| download: | /cc/Protected.exe |
| Full analysis: | https://app.any.run/tasks/c6763c5f-7d61-4a91-a04a-2f433c01d98e |
| Verdict: | Malicious activity |
| Threats: | FormBook is a data stealer that is being distributed as a MaaS. FormBook differs from a lot of competing malware by its extreme ease of use that allows even the unexperienced threat actors to use FormBook virus. |
| Analysis date: | November 06, 2023, 11:00:46 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | A22595CE0F38B327951C42E18AD3EAAF |
| SHA1: | 4ED68D78DC3C22AA0508D6A73C28A59D2663828A |
| SHA256: | 7A20DB5D819B030F6B5A73104A5519D58743282A54AACFC444ADF459AD5168BD |
| SSDEEP: | 12288:94Kc0QhZ1gLl15nD57fUvF7o52oc4Kc0QhZ1gLl15nD57fUvF7o52ogaCkKc5Zh9:94K1Qk52oc4K1Qk52ogaCkKa8MArVd |
| .dll | | | Win32 Dynamic Link Library (generic) (43.5) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (29.8) |
| .exe | | | Generic Win/DOS Executable (13.2) |
| .exe | | | DOS Executable Generic (13.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:11:04 20:59:18+01:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 737280 |
| InitializedDataSize: | 20480 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2e5c |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2896 | "C:\Users\admin\Desktop\Protected.exe" | C:\Users\admin\Desktop\Protected.exe | — | Protected.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3228 | "C:\Windows\System32\chkdsk.exe" | C:\Windows\System32\chkdsk.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Check Disk Utility Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
Formbook(PID) Process(3228) chkdsk.exe C2www.gdzizai.icu/rc2i/ Strings (79)USERNAME LOCALAPPDATA USERPROFILE APPDATA TEMP ProgramFiles CommonProgramFiles ALLUSERSPROFILE /c copy " /c del " \Run \Policies \Explorer \Registry\User \Registry\Machine \SOFTWARE\Microsoft\Windows\CurrentVersion Office\15.0\Outlook\Profiles\Outlook\ NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ \SOFTWARE\Mozilla\Mozilla \Mozilla Username: Password: formSubmitURL usernameField encryptedUsername encryptedPassword \logins.json \signons.sqlite \Microsoft\Vault\ SELECT encryptedUsername, encryptedPassword, formSubmitURL FROM moz_logins \Google\Chrome\User Data\Default\Login Data SELECT origin_url, username_value, password_value FROM logins .exe .com .scr .pif .cmd .bat ms win gdi mfc vga igfx user help config update regsvc chkdsk systray audiodg certmgr autochk taskhost colorcpl services IconCache ThumbCache Cookies SeDebugPrivilege SeShutdownPrivilege \BaseNamedObjects config.php POST HTTP/1.1 Host: Connection: close Content-Length: Cache-Control: no-cache Origin: http:// User-Agent: Mozilla Firefox/4.0 Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http:// Accept-Language: en-US Accept-Encoding: gzip, deflate
dat= f-start f-end Decoy C2 (64)gdhuadong.icu girls-at-a.click income.rocks immobilientopclub.immo frigologs.net dominohome.store lowestedt.motorcycles purplesoul18.asia fashiontochic.net jpvalettrash.com rgvneckpain.com brainstormingpartner.com xvwk.asia universalnikko.com 3887788a2.top militarysextv.com xxysocial.com coachbycoach.com caregivergrantsfindonline.today kimetsumatrix.com pasturefaithful.net ahotbet1srej.click alphax.studio trembolonaacetatoculturismo.com mgarrettcoaching.com f1kuic.top lenguahesatbp.com alibaba11.space fast.money madam-ho.net swassware.com dwhandyman.services nakdaromas.com policywonx.com ecofare.xyz fiberisdead.com ahotbet1mrtjtfy.click thedestinyprosperity.com fabricantedistribuidora.bio cleavecoffeecollective.com noticmarketingx.com fujitsuuk.online 44685.wiki agprofessionalstiler.com servicio-seur.com fruitvarietybosscustomer.store best-car-insurance.website susanlwhite.com bzaei.com webuyanyhouseforesale.com egwre.com vcardbytes.com 1baiyou.com 9165k.vip yougotit.store liuhedaohang.com job-placement-49739.bond milanomania.net cromaplus.net angelsncherry.com motomarinservis.net kitchensbazar.com tommadodsboangelholm.ovh masud-nawaz.online | |||||||||||||||
| 3460 | "C:\Users\admin\Desktop\Protected.exe" | C:\Users\admin\Desktop\Protected.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
