download:

/cc/Protected.exe

Full analysis: https://app.any.run/tasks/c6763c5f-7d61-4a91-a04a-2f433c01d98e
Verdict: Malicious activity
Threats:

FormBook is a data stealer that is being distributed as a MaaS. FormBook differs from a lot of competing malware by its extreme ease of use that allows even the unexperienced threat actors to use FormBook virus.

Analysis date: November 06, 2023, 11:00:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
formbook
xloader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A22595CE0F38B327951C42E18AD3EAAF

SHA1:

4ED68D78DC3C22AA0508D6A73C28A59D2663828A

SHA256:

7A20DB5D819B030F6B5A73104A5519D58743282A54AACFC444ADF459AD5168BD

SSDEEP:

12288:94Kc0QhZ1gLl15nD57fUvF7o52oc4Kc0QhZ1gLl15nD57fUvF7o52ogaCkKc5Zh9:94K1Qk52oc4K1Qk52ogaCkKa8MArVd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • FORMBOOK has been detected (YARA)

      • Protected.exe (PID: 3460)
      • chkdsk.exe (PID: 3228)
  • SUSPICIOUS

    • Application launched itself

      • Protected.exe (PID: 3460)
    • Starts CMD.EXE for commands execution

      • chkdsk.exe (PID: 3228)
  • INFO

    • Reads the machine GUID from the registry

      • Protected.exe (PID: 3460)
    • Checks supported languages

      • Protected.exe (PID: 3460)
      • Protected.exe (PID: 2896)
    • Reads the computer name

      • Protected.exe (PID: 3460)
      • Protected.exe (PID: 2896)
    • Manual execution by a user

      • chkdsk.exe (PID: 3228)
      • taskmgr.exe (PID: 3576)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Formbook

