| File name: | 2025-08-01_b88cfbf4ec0201b8c8a6b3af4daf963f_elex_mafia_stealc_tofsee.exe |
| Full analysis: | https://app.any.run/tasks/388b3b3d-78f4-4d6b-ba7b-9ccb24d6d207 |
| Verdict: | Malicious activity |
| Analysis date: | August 01, 2025, 02:51:24 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | B88CFBF4EC0201B8C8A6B3AF4DAF963F |
| SHA1: | 0D1D5322EE6F974F0CA16E1D1CADF90E82BE8809 |
| SHA256: | 738E8687A184D7C9C36B1CE4A57C09118B2FDDABF7C5F9CBC1504A8E30BD8F32 |
| SSDEEP: | 24576:wsYXjV7IC9xIVlZ4BnE9ICcNFjvem6USK+P7JmX1Nyz:wsYXjVEC9iVlZ4BnE9ICcNRvem6USK+v |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2003:11:11 14:39:16+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 140288 |
| InitializedDataSize: | 356352 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x113b6 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 12.0.4518.1014 |
| ProductVersionNumber: | 12.0.4518.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Microsoft Office Word |
| FileVersion: | 12.0.4518.1014 |
| InternalName: | WinWord |
| LegalCopyright: | © 2006 Microsoft Corporation. All rights reserved. |
| LegalTrademarks1: | Microsoft® is a registered trademark of Microsoft Corporation. |
| LegalTrademarks2: | Windows® is a registered trademark of Microsoft Corporation. |
| OriginalFileName: | WinWord.exe |
| ProductName: | 2007 Microsoft Office system |
| ProductVersion: | 12.0.4518.1014 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 32 | "C:\Users\admin\AppData\Local\Temp\2F72.tmp" | C:\Users\admin\AppData\Local\Temp\2F72.tmp | 2F24.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 32 | "C:\Users\admin\AppData\Local\Temp\5FD9.tmp" | C:\Users\admin\AppData\Local\Temp\5FD9.tmp | — | 5F7B.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 188 | "C:\Users\admin\AppData\Local\Temp\4646.tmp" | C:\Users\admin\AppData\Local\Temp\4646.tmp | 45D9.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 188 | "C:\Users\admin\AppData\Local\Temp\574E.tmp" | C:\Users\admin\AppData\Local\Temp\574E.tmp | — | 56F0.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 188 | "C:\Users\admin\AppData\Local\Temp\C17.tmp" | C:\Users\admin\AppData\Local\Temp\C17.tmp | — | BA9.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 188 | "C:\Users\admin\AppData\Local\Temp\21E1.tmp" | C:\Users\admin\AppData\Local\Temp\21E1.tmp | — | 2183.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 236 | "C:\Users\admin\AppData\Local\Temp\2AFE.tmp" | C:\Users\admin\AppData\Local\Temp\2AFE.tmp | 2AA0.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 236 | "C:\Users\admin\AppData\Local\Temp\49E0.tmp" | C:\Users\admin\AppData\Local\Temp\49E0.tmp | 4982.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 236 | "C:\Users\admin\AppData\Local\Temp\BFBC.tmp" | C:\Users\admin\AppData\Local\Temp\BFBC.tmp | — | BF4F.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 236 | "C:\Users\admin\AppData\Local\Temp\FFF.tmp" | C:\Users\admin\AppData\Local\Temp\FFF.tmp | — | F91.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 888 | 2025-08-01_b88cfbf4ec0201b8c8a6b3af4daf963f_elex_mafia_stealc_tofsee.exe | C:\Users\admin\AppData\Local\Temp\DC90.tmp | executable | |
MD5:AD5D48116B9C8696D892750B5BFE9FA1 | SHA256:F7AA38A82E34BA320A7E915CA4365AE0865FEF4017987393DE29894975388154 | |||
| 3000 | DD4B.tmp | C:\Users\admin\AppData\Local\Temp\DDA9.tmp | executable | |
MD5:215A3BF541C1E14A8082001A842FD85E | SHA256:FD44DE3930E3D6B01FFB8C1793D11789DC88CAA591965E00598E6F6607836E08 | |||