Formbook(PID) Process(3460) Protected.exe C2www.gdzizai.icu/rc2i/ Strings (79)USERNAME LOCALAPPDATA USERPROFILE APPDATA TEMP ProgramFiles CommonProgramFiles ALLUSERSPROFILE /c copy " /c del " \Run \Policies \Explorer \Registry\User \Registry\Machine \SOFTWARE\Microsoft\Windows\CurrentVersion Office\15.0\Outlook\Profiles\Outlook\ NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ \SOFTWARE\Mozilla\Mozilla \Mozilla Username: Password: formSubmitURL usernameField encryptedUsername encryptedPassword \logins.json \signons.sqlite \Microsoft\Vault\ SELECT encryptedUsername, encryptedPassword, formSubmitURL FROM moz_logins \Google\Chrome\User Data\Default\Login Data SELECT origin_url, username_value, password_value FROM logins .exe .com .scr .pif .cmd .bat ms win gdi mfc vga igfx user help config update regsvc chkdsk systray audiodg certmgr autochk taskhost colorcpl services IconCache ThumbCache Cookies SeDebugPrivilege SeShutdownPrivilege \BaseNamedObjects config.php POST HTTP/1.1 Host: Connection: close Content-Length: Cache-Control: no-cache Origin: http:// User-Agent: Mozilla Firefox/4.0 Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http:// Accept-Language: en-US Accept-Encoding: gzip, deflate
dat= f-start f-end Decoy C2 (64)gdhuadong.icu girls-at-a.click income.rocks immobilientopclub.immo frigologs.net dominohome.store lowestedt.motorcycles purplesoul18.asia fashiontochic.net jpvalettrash.com rgvneckpain.com brainstormingpartner.com xvwk.asia universalnikko.com 3887788a2.top militarysextv.com xxysocial.com coachbycoach.com caregivergrantsfindonline.today kimetsumatrix.com pasturefaithful.net ahotbet1srej.click alphax.studio trembolonaacetatoculturismo.com mgarrettcoaching.com f1kuic.top lenguahesatbp.com alibaba11.space fast.money madam-ho.net swassware.com dwhandyman.services nakdaromas.com policywonx.com ecofare.xyz fiberisdead.com ahotbet1mrtjtfy.click thedestinyprosperity.com fabricantedistribuidora.bio cleavecoffeecollective.com noticmarketingx.com fujitsuuk.online 44685.wiki agprofessionalstiler.com servicio-seur.com fruitvarietybosscustomer.store best-car-insurance.website susanlwhite.com bzaei.com webuyanyhouseforesale.com egwre.com vcardbytes.com 1baiyou.com 9165k.vip yougotit.store liuhedaohang.com job-placement-49739.bond milanomania.net cromaplus.net angelsncherry.com motomarinservis.net kitchensbazar.com tommadodsboangelholm.ovh masud-nawaz.online | |||||||||||||||
| 3468 | /c del "C:\Users\admin\Desktop\Protected.exe" | C:\Windows\System32\cmd.exe | — | chkdsk.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3576 | "C:\Windows\system32\taskmgr.exe" /4 | C:\Windows\System32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3576) taskmgr.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager |
| Operation: | write | Name: | UsrColumnSettings |
Value: 1C0C0000340400000000000050000000010000001D0C0000350400000000000023000000010000001E0C000036040000000000003C000000010000001F0C000039040000000000004E00000001000000200C000037040000000000004E00000001000000 | |||
| (PID) Process: | (3576) taskmgr.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager |
| Operation: | write | Name: | Preferences |
Value: 30030000E803000001000000010000004401000076000000DC0200005C0200000200000001000000000000000000000001000000000000000100000000000000000000000200000004000000090000001D000000FFFFFFFF00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000009C00000040000000210000004600000052000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000000002000000010000000300000004000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0500000000000000FFFFFFFF00000000020000000300000004000000FFFFFFFF00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000630060003C005A00FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000010000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0400000000000000FFFFFFFF02000000FFFFFFFF4F00000028000000970000003400000050000000000000000100000002000000030000000400000000000000FFFFFFFF43000000000000000000000001000000 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |