File name:

20240313_040152_gKzw-Qd9B491TDzN8IPQHTZOoCk74UDI.eml

Full analysis: https://app.any.run/tasks/ff618323-9466-4a01-87c5-5f21723a93dd
Verdict: Malicious activity
Threats:

FormBook is a data stealer that is being distributed as a MaaS. FormBook differs from a lot of competing malware by its extreme ease of use that allows even the unexperienced threat actors to use FormBook virus.

Analysis date: March 13, 2024, 12:01:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
spam
formbook
xloader
Indicators:
MIME: text/plain
File info: ASCII text, with CRLF, LF line terminators
MD5:

F8D7915AC62615426E9B3C519BB4785B

SHA1:

90A267E6669E1916E9C5CE0C6162E74E2A6465B9

SHA256:

75A9F95F5E68A1CA1191C5AB7AFE15BABC30848D08FD273A893A3D04E4691BEC

SSDEEP:

24576:Qz3aJuWxE8QV9X04MAql8DvMPjhysRCFO2J3dDB:QzZsAnjMVRo7DB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • OUTLOOK.EXE (PID: 3656)
    • Unusual execution from MS Outlook

      • OUTLOOK.EXE (PID: 3656)
    • FORMBOOK has been detected (YARA)

      • dvdplay.exe (PID: 3776)
  • SUSPICIOUS

    • Creates file in the systems drive root

      • WinRAR.exe (PID: 116)
    • Non-standard symbols in registry

      • OUTLOOK.EXE (PID: 3656)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 116)
    • Application launched itself

      • SC_TR11670000_pdf.exe (PID: 956)
      • SC_TR11670000_pdf.exe (PID: 3620)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 116)
      • OUTLOOK.EXE (PID: 3656)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 116)
      • WinRAR.exe (PID: 3252)
    • Checks supported languages

      • SC_TR11670000_pdf.exe (PID: 956)
      • SC_TR11670000_pdf.exe (PID: 2152)
      • SC_TR11670000_pdf.exe (PID: 3620)
      • SC_TR11670000_pdf.exe (PID: 2808)
    • Reads the computer name

      • SC_TR11670000_pdf.exe (PID: 956)
      • SC_TR11670000_pdf.exe (PID: 3620)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 116)
      • WinRAR.exe (PID: 3252)
    • Reads the machine GUID from the registry

      • SC_TR11670000_pdf.exe (PID: 956)
      • SC_TR11670000_pdf.exe (PID: 3620)
    • Manual execution by a user

      • notepad.exe (PID: 3980)
      • explorer.exe (PID: 3976)
      • WinRAR.exe (PID: 2788)
      • SC_TR11670000_pdf.exe (PID: 3620)
      • notepad++.exe (PID: 664)
      • WinRAR.exe (PID: 3252)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.eml | E-Mail message (Var. 3) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
12
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start outlook.exe winrar.exe sc_tr11670000_pdf.exe no specs sc_tr11670000_pdf.exe no specs #FORMBOOK dvdplay.exe no specs winrar.exe no specs notepad.exe no specs explorer.exe no specs sc_tr11670000_pdf.exe no specs sc_tr11670000_pdf.exe no specs notepad++.exe winrar.exe

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\T0WV8NJD\SC_TR11670000_pdf.rar"C:\Program Files\WinRAR\WinRAR.exe
OUTLOOK.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
664"C:\Program Files\Notepad++\notepad++.exe" "C:\Users\admin\Desktop\SC_TR11670000_pdf.exe"C:\Program Files\Notepad++\notepad++.exe
explorer.exe
User:
admin
Company:
Don HO don.h@free.fr
Integrity Level:
MEDIUM
Description:
Notepad++ : a free (GNU) source code editor
Exit code:
0
Version:
7.91
Modules
Images
c:\program files\notepad++\notepad++.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
956"C:\Users\admin\AppData\Local\Temp\Rar$EXa116.31550\SC_TR11670000_pdf.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa116.31550\SC_TR11670000_pdf.exeWinRAR.exe
User:
admin
Company:
Class 5C11 - FIT HANU
Integrity Level:
MEDIUM
Description:
MyPhotos
Exit code:
0
Version:
18.5
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa116.31550\sc_tr11670000_pdf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2152"C:\Users\admin\AppData\Local\Temp\Rar$EXa116.31550\SC_TR11670000_pdf.exe"C:\Users\admin\AppData\Local\Temp\Rar$EXa116.31550\SC_TR11670000_pdf.exeSC_TR11670000_pdf.exe
User:
admin
Company:
Class 5C11 - FIT HANU
Integrity Level:
MEDIUM
Description:
MyPhotos
Exit code:
0
Version:
18.5
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa116.31550\sc_tr11670000_pdf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2788"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\SC_TR11670000_pdf.rar" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
1
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2808"C:\Users\admin\Desktop\SC_TR11670000_pdf.exe"C:\Users\admin\Desktop\SC_TR11670000_pdf.exeSC_TR11670000_pdf.exe
User:
admin
Company:
Class 5C11 - FIT HANU
Integrity Level:
MEDIUM
Description:
MyPhotos
Exit code:
0
Version:
18.5
Modules
Images
c:\users\admin\desktop\sc_tr11670000_pdf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3252"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\SC_TR11670000_pdf.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3620"C:\Users\admin\Desktop\SC_TR11670000_pdf.exe" C:\Users\admin\Desktop\SC_TR11670000_pdf.exeexplorer.exe
User:
admin
Company:
Class 5C11 - FIT HANU
Integrity Level:
MEDIUM
Description:
MyPhotos
Exit code:
0
Version:
18.5
Modules
Images
c:\users\admin\desktop\sc_tr11670000_pdf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3656"C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" /eml "C:\Users\admin\Downloads\20240313_040152_gKzw-Qd9B491TDzN8IPQHTZOoCk74UDI.eml"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Exit code:
0
Version:
14.0.6025.1000
Modules
Images
c:\program files\microsoft office\office14\outlook.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3776"C:\Windows\System32\dvdplay.exe"C:\Windows\System32\dvdplay.exe
OUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
dvdplay placeholder Application
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dvdplay.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
Total events
19 861
Read events
19 208
Write events
615
Delete events
38

Modification events

(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1055
Value:
Off
Executable files
3
Suspicious files
4
Text files
7
Unknown types
1

Dropped files

PID
Process
Filename
Type
3656OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVR7AC.tmp.cvr
MD5:
SHA256:
3656OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
MD5:
SHA256:
3656OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\T0WV8NJD\SC_TR11670000_pdf.rar:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
3656OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\tmp953.tmpbinary
MD5:44CE90E05741483ADDCF7523FB7D3457
SHA256:79F7DBF4DF1CE95F09EACAE8CC7354467916F62113B09C16E1FD514BD160A9E9
3656OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotmpgc
MD5:0B59AD45CD8AEEEF2063F71A0BCE582D
SHA256:70E97D20DCE8DD7B1F1D0DE223F38190CC0931C42474586233335FBB1E0BBD9F
3656OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\T0WV8NJD\SC_TR11670000_pdf.rarcompressed
MD5:FDD8A2EC77DA1C7A99495F7D3B0BD482
SHA256:F47E49C9624CCE5009ED3954CA86E6C346B167D9D08275D750810F7841F69B4B
3656OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\T0WV8NJD\SC_TR11670000_pdf (2).rarcompressed
MD5:FDD8A2EC77DA1C7A99495F7D3B0BD482
SHA256:F47E49C9624CCE5009ED3954CA86E6C346B167D9D08275D750810F7841F69B4B
3656OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{9C50085E-9797-4C92-B5B7-A421F9AAEA8C}\{1C306CB1-771E-4B4B-A902-86E897877F5B}.pngimage
MD5:4C61C12EDBC453D7AE184976E95258E1
SHA256:296526F9A716C1AA91BA5D6F69F0EB92FDF79C2CB2CFCF0CEB22B7CCBC27035F
3656OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Outlook\mapisvc.inftext
MD5:F3B25701FE362EC84616A93A45CE9998
SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
3656OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\T0WV8NJD\SC_TR11670000_pdf (2).rar:Zone.Identifier:$DATAtext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
4
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3656
OUTLOOK.EXE
GET
64.4.26.155:80
http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
3656
OUTLOOK.EXE
64.4.26.155:80
config.messenger.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
config.messenger.msn.com
  • 64.4.26.155
whitelisted

Threats

No threats detected
Process
Message
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\plugins\Config\nppPluginList.dll