| 2680 | DC90.tmp | C:\Users\admin\AppData\Local\Temp\DCED.tmp | executable | |
MD5:0DD735D34D010A538E8AED4FCA7287C8 | SHA256:7A67DE15C7DF371191CA67ACC7A0539871EF817C8341FC9DA47E8D16CB8D4244 | |||
| 1232 | DE07.tmp | C:\Users\admin\AppData\Local\Temp\DE64.tmp | executable | |
MD5:5206DE48E7C33C943F2408F2DF3E6A03 | SHA256:B0DBAE30DB508B31BB4C3A4EBD3A538BE781B3535C52EB024AA6B01DC3DE2673 | |||
| 1576 | DCED.tmp | C:\Users\admin\AppData\Local\Temp\DD4B.tmp | executable | |
MD5:B43A57178D7AA40AF2E82BBCCCD6FE06 | SHA256:1F9DCC5395153E653F55DFC81AABD98DB01BBFCB7B1A20ACFA271F53CBD5F7BE | |||
| 6240 | DE64.tmp | C:\Users\admin\AppData\Local\Temp\DEC2.tmp | executable | |
MD5:C22A00968F305DCECFE07C4CE10D1197 | SHA256:0E69A8893E7011159BAC54F01A45E1F0BC64078C1656643B0F3FF8B77C134CFC | |||
| 4684 | DDA9.tmp | C:\Users\admin\AppData\Local\Temp\DE07.tmp | executable | |
MD5:1DEDA8B761C7A924D013F34833A925AE | SHA256:C325CA7BBE9EF6C62AB6B1DFE6F29E19EBA93CE2665B7B0D40132AF40FB2A492 | |||
| 5248 | DEC2.tmp | C:\Users\admin\AppData\Local\Temp\DF20.tmp | executable | |
MD5:82CF530A03CB66CDE25FA31C72BF85F0 | SHA256:2124F4E2BB00C3ADCD8EB73B083983BDB8889F324B0195DC61F2A266744FDB86 | |||
| 4700 | DF7E.tmp | C:\Users\admin\AppData\Local\Temp\DFEB.tmp | executable | |
MD5:6A4E48D0B0BAF522E50E29741A050557 | SHA256:FCD5F47AFB44B4B48E8F6156B519898DE6C8E89EFED600CB3639C4CBA6F859D6 | |||
| 4708 | DF20.tmp | C:\Users\admin\AppData\Local\Temp\DF7E.tmp | executable | |
MD5:79BA4A6404B3BEE2FB5ADFC2E3CF7428 | SHA256:3350A4403D79047551B051160C7BBDD864977E11AC4CEF28F68F8751B17437E3 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1268 | svchost.exe | GET | 200 | 2.20.245.139:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | SE | binary | 825 b | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 2.20.245.139:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | SE | binary | 825 b | whitelisted |
4916 | RUXIMICS.exe | GET | 200 | 2.20.245.139:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | SE | binary | 825 b | whitelisted |
1268 | svchost.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | QA | binary | 814 b | whitelisted |
— | — | POST | 400 | 40.126.31.2:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | US | text | 203 b | whitelisted |
4916 | RUXIMICS.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | QA | binary | 814 b | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | QA | binary | 814 b | whitelisted |
— | — | POST | 200 | 20.190.159.75:443 | https://login.live.com/RST2.srf | US | xml | 1.24 Kb | whitelisted |
— | — | POST | 400 | 20.190.159.2:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | US | text | 203 b | whitelisted |
— | — | POST | 400 | 20.190.159.130:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | US | text | 203 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1268 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4916 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1268 | svchost.exe | 2.20.245.139:80 | crl.microsoft.com | Akamai International B.V. | SE | whitelisted |
5944 | MoUsoCoreWorker.exe | 2.20.245.139:80 | crl.microsoft.com | Akamai International B.V. | SE | whitelisted |
4916 | RUXIMICS.exe | 2.20.245.139:80 | crl.microsoft.com | Akamai International B.V. | SE | whitelisted |
1268 | svchost.exe | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
4916 | RUXIMICS.exe | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |