| File name: | pamela.doria@minerasancristobal.com.zip |
| Full analysis: | https://app.any.run/tasks/e2b2332f-41ed-493b-8967-17b377490cf3 |
| Verdict: | Malicious activity |
| Threats: | FormBook is a data stealer that is being distributed as a MaaS. FormBook differs from a lot of competing malware by its extreme ease of use that allows even the unexperienced threat actors to use FormBook virus. |
| Analysis date: | May 22, 2026, 21:28:40 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v4.5 to extract, compression method=deflate |
| MD5: | 5CB52937ED4BAFA0E7FB996177AF8C50 |
| SHA1: | 77DAD217FF0170D2F6A66CF4CE6E83BFAC082362 |
| SHA256: | A5708C8987EC5D93BC654A293BFD205AFADC9248A877089BC5D773462E11A312 |
| SSDEEP: | 49152:xnB2SHWhTKNiLSfkUa9D1RuV2PnCIZh1v/5QE+HC3AOPrfJ2tVZyoOizBg8SHw6W:xnByYNiLpD1RW2Pnt3/5QN+ASrfkVRB/ |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 45 |
|---|---|
| ZipBitFlag: | 0x0009 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2026:05:22 21:16:00 |
| ZipCRC: | 0x904f5535 |
| ZipCompressedSize: | 4294967295 |
| ZipUncompressedSize: | 4294967295 |
| ZipFileName: | 14dd6260-1c87-4114-1521-08deb8428fb3/b5fd0f98-26a0-1820-5047-4f74c50cac7c.eml |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1108 | C:\WINDOWS\system32\OpenWith.exe -Embedding | C:\Windows\System32\OpenWith.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Pick an app Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2828 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\pamela.doria@minerasancristobal.com.zip | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 2952 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3048 | "C:\Windows\SysWOW64\systray.exe" | C:\Windows\SysWOW64\systray.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Systray .exe stub Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
Formbook(PID) Process(3048) systray.exe C2 (1)www.finance77-laudantium.pro/ge47/ Decoy C2 (64)venloria.us bythebellboxing.com dakarcocktail.com wrqgd.xyz furbabyfortune.shop thousandoaksbsalandscaping.com fixitfuego.online contexception.com bosslifesa.com happybusiness.fr pokerdom-kasinos-site.ru getscalespilot.co eqtreporting.com jefyd.top taskforcebot.com spectrumcomercial.com 43dqb.top ncooleyrealty.com usemention.ai droppingjulzz.com neurowellnesslab.site twgxcc.art h38zn.top duo240.top myleadsgen.co maedso.com park-promote-portability.xyz appliancerookies.shop biforin.com assessoriabr.com dtu92.top nettflex.site 911itg.com valentinar.ru hup30.top chipskk.com bethq.work naturalstone.store marineinsurer.one dojcatena.com sydneyjoos.com aitooling.ru j3152xx.cc cutoffwheelsrus.com pepxly.makeup inscritos20266.online projectyola.click c8un2-bz0ox-ecsxpp.xyz souldiggin.com lillyandlark.com adrisex.com zavixaro.shop 4554.tw heyarefamily.store topclickgaming735.info yinboxops.co uj3gb7q.shop clawbytes.xyz mt9sx9.asia i4feaqo5h.xyz 12points.se carolinabiscaro.net continuumclothing.com ozenziraat.com Strings (79)USERNAME LOCALAPPDATA USERPROFILE APPDATA TEMP ProgramFiles CommonProgramFiles ALLUSERSPROFILE /c copy " /c del " \Run \Policies \Explorer \Registry\User \Registry\Machine \SOFTWARE\Microsoft\Windows\CurrentVersion Office\15.0\Outlook\Profiles\Outlook\ NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ \SOFTWARE\Mozilla\Mozilla \Mozilla Username: Password: formSubmitURL usernameField encryptedUsername encryptedPassword \logins.json \signons.sqlite \Microsoft\Vault\ SELECT encryptedUsername, encryptedPassword, formSubmitURL FROM moz_logins \Google\Chrome\User Data\Default\Login Data SELECT origin_url, username_value, password_value FROM logins .exe .com .scr .pif .cmd .bat ms win gdi mfc vga igfx user help config update regsvc chkdsk systray audiodg certmgr autochk taskhost colorcpl services IconCache ThumbCache Cookies SeDebugPrivilege SeShutdownPrivilege \BaseNamedObjects config.php POST HTTP/1.1 Host: Connection: close Content-Length: Cache-Control: no-cache Origin: http:// User-Agent: Mozilla Firefox/4.0 Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http:// Accept-Language: en-US Accept-Encoding: gzip, deflate
