File name:

sihost.exe

Full analysis: https://app.any.run/tasks/562420e4-8074-4c20-addf-5d520abee91c
Verdict: Malicious activity
Threats:

FormBook is a data stealer that is being distributed as a MaaS. FormBook differs from a lot of competing malware by its extreme ease of use that allows even the unexperienced threat actors to use FormBook virus.

Analysis date: November 23, 2023, 11:03:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
formbook
xloader
stealer
spyware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

8A7EE9DBD620232871C7CE897FCB14E9

SHA1:

C00368C6344A13BDBCEF92ABD262DCD5D81518E7

SHA256:

4CAC61484C84732DBE188CAA0A13F8A688299C46A9D689B4B90FC76F299FE8D1

SSDEEP:

24576:b4K0/0LaX/moYkQwPSeDfgxpY1x+yn9EyWs5Wzhn9BhmhNJqgcI8+eb4:p0/0LaX/moYk3SeDfgxpY1x+c9ERs5W2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • FORMBOOK has been detected (YARA)

      • where.exe (PID: 3480)
    • Steals credentials

      • where.exe (PID: 3480)
    • FORMBOOK has been detected (SURICATA)

      • explorer.exe (PID: 1388)
    • Actions looks like stealing of personal data

      • where.exe (PID: 3480)
  • SUSPICIOUS

    • Reads the Internet Settings

      • sihost.exe (PID: 3416)
      • where.exe (PID: 3480)
    • Application launched itself

      • sihost.exe (PID: 3416)
    • Loads DLL from Mozilla Firefox

      • where.exe (PID: 3480)
    • Process drops SQLite DLL files

      • where.exe (PID: 3480)
  • INFO

    • Checks supported languages

      • wmpnscfg.exe (PID: 3432)
      • sihost.exe (PID: 3416)
      • sihost.exe (PID: 2900)
      • wmpnscfg.exe (PID: 3884)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3432)
      • sihost.exe (PID: 3416)
      • wmpnscfg.exe (PID: 3884)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3432)
      • where.exe (PID: 3480)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3432)
      • sihost.exe (PID: 3416)
      • wmpnscfg.exe (PID: 3884)
    • Checks proxy server information

      • where.exe (PID: 3480)
    • Create files in a temporary directory

      • where.exe (PID: 3480)
    • Creates files or folders in the user directory

      • where.exe (PID: 3480)
    • Drops the executable file immediately after the start

      • where.exe (PID: 3480)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (82.9)
.dll | Win32 Dynamic Link Library (generic) (7.4)
.exe | Win32 Executable (generic) (5.1)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:11:21 05:27:39+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 622592
InitializedDataSize: 24576
UninitializedDataSize: -
EntryPoint: 0x99da6
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: MC Wizard
CompanyName: MC
FileDescription: Wizarding Tools
FileVersion: 0.0.0.0
InternalName: rId.exe
LegalCopyright: -
LegalTrademarks: -
OriginalFileName: rId.exe
ProductName: WizardingTools
ProductVersion: 0.0.0.0
AssemblyVersion: 0.0.0.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
7
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sihost.exe no specs wmpnscfg.exe no specs sihost.exe no specs #FORMBOOK where.exe #FORMBOOK explorer.exe wmpnscfg.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1388C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2900"C:\Users\admin\AppData\Local\Temp\sihost.exe"C:\Users\admin\AppData\Local\Temp\sihost.exesihost.exe
User:
admin
Company:
MC
Integrity Level:
MEDIUM
Description:
Wizarding Tools
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\sihost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3416"C:\Users\admin\AppData\Local\Temp\sihost.exe" C:\Users\admin\AppData\Local\Temp\sihost.exeexplorer.exe
User:
admin
Company:
MC
Integrity Level:
MEDIUM
Description:
Wizarding Tools
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\sihost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3432"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3480"C:\Windows\System32\where.exe"C:\Windows\System32\where.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Where - Lists location of files
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\where.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
3884"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3940"C:\Program Files\Mozilla Firefox\Firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exewhere.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
1 765
Read events
1 727
Write events
30
Delete events
8

Modification events

(PID) Process:(1388) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000F6D6788197A75D498472ACE88906AC8D000000000200000000001066000000010000200000007F0C5AFCF1AE7F71286A81A9B86E67A7BE47980777E154AD953E683E2064784E000000000E8000000002000020000000C547D0854BEA52CCDED7859B79990A863903B335001ED826D40C3D8E323F237F30000000DF0FBC24E15CFF4FE438F74D8486DFB808CBF3EC9160BD0CF16731298F2800053F0DC9D2737FB85ABF81EDB882A089A94000000011BAC043EAAF96F8497DEE93A36C7829C97427DA018BC7750377DAC2CC3CE4D64139784732F789D57202D54D80C3AAC2B4B5EE990B65AEF23416199647916AD4
(PID) Process:(1388) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3432) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A93A65AA-6901-4282-B4F7-B8E5A6C83760}\{94467C9F-6565-4542-816D-AD0B00E6E8C7}
Operation:delete keyName:(default)
Value:
(PID) Process:(3432) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A93A65AA-6901-4282-B4F7-B8E5A6C83760}
Operation:delete keyName:(default)
Value:
(PID) Process:(3432) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EC72A986-7FCA-4335-AB4E-8FD31D240EC5}\{94467C9F-6565-4542-816D-AD0B00E6E8C7}
Operation:delete keyName:(default)
Value:
(PID) Process:(3432) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EC72A986-7FCA-4335-AB4E-8FD31D240EC5}
Operation:delete keyName:(default)
Value:
(PID) Process:(3432) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{3613793F-F499-475C-8CCA-E02E6560410D}
Operation:delete keyName:(default)
Value:
(PID) Process:(3416) sihost.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3416) sihost.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3416) sihost.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
1
Suspicious files
3
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3480where.exeC:\Users\admin\AppData\Local\Temp\sqlite3.deftext
MD5:CD9B704B328573406D319F6E22E043BE
SHA256:8274A340B59D469C27EB238A7984D250287C7820556A9E2693E8F1ECD907936A
3480where.exeC:\Users\admin\AppData\Local\Temp\sqlite3.dllexecutable
MD5:E1B58E0AA1B377A1D0E940660AD1ACE1
SHA256:1B98C006231D38524E2278A474C49274FE42E0BB1A31BCFDA02E6E32F559B777
3480where.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\sqlite-dll-win32-x86-3220000[1].zipcompressed
MD5:9EC4D0FE38CB4DE94D578BFD72C8EEBD
SHA256:2402C65692D0A822D7931489D1BBF29FA9BFBF210819C1614DD8D2350E747F2F
3480where.exeC:\Users\admin\AppData\Local\Temp\dtgx3x.zipcompressed
MD5:9EC4D0FE38CB4DE94D578BFD72C8EEBD
SHA256:2402C65692D0A822D7931489D1BBF29FA9BFBF210819C1614DD8D2350E747F2F
3480where.exeC:\Users\admin\AppData\Local\Temp\705929p4binary
MD5:52E51471E9281235323F633CD0DEA56C
SHA256:147F3137B387FE4FBE3215B7864568404580A799D031009FE9C718F4C2EF87D0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
16
DNS requests
5
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1388
explorer.exe
GET
404
34.120.137.41:80
http://www.talknconvert.com/zqco/?E8-PMH=+y3ZRElHCLe7jmdKMpKJHOZUDd5Y5ZHGGHfUVKPtd2bXz9pNtTUvPUI0E2mMKKDMK40SLr9h4U0bLKie7CWEkew9bu0FTKZh1UY55PY=&O2=72i0zr2HBnLpEd6
unknown
html
80.7 Kb
unknown
3480
where.exe
GET
200
45.33.6.223:80
http://www.sqlite.org/2018/sqlite-dll-win32-x86-3220000.zip
unknown
compressed
438 Kb
unknown
1388
explorer.exe
POST
404
198.44.187.121:80
http://www.zz23xw.top/zqco/
unknown
html
146 b
unknown
1388
explorer.exe
POST
404
198.44.187.121:80
http://www.zz23xw.top/zqco/
unknown
html
146 b
unknown
1388
explorer.exe
POST
404
198.44.187.121:80
http://www.zz23xw.top/zqco/
unknown
html
146 b
unknown
1388
explorer.exe
POST
404
198.44.187.121:80
http://www.zz23xw.top/zqco/
unknown
html
146 b
unknown
1388
explorer.exe
GET
404
198.44.187.121:80
http://www.zz23xw.top/zqco/?E8-PMH=VoRUmMaSMr2kGXzG8D6zu1gywvbhw0tvfeSWrzBmFVf4r1pcQgw7LosabWMBXohSSG87M+jYFIXYlgUy6IoePMUY4H5zPfEgPR9WUDg=&O2=72i0zr2HBnLpEd6
unknown
html
146 b
unknown
1388
explorer.exe
POST
200
199.59.243.225:80
http://www.oneillspubs.com/zqco/
unknown
html
1.07 Kb
unknown
1388
explorer.exe
POST
404
198.44.187.121:80
http://www.zz23xw.top/zqco/
unknown
html
146 b
unknown
1388
explorer.exe
POST
404
198.44.187.121:80
http://www.zz23xw.top/zqco/
unknown
html
146 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1388
explorer.exe
34.120.137.41:80
www.talknconvert.com
GOOGLE-CLOUD-PLATFORM
US
unknown
3480
where.exe
45.33.6.223:80
www.sqlite.org
Linode, LLC
US
unknown
1388
explorer.exe
198.44.187.121:80
www.zz23xw.top
ZEN-ECN
US
unknown
1388
explorer.exe
199.59.243.225:80
www.oneillspubs.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
www.talknconvert.com
  • 34.120.137.41
unknown
www.sqlite.org
  • 45.33.6.223
whitelisted
www.zz23xw.top
  • 198.44.187.121
unknown
www.oneillspubs.com
  • 199.59.243.225
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
1388
explorer.exe
Potentially Bad Traffic
ET INFO HTTP Request to a *.top domain
1388
explorer.exe
A Network Trojan was detected
STEALER [ANY.RUN] Formbook HTTP header
1388
explorer.exe
A Network Trojan was detected
STEALER [ANY.RUN] Formbook HTTP header
1388
explorer.exe
A Network Trojan was detected
STEALER [ANY.RUN] Formbook HTTP header
1388
explorer.exe
A Network Trojan was detected
STEALER [ANY.RUN] Formbook HTTP header
No debug info