Temp\705929p4 | binary | |
MD5:52E51471E9281235323F633CD0DEA56C | SHA256:147F3137B387FE4FBE3215B7864568404580A799D031009FE9C718F4C2EF87D0 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1388 | explorer.exe | GET | 404 | 34.120.137.41:80 | http://www.talknconvert.com/zqco/?E8-PMH=+y3ZRElHCLe7jmdKMpKJHOZUDd5Y5ZHGGHfUVKPtd2bXz9pNtTUvPUI0E2mMKKDMK40SLr9h4U0bLKie7CWEkew9bu0FTKZh1UY55PY=&O2=72i0zr2HBnLpEd6 | unknown | html | 80.7 Kb | unknown |
3480 | where.exe | GET | 200 | 45.33.6.223:80 | http://www.sqlite.org/2018/sqlite-dll-win32-x86-3220000.zip | unknown | compressed | 438 Kb | unknown |
1388 | explorer.exe | POST | 404 | 198.44.187.121:80 | http://www.zz23xw.top/zqco/ | unknown | html | 146 b | unknown |
1388 | explorer.exe | POST | 404 | 198.44.187.121:80 | http://www.zz23xw.top/zqco/ | unknown | html | 146 b | unknown |
1388 | explorer.exe | POST | 404 | 198.44.187.121:80 | http://www.zz23xw.top/zqco/ | unknown | html | 146 b | unknown |
1388 | explorer.exe | POST | 404 | 198.44.187.121:80 | http://www.zz23xw.top/zqco/ | unknown | html | 146 b | unknown |
1388 | explorer.exe | GET | 404 | 198.44.187.121:80 | http://www.zz23xw.top/zqco/?E8-PMH=VoRUmMaSMr2kGXzG8D6zu1gywvbhw0tvfeSWrzBmFVf4r1pcQgw7LosabWMBXohSSG87M+jYFIXYlgUy6IoePMUY4H5zPfEgPR9WUDg=&O2=72i0zr2HBnLpEd6 | unknown | html | 146 b | unknown |
1388 | explorer.exe | POST | 200 | 199.59.243.225:80 | http://www.oneillspubs.com/zqco/ | unknown | html | 1.07 Kb | unknown |
1388 | explorer.exe | POST | 404 | 198.44.187.121:80 | http://www.zz23xw.top/zqco/ | unknown | html | 146 b | unknown |
1388 | explorer.exe | POST | 404 | 198.44.187.121:80 | http://www.zz23xw.top/zqco/ | unknown | html | 146 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1388 | explorer.exe | 34.120.137.41:80 | www.talknconvert.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
3480 | where.exe | 45.33.6.223:80 | www.sqlite.org | Linode, LLC | US | unknown |
1388 | explorer.exe | 198.44.187.121:80 | www.zz23xw.top | ZEN-ECN | US | unknown |
1388 | explorer.exe | 199.59.243.225:80 | www.oneillspubs.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.talknconvert.com |
| unknown |
www.sqlite.org |
| whitelisted |
www.zz23xw.top |
| unknown |
www.oneillspubs.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
1388 | explorer.exe | Potentially Bad Traffic | ET INFO HTTP Request to a *.top domain |
1388 | explorer.exe | A Network Trojan was detected | STEALER [ANY.RUN] Formbook HTTP header |
1388 | explorer.exe | A Network Trojan was detected | STEALER [ANY.RUN] Formbook HTTP header |
1388 | explorer.exe | A Network Trojan was detected | STEALER [ANY.RUN] Formbook HTTP header |
1388 | explorer.exe | A Network Trojan was detected | STEALER [ANY.RUN] Formbook HTTP header |