File name:

20240313_040152_gKzw-Qd9B491TDzN8IPQHTZOoCk74UDI.eml

Full analysis: https://app.any.run/tasks/ff618323-9466-4a01-87c5-5f21723a93dd
Verdict: Malicious activity
Threats:

FormBook is a data stealer that is being distributed as a MaaS. FormBook differs from a lot of competing malware by its extreme ease of use that allows even the unexperienced threat actors to use FormBook virus.

Analysis date: March 13, 2024, 12:01:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
spam
formbook
xloader
Indicators:
MIME: text/plain
File info: ASCII text, with CRLF, LF line terminators
MD5:

F8D7915AC62615426E9B3C519BB4785B

SHA1:

90A267E6669E1916E9C5CE0C6162E74E2A6465B9

SHA256:

75A9F95F5E68A1CA1191C5AB7AFE15BABC30848D08FD273A893A3D04E4691BEC

SSDEEP:

24576:Qz3aJuWxE8QV9X04MAql8DvMPjhysRCFO2J3dDB:QzZsAnjMVRo7DB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual execution from MS Outlook

      • OUTLOOK.EXE (PID: 3656)
    • FORMBOOK has been detected (YARA)

      • dvdplay.exe (PID: 3776)
    • Drops the executable file immediately after the start

      • OUTLOOK.EXE (PID: 3656)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 116)
    • Non-standard symbols in registry

      • OUTLOOK.EXE (PID: 3656)
    • Application launched itself

      • SC_TR11670000_pdf.exe (PID: 956)
      • SC_TR11670000_pdf.exe (PID: 3620)
    • Creates file in the systems drive root

      • WinRAR.exe (PID: 116)
  • INFO

    • The process uses the downloaded file

      • OUTLOOK.EXE (PID: 3656)
      • WinRAR.exe (PID: 116)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 116)
      • WinRAR.exe (PID: 3252)
    • Reads the computer name

      • SC_TR11670000_pdf.exe (PID: 956)
      • SC_TR11670000_pdf.exe (PID: 3620)
    • Reads the machine GUID from the registry

      • SC_TR11670000_pdf.exe (PID: 956)
      • SC_TR11670000_pdf.exe (PID: 3620)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 116)
      • WinRAR.exe (PID: 3252)
    • Checks supported languages

      • SC_TR11670000_pdf.exe (PID: 956)
      • SC_TR11670000_pdf.exe (PID: 2152)
      • SC_TR11670000_pdf.exe (PID: 2808)
      • SC_TR11670000_pdf.exe (PID: 3620)
    • Manual execution by a user

      • WinRAR.exe (PID: 2788)
      • notepad++.exe (PID: 664)
      • WinRAR.exe (PID: 3252)
      • notepad.exe (PID: 3980)
      • explorer.exe (PID: 3976)
      • SC_TR11670000_pdf.exe (PID: 3620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.eml | E-Mail message (Var. 3) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
12
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start outlook.exe winrar.exe sc_tr11670000_pdf.exe no specs sc_tr11670000_pdf.exe no specs #FORMBOOK dvdplay.exe no specs winrar.exe no specs notepad.exe no specs explorer.exe no specs sc_tr11670000_pdf.exe no specs sc_tr11670000_pdf.exe no specs notepad++.exe winrar.exe

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\T0WV8NJD\SC_TR11670000_pdf.rar"C:\Program Files\WinRAR\WinRAR.exe
OUTLOOK.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
664"C:\Program Files\Notepad++\notepad++.exe" "C:\Users\admin\Desktop\SC_TR11670000_pdf.exe"C:\Program Files\Notepad++\notepad++.exe
explorer.exe
User:
admin
Company:
Don HO don.h@free.fr
Integrity Level:
MEDIUM
Description:
Notepad++ : a free (GNU) source code editor
Exit code:
0
Version:
7.91
Modules
Images
c:\program files\notepad++\notepad++.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
956"C:\Users\admin\AppData\Local\Temp\Rar$EXa116.31550\SC_TR11670000_pdf.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa116.31550\SC_TR11670000_pdf.exeWinRAR.exe
User:
admin
Company:
Class 5C11 - FIT HANU
Integrity Level:
MEDIUM
Description:
MyPhotos
Exit code:
0
Version:
18.5
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa116.31550\sc_tr11670000_pdf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2152"C:\Users\admin\AppData\Local\Temp\Rar$EXa116.31550\SC_TR11670000_pdf.exe"C:\Users\admin\AppData\Local\Temp\Rar$EXa116.31550\SC_TR11670000_pdf.exeSC_TR11670000_pdf.exe
User:
admin
Company:
Class 5C11 - FIT HANU
Integrity Level:
MEDIUM
Description:
MyPhotos
Exit code:
0
Version:
18.5
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa116.31550\sc_tr11670000_pdf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2788"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\SC_TR11670000_pdf.rar" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
1
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2808"C:\Users\admin\Desktop\SC_TR11670000_pdf.exe"C:\Users\admin\Desktop\SC_TR11670000_pdf.exeSC_TR11670000_pdf.exe
User:
admin
Company:
Class 5C11 - FIT HANU
Integrity Level:
MEDIUM
Description:
MyPhotos
Exit code:
0
Version:
18.5
Modules
Images
c:\users\admin\desktop\sc_tr11670000_pdf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3252"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\SC_TR11670000_pdf.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3620"C:\Users\admin\Desktop\SC_TR11670000_pdf.exe" C:\Users\admin\Desktop\SC_TR11670000_pdf.exeexplorer.exe
User:
admin
Company:
Class 5C11 - FIT HANU
Integrity Level:
MEDIUM
Description:
MyPhotos
Exit code:
0
Version:
18.5
Modules
Images
c:\users\admin\desktop\sc_tr11670000_pdf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3656"C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" /eml "C:\Users\admin\Downloads\20240313_040152_gKzw-Qd9B491TDzN8IPQHTZOoCk74UDI.eml"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Exit code:
0
Version:
14.0.6025.1000
Modules
Images
c:\program files\microsoft office\office14\outlook.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3776"C:\Windows\System32\dvdplay.exe"C:\Windows\System32\dvdplay.exe
OUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
dvdplay placeholder Application
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dvdplay.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
Total events
19 861
Read events
19 208
Write events
615
Delete events
38

Modification events

(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
Off
(PID) Process:(3656) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1055
Value:
Off
Executable files
3
Suspicious files
4
Text files
7
Unknown types
1

Dropped files

PID
Process
Filename
Type
3656OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVR7AC.tmp.cvr
MD5:
SHA256:
3656OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
MD5:
SHA256:
664notepad++.exeC:\Users\admin\AppData\Roaming\Notepad++\config.xmlxml
MD5:75DAF0C838CA0F9DAA89D4074A504E1B
SHA256:97901B6DEF410AA997B0E91A0FD0947EB3A26B7D5C83FD7228FDE04F981AC53C
116WinRAR.exeC:\Users\admin\Desktop\SC_TR11670000_pdf.exeexecutable
MD5:F846DFD6FCDBC27F6D20CC8AA00E3558
SHA256:2603836FC2F2C8BBEB6945A9D1432956A30E83CFCB88FF8652DF9FDC530E9D49
3656OUTLOOK.EXEC:\Users\admin\Desktop\SC_TR11670000_pdf.rar:Zone.Identifier:$DATAtext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
3656OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\T0WV8NJD\SC_TR11670000_pdf (2).rar:Zone.Identifier:$DATAtext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
3252WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa3252.45804\SC_TR11670000_pdf.exeexecutable
MD5:F846DFD6FCDBC27F6D20CC8AA00E3558
SHA256:2603836FC2F2C8BBEB6945A9D1432956A30E83CFCB88FF8652DF9FDC530E9D49
3656OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\T0WV8NJD\SC_TR11670000_pdf.rar:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
3656OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\T0WV8NJD\SC_TR11670000_pdf (2).rarcompressed
MD5:FDD8A2EC77DA1C7A99495F7D3B0BD482
SHA256:F47E49C9624CCE5009ED3954CA86E6C346B167D9D08275D750810F7841F69B4B
664notepad++.exeC:\Users\admin\AppData\Roaming\Notepad++\session.xmltext
MD5:4261A624F6A2F71FB61E3F15826F8CFB
SHA256:504A8176A71A458BD6843AD16B3A35497C830FD0E64A984643B3592C7497400D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
4
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3656
OUTLOOK.EXE
GET
64.4.26.155:80
http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
3656
OUTLOOK.EXE
64.4.26.155:80
config.messenger.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
config.messenger.msn.com
  • 64.4.26.155
whitelisted

Threats

No threats detected
Process
Message
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\plugins\Config\nppPluginList.dll