dat= f-start f-end | |||||||||||||||
| 3076 | /c del "C:\Users\admin\Desktop\Solicitud de orden de compra OC 26003850.exe" | C:\Windows\SysWOW64\cmd.exe | — | systray.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4056 | "C:\Users\admin\Desktop\Solicitud de orden de compra OC 26003850.exe" | C:\Users\admin\Desktop\Solicitud de orden de compra OC 26003850.exe | — | explorer.exe | |||||||||||
User: admin Company: Antigravity Integrity Level: MEDIUM Description: AvalancheRunner Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 4696 | C:\WINDOWS\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4704 | C:\WINDOWS\SysWOW64\DllHost.exe /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7} | C:\Windows\SysWOW64\dllhost.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4712 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\pamela.doria@minerasancristobal.com.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 5420 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\pamela.doria@minerasancristobal.com.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7176 | OUTLOOK.EXE | C:\Users\admin\Documents\Outlook Files\Outlook1.pst | — | |
MD5:— | SHA256:— | |||
| 4696 | explorer.exe | C:\Users\admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat | text | |
MD5:E49C56350AEDF784BFE00E444B879672 | SHA256:A8BD235303668981563DFB5AAE338CB802817C4060E2C199B7C84901D57B7E1E | |||
| 7176 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbres | binary | |
MD5:97AA747A78D23E9781A6A75929DB81E2 | SHA256:C6D5148460F1451120B6497D3ECA6B485C5FAB1B22E3CCB2A9770059A650519B | |||
| 7176 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\C8350D72.dat | image | |
MD5:6EC69A42C6539834E874CD9B3BE52070 | SHA256:015F0D8037663C4FC370D1BC1925A20A37965F244926E02C1811CE973BF8D32D | |||
| 7176 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\C0129997-CEBE-49A9-8BDE-4287459CBF12 | xml | |
MD5:4F2223FE9A614EE5846778F30EEEC054 | SHA256:7068E26FB9CC3904A8698CF1302D222DF2F6F97AEA012C50CE8340DA15F65FFF | |||
| 2828 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIb2828.46838\b5fd0f98-26a0-1820-5047-4f74c50cac7c.eml | binary | |
MD5:1294DE037D77D0AE880F3AC5216498C2 | SHA256:BBF8AE8CFAB1043064FFF736DA7886D1C2484CD0587FFB3C70432EBA4C11257A | |||
| 7176 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\olk2278.tmp | binary | |
MD5:95DBDB3818756A4DE874A99589C613C8 | SHA256:5693E1D80C1300967DFB6A97F1735DA13BE9A0D33169D4A9CE547426FB625EF2 | |||
| 2828 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIb2828.46838\b5fd0f98-26a0-1820-5047-4f74c50cac7c.eml:OECustomProperty | binary | |
MD5:F6070E55637A0A0FD1B44541E0C887A2 | SHA256:D32E86DE66C7206F30D6C795F6BCEDD50332CF6A819E1140B58A9A47F3F20301 | |||
| 7176 | OUTLOOK.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm | binary | |
MD5:8234EDFDC8FAB2A9B720181B081E3091 | SHA256:AD8F0868EA1695F8315D13F62258CCB58E8B45187B921AC3979B493A6AFF816C | |||
| 7176 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\5475cb191e478c39370a215b2da98a37e9dc813d.tbres | binary | |
MD5:5674BD993636C519AB622D95786D1808 | SHA256:C993C318976A69F3ACC717809D52E7BA64FEE059E751464AF6AFE3A5E8C16911 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
7176 | OUTLOOK.EXE | GET | 200 | 52.123.128.14:443 | https://ecs.office.com/config/v2/Office/outlook/16.0.16026.20146/Production/CC?&Clientid=%7bD61AB268-C26A-439D-BB15-2A0DEDFCA6A3%7d&Application=outlook&Platform=win32&Version=16.0.16026.20146&MsoVersion=16.0.16026.20002&SDX=fa000000002.2.0.1907.31003&SDX=fa000000005.1.0.1909.30011&SDX=fa000000006.1.0.1909.13002&SDX=fa000000008.1.0.1908.16006&SDX=fa000000009.1.0.1908.6002&SDX=fa000000016.1.0.1810.13001&SDX=fa000000029.1.0.1906.25001&SDX=fa000000033.1.0.1908.24001&SDX=wa104381125.1.0.1810.9001&ProcessName=outlook.exe&Audience=Production&Build=ship&Architecture=x64&Language=en-US&SubscriptionLicense=false&PerpetualLicense=2019&LicenseCategory=6&LicenseSKU=Professional2019Retail&OsVersion=10.0&OsBuild=19045&Channel=CC&InstallType=C2R&SessionId=%7b1237B80A-8AFB-4498-A5B8-FAF3F405D7DE%7d&LabMachine=false | US | text | 341 Kb | whitelisted |
