| File name: | Recibo de transferencia de pago 20240209 Bs9808500.exe |
| Full analysis: | https://app.any.run/tasks/0de4cd23-4c09-4165-b1e3-b1fce2c4571f |
| Verdict: | Malicious activity |
| Threats: | FormBook is a data stealer that is being distributed as a MaaS. FormBook differs from a lot of competing malware by its extreme ease of use that allows even the unexperienced threat actors to use FormBook virus. |
| Analysis date: | February 20, 2024, 20:05:00 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | CF7FC3AE06A494C5659DAA2A66971E8C |
| SHA1: | B4CB522E9DA268A729E6E685557D45B8FBA9E4C5 |
| SHA256: | 94ADE5DBC8785CEB3C54891A66C6C906FBE73D1FDD47922AC6DE49561EF967A9 |
| SSDEEP: | 24576:UGyD1MaoIayJ3HJcIF8idTKyoyanrbenHQKIGvoZSzY5/MzjB:UGyD1MaoIayJ3HJcIF8cTKyoyanrben9 |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (63.1) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (23.8) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.6) |
| .exe | | | Win32 Executable (generic) (3.8) |
| .exe | | | Generic Win/DOS Executable (1.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:02:09 12:36:28+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 48 |
| CodeSize: | 623616 |
| InitializedDataSize: | 2048 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9a3b6 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | - |
| FileDescription: | Multicast Information |
| FileVersion: | 1.0.0.0 |
| InternalName: | tEuFehk.exe |
| LegalCopyright: | Copyright © 2024 |
| LegalTrademarks: | - |
| OriginalFileName: | tEuFehk.exe |
| ProductName: | Multicast Information |
| ProductVersion: | 1.0.0.0 |
| AssemblyVersion: | 1.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1384 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3660 | /c del "C:\Users\admin\AppData\Local\Temp\Recibo de transferencia de pago 20240209 Bs9808500.exe" | C:\Windows\System32\cmd.exe | — | wlanext.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3784 | "C:\Windows\System32\wlanext.exe" | C:\Windows\System32\wlanext.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Wireless LAN 802.11 Extensibility Framework Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
Formbook(PID) Process(3784) wlanext.exe C2www.rdlva.com/pz08/ Strings (79)USERNAME LOCALAPPDATA USERPROFILE APPDATA TEMP ProgramFiles CommonProgramFiles ALLUSERSPROFILE /c copy " /c del " \Run \Policies \Explorer \Registry\User \Registry\Machine \SOFTWARE\Microsoft\Windows\CurrentVersion Office\15.0\Outlook\Profiles\Outlook\ NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ \SOFTWARE\Mozilla\Mozilla \Mozilla Username: Password: formSubmitURL usernameField encryptedUsername encryptedPassword \logins.json \signons.sqlite \Microsoft\Vault\ SELECT encryptedUsername, encryptedPassword, formSubmitURL FROM moz_logins \Google\Chrome\User Data\Default\Login Data SELECT origin_url, username_value, password_value FROM logins .exe .com .scr .pif .cmd .bat ms win gdi mfc vga igfx user help config update regsvc chkdsk systray audiodg certmgr autochk taskhost colorcpl services IconCache ThumbCache Cookies SeDebugPrivilege SeShutdownPrivilege \BaseNamedObjects config.php POST HTTP/1.1 Host: Connection: close Content-Length: Cache-Control: no-cache Origin: http:// User-Agent: Mozilla Firefox/4.0 Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http:// Accept-Language: en-US Accept-Encoding: gzip, deflate
dat= f-start f-end Decoy C2 (64)deespresence.com fanyablack.com papermoonnursery.com sunriseclohting.store jenstandsforarkansas.com lkhtalentconsulting.com baerana.com hyperphit.com davidianbrant.com itkagear.com web-findmy.site liveforwardventures.com skyenglearn.online studio-sticky.store yassa-hany.online tacoshack479.com bigtexture.xyz erxkula.shop go-bloggers.com qwdlwys.site taylorpritchett.com yobo-by.com trendsdrop.com boostyourselftoday.com taxibactrungnam.com sgzycp.net anti-theft-device-82641.bond ytytyt016.xyz loveyourhome.style ithinkmoney.com bertric.info permanentday.space kxn.ink onlythumbs.online techrihno.com washing-machine-46612.bond phdop.xyz nordens-media.com gourmetfoodfactory.com ketoalycetiworks.buzz amplilim.site usetruerreview.com inprime.xyz aloyoga-uae.com quickfibrokers.com primadesignerhomes.com greatlifehacks.online thewipglobal.com tobegoodlife.net hotelfincamalvasia.com trevts.com ae-skinlab.com grammarhome.com cld005.com first-solution.online keylabcerrajeria.com besttravelsgate.com friskiwear.com hedrickmanufactory.com pinewell.world 5819995.com c2help.live kai3.center plantasdasminas.com | |||||||||||||||
| 3952 | "C:\Users\admin\AppData\Local\Temp\Recibo de transferencia de pago 20240209 Bs9808500.exe" | C:\Users\admin\AppData\Local\Temp\Recibo de transferencia de pago 20240209 Bs9808500.exe | — | Recibo de transferencia de pago 20240209 Bs9808500.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Multicast Information Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 4052 | "C:\Users\admin\AppData\Local\Temp\Recibo de transferencia de pago 20240209 Bs9808500.exe" | C:\Users\admin\AppData\Local\Temp\Recibo de transferencia de pago 20240209 Bs9808500.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Multicast Information Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (4052) Recibo de transferencia de pago 20240209 Bs9808500.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (4052) Recibo de transferencia de pago 20240209 Bs9808500.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (4052) Recibo de transferencia de pago 20240209 Bs9808500.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (4052) Recibo de transferencia de pago 20240209 Bs9808500.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
www.ytytyt016.xyz |
| unknown |