(PID) Process(3460) Protected.exe
C2www.gdzizai.icu/rc2i/
Strings (79)USERNAME
LOCALAPPDATA
USERPROFILE
APPDATA
TEMP
ProgramFiles
CommonProgramFiles
ALLUSERSPROFILE
/c copy "
/c del "
\Run
\Policies
\Explorer
\Registry\User
\Registry\Machine
\SOFTWARE\Microsoft\Windows\CurrentVersion
Office\15.0\Outlook\Profiles\Outlook\
NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\
\SOFTWARE\Mozilla\Mozilla
\Mozilla
Username:
Password:
formSubmitURL
usernameField
encryptedUsername
encryptedPassword
\logins.json
\signons.sqlite
\Microsoft\Vault\
SELECT encryptedUsername, encryptedPassword, formSubmitURL FROM moz_logins
\Google\Chrome\User Data\Default\Login Data
SELECT origin_url, username_value, password_value FROM logins
.exe
.com
.scr
.pif
.cmd
.bat
ms
win
gdi
mfc
vga
igfx
user
help
config
update
regsvc
chkdsk
systray
audiodg
certmgr
autochk
taskhost
colorcpl
services
IconCache
ThumbCache
Cookies
SeDebugPrivilege
SeShutdownPrivilege
\BaseNamedObjects
config.php
POST
HTTP/1.1
Host:
Connection: close
Content-Length:
Cache-Control: no-cache
Origin: http://
User-Agent: Mozilla Firefox/4.0
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://
Accept-Language: en-US
Accept-Encoding: gzip, deflate dat=
f-start
f-end
Decoy C2 (64)gdhuadong.icu
girls-at-a.click
income.rocks
immobilientopclub.immo
frigologs.net
dominohome.store
lowestedt.motorcycles
purplesoul18.asia
fashiontochic.net
jpvalettrash.com
rgvneckpain.com
brainstormingpartner.com
xvwk.asia
universalnikko.com
3887788a2.top
militarysextv.com
xxysocial.com
coachbycoach.com
caregivergrantsfindonline.today
kimetsumatrix.com
pasturefaithful.net
ahotbet1srej.click
alphax.studio
trembolonaacetatoculturismo.com
mgarrettcoaching.com
f1kuic.top
lenguahesatbp.com
alibaba11.space
fast.money
madam-ho.net
swassware.com
dwhandyman.services
nakdaromas.com
policywonx.com
ecofare.xyz
fiberisdead.com
ahotbet1mrtjtfy.click
thedestinyprosperity.com
fabricantedistribuidora.bio
cleavecoffeecollective.com
noticmarketingx.com
fujitsuuk.online
44685.wiki
agprofessionalstiler.com
servicio-seur.com
fruitvarietybosscustomer.store
best-car-insurance.website
susanlwhite.com
bzaei.com
webuyanyhouseforesale.com
egwre.com
vcardbytes.com
1baiyou.com
9165k.vip
yougotit.store
liuhedaohang.com
job-placement-49739.bond
milanomania.net
cromaplus.net
angelsncherry.com
motomarinservis.net
kitchensbazar.com
tommadodsboangelholm.ovh
masud-nawaz.online
(PID) Process(3228) chkdsk.exe
C2www.gdzizai.icu/rc2i/
Strings (79)USERNAME
LOCALAPPDATA
USERPROFILE
APPDATA
TEMP
ProgramFiles
CommonProgramFiles
ALLUSERSPROFILE
/c copy "
/c del "
\Run
\Policies
\Explorer
\Registry\User
\Registry\Machine
\SOFTWARE\Microsoft\Windows\CurrentVersion
Office\15.0\Outlook\Profiles\Outlook\
NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\
\SOFTWARE\Mozilla\Mozilla
\Mozilla
Username:
Password:
formSubmitURL
usernameField
encryptedUsername
encryptedPassword
\logins.json
\signons.sqlite
\Microsoft\Vault\
SELECT encryptedUsername, encryptedPassword, formSubmitURL FROM moz_logins
\Google\Chrome\User Data\Default\Login Data
SELECT origin_url, username_value, password_value FROM logins
.exe
.com
.scr
.pif
.cmd
.bat
ms
win
gdi
mfc
vga
igfx
user
help
config
update
regsvc
chkdsk
systray
audiodg
certmgr
autochk
taskhost
colorcpl
services
IconCache
ThumbCache
Cookies
SeDebugPrivilege
SeShutdownPrivilege
\BaseNamedObjects
config.php
POST
HTTP/1.1
Host:
Connection: close
Content-Length:
Cache-Control: no-cache
Origin: http://
User-Agent: Mozilla Firefox/4.0
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://
Accept-Language: en-US
Accept-Encoding: gzip, deflate dat=
f-start
f-end
Decoy C2 (64)gdhuadong.icu
girls-at-a.click
income.rocks
immobilientopclub.immo
frigologs.net
dominohome.store
lowestedt.motorcycles
purplesoul18.asia
fashiontochic.net
jpvalettrash.com
rgvneckpain.com
brainstormingpartner.com
xvwk.asia
universalnikko.com
3887788a2.top
militarysextv.com
xxysocial.com
coachbycoach.com
caregivergrantsfindonline.today
kimetsumatrix.com
pasturefaithful.net
ahotbet1srej.click
alphax.studio
trembolonaacetatoculturismo.com
mgarrettcoaching.com