7176 | OUTLOOK.EXE | GET | 200 | 23.11.40.157:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAsMayxGaRewR3PGR9SvwMg%3D | NL | binary | 471 b | whitelisted |
7176 | OUTLOOK.EXE | POST | 200 | 52.110.17.40:443 | https://roaming.svc.cloud.microsoft/rs/RoamingSoapService.svc | US | text | 654 b | whitelisted |
7176 | OUTLOOK.EXE | GET | 200 | 204.79.197.203:80 | http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBR0TBEVYklX7A9yLoLD9hqmCWDxFgQU3pGGSLehMVkx8UtfB6nciHnaqHYCEzMAAAAPMyBlN%2B5Crk8AAAAAAA8%3D | US | binary | 2.23 Kb | whitelisted |
7176 | OUTLOOK.EXE | GET | 200 | 52.111.231.13:443 | https://messaging.lifecycle.office.com/getcustommessage16?app=6&ui=en-US&src=BizBar&messagetype=BizBar&hwid=04111-083-043729&ver=16.0.16026&lc=en-US&platform=10%3A0%3A19045%3A2%3A0%3A0%3A256%3A1%3A&productid=%7B1717C1E0-47D3-4899-A6D3-1022DB7415E0%7D%3A00411-10830-43729-AA720%3AOffice%2019%2C%20Office19Professional2019R_Retail%20edition&clientsessionid=%7B1237B80A-8AFB-4498-A5B8-FAF3F405D7DE%7D&datapropertybag=%7B%22Audience%22%3A%22Production%22%2C%22AudienceGroup%22%3A%22Production%22%2C%22AudienceChannel%22%3A%22CC%22%2C%22Flight%22%3A%22ofsh6c2b1tla1a31%2Cofcrui4yvdulbf31%2Cofhpex3jznepoo31%2Cofpioygfqmufst31%22%7D | US | text | 542 b | unknown |
7176 | OUTLOOK.EXE | POST | 200 | 72.145.35.44:443 | https://editor.svc.cloud.microsoft/NlEditor/CloudSuggest/V1 | US | text | 155 b | whitelisted |
5276 | MoUsoCoreWorker.exe | GET | 304 | 48.209.138.189:443 | https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30 | US | — | — | whitelisted |
5316 | svchost.exe | POST | 200 | 40.126.32.136:443 | https://login.live.com/RST2.srf | US | xml | 1.24 Kb | whitelisted |
5316 | svchost.exe | POST | 400 | 40.126.32.136:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | US | text | 204 b | whitelisted |
7884 | SIHClient.exe | GET | 304 | 74.178.76.128:443 | https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL | US | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
5276 | MoUsoCoreWorker.exe | 48.209.138.168:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
— | — | 48.209.138.168:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8044 | svchost.exe | 2.16.164.51:80 | crl.microsoft.com | AKAMAI-ASN1 | NL | whitelisted |
— | — | 48.192.1.65:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8044 | svchost.exe | 23.59.18.102:80 | www.microsoft.com | AKAMAI-AS | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
3428 | svchost.exe | 172.211.123.248:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7176 | OUTLOOK.EXE | 52.110.17.68:443 | officeclient.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7176 | OUTLOOK.EXE | 52.123.128.14:443 | ecs.office.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
officeclient.microsoft.com |
| whitelisted |
ecs.office.com |
| whitelisted |
roaming.svc.cloud.microsoft |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
5276 | MoUsoCoreWorker.exe | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |
4696 | explorer.exe | Malware Command and Control Activity Detected | ET MALWARE FormBook CnC Checkin (GET) |
2232 | svchost.exe | Misc activity | INFO [ANY.RUN] .cc TLD domain request |
4696 | explorer.exe | Malware Command and Control Activity Detected | ET MALWARE FormBook CnC Checkin (GET) |
4696 | explorer.exe | Malware Command and Control Activity Detected | ET MALWARE FormBook CnC Checkin (GET) |
4696 | explorer.exe | Malware Command and Control Activity Detected | ET MALWARE FormBook CnC Checkin (GET) |