f1kuic.top
lenguahesatbp.com
alibaba11.space
fast.money
madam-ho.net
swassware.com
dwhandyman.services
nakdaromas.com
policywonx.com
ecofare.xyz
fiberisdead.com
ahotbet1mrtjtfy.click
thedestinyprosperity.com
fabricantedistribuidora.bio
cleavecoffeecollective.com
noticmarketingx.com
fujitsuuk.online
44685.wiki
agprofessionalstiler.com
servicio-seur.com
fruitvarietybosscustomer.store
best-car-insurance.website
susanlwhite.com
bzaei.com
webuyanyhouseforesale.com
egwre.com
vcardbytes.com
1baiyou.com
9165k.vip
yougotit.store
liuhedaohang.com
job-placement-49739.bond
milanomania.net
cromaplus.net
angelsncherry.com
motomarinservis.net
kitchensbazar.com
tommadodsboangelholm.ovh
masud-nawaz.online
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:11:04 20:59:18+01:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 737280
InitializedDataSize: 20480
UninitializedDataSize: -
EntryPoint: 0x2e5c
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #FORMBOOK protected.exe no specs protected.exe no specs #FORMBOOK chkdsk.exe no specs cmd.exe no specs taskmgr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2896"C:\Users\admin\Desktop\Protected.exe"C:\Users\admin\Desktop\Protected.exeProtected.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\protected.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3228"C:\Windows\System32\chkdsk.exe"C:\Windows\System32\chkdsk.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Check Disk Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chkdsk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Formbook
(PID) Process(3228) chkdsk.exe
C2www.gdzizai.icu/rc2i/
Strings (79)USERNAME
LOCALAPPDATA
USERPROFILE
APPDATA
TEMP
ProgramFiles
CommonProgramFiles
ALLUSERSPROFILE
/c copy "
/c del "
\Run
\Policies
\Explorer
\Registry\User
\Registry\Machine
\SOFTWARE\Microsoft\Windows\CurrentVersion
Office\15.0\Outlook\Profiles\Outlook\
NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\
\SOFTWARE\Mozilla\Mozilla
\Mozilla
Username:
Password:
formSubmitURL
usernameField
encryptedUsername
encryptedPassword
\logins.json
\signons.sqlite
\Microsoft\Vault\
SELECT encryptedUsername, encryptedPassword, formSubmitURL FROM moz_logins
\Google\Chrome\User Data\Default\Login Data
SELECT origin_url, username_value, password_value FROM logins
.exe
.com
.scr
.pif
.cmd
.bat
ms
win
gdi
mfc
vga
igfx
user
help
config
update
regsvc
chkdsk
systray
audiodg
certmgr
autochk
taskhost
colorcpl
services
IconCache
ThumbCache
Cookies
SeDebugPrivilege
SeShutdownPrivilege
\BaseNamedObjects
config.php
POST
HTTP/1.1
Host:
Connection: close
Content-Length:
Cache-Control: no-cache
Origin: http://
User-Agent: Mozilla Firefox/4.0
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://
Accept-Language: en-US
Accept-Encoding: gzip, deflate dat=
f-start
f-end
Decoy C2 (64)gdhuadong.icu
girls-at-a.click
income.rocks
immobilientopclub.immo
frigologs.net
dominohome.store
lowestedt.motorcycles
purplesoul18.asia
fashiontochic.net
jpvalettrash.com
rgvneckpain.com
brainstormingpartner.com
xvwk.asia
universalnikko.com
3887788a2.top
militarysextv.com
xxysocial.com
coachbycoach.com
caregivergrantsfindonline.today
kimetsumatrix.com
pasturefaithful.net
ahotbet1srej.click
alphax.studio
trembolonaacetatoculturismo.com
mgarrettcoaching.com
f1kuic.top
lenguahesatbp.com
alibaba11.space
fast.money
madam-ho.net
swassware.com
dwhandyman.services
nakdaromas.com
policywonx.com
ecofare.xyz
fiberisdead.com
ahotbet1mrtjtfy.click
thedestinyprosperity.com
fabricantedistribuidora.bio
cleavecoffeecollective.com
noticmarketingx.com
fujitsuuk.online
44685.wiki
agprofessionalstiler.com
servicio-seur.com
fruitvarietybosscustomer.store
best-car-insurance.website
susanlwhite.com
bzaei.com
webuyanyhouseforesale.com
egwre.com
vcardbytes.com
1baiyou.com
9165k.vip
yougotit.store
liuhedaohang.com
job-placement-49739.bond
milanomania.net
cromaplus.net
angelsncherry.com
motomarinservis.net
kitchensbazar.com
tommadodsboangelholm.ovh
masud-nawaz.online
3460"C:\Users\admin\Desktop\Protected.exe" C:\Users\admin\Desktop\Protected.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\protected.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Formbook
(PID) Process(3460) Protected.exe
C2www.gdzizai.icu/rc2i/
Strings (79)USERNAME
LOCALAPPDATA
USERPROFILE
APPDATA
TEMP
ProgramFiles
CommonProgramFiles
ALLUSERSPROFILE
/c copy "
/c del "
\Run
\Policies
\Explorer
\Registry\User
\Registry\Machine
\SOFTWARE\Microsoft\Windows\CurrentVersion
Office\15.0\Outlook\Profiles\Outlook\
NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\
\SOFTWARE\Mozilla\Mozilla
\Mozilla
Username:
Password:
formSubmitURL
usernameField
encryptedUsername
encryptedPassword
\logins.json
\signons.sqlite
\Microsoft\Vault\
SELECT encryptedUsername, encryptedPassword, formSubmitURL FROM moz_logins
\Google\Chrome\User Data\Default\Login Data
SELECT origin_url, username_value, password_value FROM logins
.exe
.com
.scr
.pif
.cmd
.bat
ms
win
gdi
mfc
vga
igfx
user
help
config
update
regsvc
chkdsk
systray
audiodg
certmgr
autochk
taskhost
colorcpl
services
IconCache
ThumbCache
Cookies
SeDebugPrivilege
SeShutdownPrivilege
\BaseNamedObjects
config.php
POST
HTTP/1.1
Host:
Connection: close
Content-Length:
Cache-Control: no-cache
Origin: http://
User-Agent: Mozilla Firefox/4.0
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://
Accept-Language: en-US
Accept-Encoding: gzip, deflate dat=
f-start
f-end
Decoy C2 (64)gdhuadong.icu
girls-at-a.click
income.rocks
immobilientopclub.immo
frigologs.net
dominohome.store
lowestedt.motorcycles
purplesoul18.asia
fashiontochic.net
jpvalettrash.com
rgvneckpain.com
brainstormingpartner.com
xvwk.asia
universalnikko.com
3887788a2.top
militarysextv.com
xxysocial.com
coachbycoach.com
caregivergrantsfindonline.today
kimetsumatrix.com
pasturefaithful.net
ahotbet1srej.click
alphax.studio
trembolonaacetatoculturismo.com
mgarrettcoaching.com
f1kuic.top
lenguahesatbp.com
alibaba11.space
fast.money
madam-ho.net
swassware.com
dwhandyman.services
nakdaromas.com
policywonx.com
ecofare.xyz
fiberisdead.com
ahotbet1mrtjtfy.click
thedestinyprosperity.com
fabricantedistribuidora.bio
cleavecoffeecollective.com
noticmarketingx.com
fujitsuuk.online
44685.wiki
agprofessionalstiler.com
servicio-seur.com
fruitvarietybosscustomer.store
best-car-insurance.website
susanlwhite.com
bzaei.com
webuyanyhouseforesale.com
egwre.com
vcardbytes.com
1baiyou.com
9165k.vip
yougotit.store
liuhedaohang.com
job-placement-49739.bond
milanomania.net
cromaplus.net
angelsncherry.com
motomarinservis.net
kitchensbazar.com
tommadodsboangelholm.ovh
masud-nawaz.online
3468/c del "C:\Users\admin\Desktop\Protected.exe"C:\Windows\System32\cmd.exechkdsk.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3576"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
150
Read events
148
Write events
2
Delete events
0

Modification events

(PID) Process:(3576) taskmgr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager
Operation:writeName:UsrColumnSettings
Value:
1C0C0000340400000000000050000000010000001D0C0000350400000000000023000000010000001E0C000036040000000000003C000000010000001F0C000039040000000000004E00000001000000200C000037040000000000004E00000001000000
(PID) Process:(3576) taskmgr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager
Operation:writeName:Preferences
Value:
30030000E803000001000000010000004401000076000000DC0200005C0200000200000001000000000000000000000001000000000000000100000000000000000000000200000004000000090000001D000000FFFFFFFF00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000009C00000040000000210000004600000052000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000000002000000010000000300000004000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0500000000000000FFFFFFFF00000000020000000300000004000000FFFFFFFF00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000630060003C005A00FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000010000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0400000000000000FFFFFFFF02000000FFFFFFFF4F00000028000000970000003400000050000000000000000100000002000000030000000400000000000000FFFFFFFF43000000000000000000000001000000
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info