File name:

pamela.doria@minerasancristobal.com.zip

Full analysis: https://app.any.run/tasks/e2b2332f-41ed-493b-8967-17b377490cf3
Verdict: Malicious activity
Threats:

FormBook is a data stealer that is being distributed as a MaaS. FormBook differs from a lot of competing malware by its extreme ease of use that allows even the unexperienced threat actors to use FormBook virus.

Analysis date: May 22, 2026, 21:28:40
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
susp-attachments
attachments
attc-unc
formbook
stealer
xloader
netreactor
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract, compression method=deflate
MD5:

5CB52937ED4BAFA0E7FB996177AF8C50

SHA1:

77DAD217FF0170D2F6A66CF4CE6E83BFAC082362

SHA256:

A5708C8987EC5D93BC654A293BFD205AFADC9248A877089BC5D773462E11A312

SSDEEP:

49152:xnB2SHWhTKNiLSfkUa9D1RuV2PnCIZh1v/5QE+HC3AOPrfJ2tVZyoOizBg8SHw6W:xnByYNiLpD1RW2Pnt3/5QN+ASrfkVRB/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Known privilege escalation attack

      • dllhost.exe (PID: 4704)
    • Changes Windows Defender settings

      • Solicitud de orden de compra OC 26003850.exe (PID: 5852)
    • Adds path to the Windows Defender exclusion list

      • Solicitud de orden de compra OC 26003850.exe (PID: 5852)
    • FORMBOOK has been detected

      • systray.exe (PID: 3048)
      • explorer.exe (PID: 4696)
    • FORMBOOK has been detected (YARA)

      • systray.exe (PID: 3048)
    • FORMBOOK has been detected (SURICATA)

      • explorer.exe (PID: 4696)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • WinRAR.exe (PID: 2828)
    • Executable content was dropped or overwritten

      • explorer.exe (PID: 4696)
    • Probably UAC bypass using CMSTP.exe (Connection Manager service profile)

      • Solicitud de orden de compra OC 26003850.exe (PID: 4056)
    • Used cmstp for execute code hidden within an inf file

      • Solicitud de orden de compra OC 26003850.exe (PID: 4056)
    • File deletion via cmd.exe

      • cmd.exe (PID: 3076)
    • Starts POWERSHELL.EXE for commands execution

      • Solicitud de orden de compra OC 26003850.exe (PID: 5852)
    • Adds exclusion path to Windows Defender (POWERSHELL)

      • Solicitud de orden de compra OC 26003850.exe (PID: 5852)
    • Application launched itself

      • Solicitud de orden de compra OC 26003850.exe (PID: 5852)
    • Uses TASKKILL.EXE to kill process

      • dllhost.exe (PID: 4704)
    • Contacting a server suspected of hosting an CnC

      • explorer.exe (PID: 4696)
  • INFO

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2828)
      • explorer.exe (PID: 4696)
      • Solicitud de orden de compra OC 26003850.exe (PID: 4056)
      • Solicitud de orden de compra OC 26003850.exe (PID: 5852)
    • Reads Microsoft Office registry keys

      • WinRAR.exe (PID: 2828)
      • OpenWith.exe (PID: 1108)
      • explorer.exe (PID: 4696)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5420)
      • WinRAR.exe (PID: 5864)
    • Manual execution by a user

      • WinRAR.exe (PID: 5420)
      • Solicitud de orden de compra OC 26003850.exe (PID: 4056)
      • systray.exe (PID: 3048)
      • WinRAR.exe (PID: 4712)
      • WinRAR.exe (PID: 5864)
    • Reads the computer name

      • Solicitud de orden de compra OC 26003850.exe (PID: 4056)
      • Solicitud de orden de compra OC 26003850.exe (PID: 7544)
      • Solicitud de orden de compra OC 26003850.exe (PID: 5852)
    • Checks supported languages

      • Solicitud de orden de compra OC 26003850.exe (PID: 4056)
      • Solicitud de orden de compra OC 26003850.exe (PID: 5852)
      • Solicitud de orden de compra OC 26003850.exe (PID: 7544)
    • Reads the machine GUID from the registry

      • Solicitud de orden de compra OC 26003850.exe (PID: 4056)
      • Solicitud de orden de compra OC 26003850.exe (PID: 5852)
    • Process checks computer location settings

      • Solicitud de orden de compra OC 26003850.exe (PID: 4056)
      • Solicitud de orden de compra OC 26003850.exe (PID: 5852)
    • Disables trace logs

      • cmstp.exe (PID: 7964)
    • Creates files or folders in the user directory

      • explorer.exe (PID: 4696)
    • .NET Reactor protector has been detected

      • Solicitud de orden de compra OC 26003850.exe (PID: 5852)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 7224)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Formbook

(PID) Process(3048) systray.exe
C2 (1)www.finance77-laudantium.pro/ge47/
Decoy C2 (64)venloria.us
bythebellboxing.com
dakarcocktail.com
wrqgd.xyz
furbabyfortune.shop
thousandoaksbsalandscaping.com
fixitfuego.online
contexception.com
bosslifesa.com
happybusiness.fr
pokerdom-kasinos-site.ru
getscalespilot.co
eqtreporting.com
jefyd.top
taskforcebot.com
spectrumcomercial.com
43dqb.top
ncooleyrealty.com
usemention.ai
droppingjulzz.com
neurowellnesslab.site
twgxcc.art
h38zn.top
duo240.top
myleadsgen.co
maedso.com
park-promote-portability.xyz
appliancerookies.shop
biforin.com
assessoriabr.com
dtu92.top
nettflex.site
911itg.com
valentinar.ru
hup30.top
chipskk.com
bethq.work
naturalstone.store
marineinsurer.one
dojcatena.com
sydneyjoos.com
aitooling.ru
j3152xx.cc
cutoffwheelsrus.com
pepxly.makeup
inscritos20266.online
projectyola.click
c8un2-bz0ox-ecsxpp.xyz
souldiggin.com
lillyandlark.com
adrisex.com
zavixaro.shop
4554.tw
heyarefamily.store
topclickgaming735.info
yinboxops.co
uj3gb7q.shop
clawbytes.xyz
mt9sx9.asia
i4feaqo5h.xyz
12points.se
carolinabiscaro.net
continuumclothing.com
ozenziraat.com
Strings (79)USERNAME
LOCALAPPDATA
USERPROFILE
APPDATA
TEMP
ProgramFiles
CommonProgramFiles
ALLUSERSPROFILE
/c copy "
/c del "
\Run
\Policies
\Explorer
\Registry\User
\Registry\Machine
\SOFTWARE\Microsoft\Windows\CurrentVersion
Office\15.0\Outlook\Profiles\Outlook\
NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\
\SOFTWARE\Mozilla\Mozilla
\Mozilla
Username:
Password:
formSubmitURL
usernameField
encryptedUsername
encryptedPassword
\logins.json
\signons.sqlite
\Microsoft\Vault\
SELECT encryptedUsername, encryptedPassword, formSubmitURL FROM moz_logins
\Google\Chrome\User Data\Default\Login Data
SELECT origin_url, username_value, password_value FROM logins
.exe
.com
.scr
.pif
.cmd
.bat
ms
win
gdi
mfc
vga
igfx
user
help
config
update
regsvc
chkdsk
systray
audiodg
certmgr
autochk
taskhost
colorcpl
services
IconCache
ThumbCache
Cookies
SeDebugPrivilege
SeShutdownPrivilege
\BaseNamedObjects
config.php
POST
HTTP/1.1
Host:
Connection: close
Content-Length:
Cache-Control: no-cache
Origin: http://
User-Agent: Mozilla Firefox/4.0
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://
Accept-Language: en-US
Accept-Encoding: gzip, deflate dat=
f-start
f-end
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 45
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 2026:05:22 21:16:00
ZipCRC: 0x904f5535
ZipCompressedSize: 4294967295
ZipUncompressedSize: 4294967295
ZipFileName: 14dd6260-1c87-4114-1521-08deb8428fb3/b5fd0f98-26a0-1820-5047-4f74c50cac7c.eml
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
166
Monitored processes
22
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs outlook.exe ai.exe no specs openwith.exe no specs winrar.exe solicitud de orden de compra oc 26003850.exe no specs cmstp.exe no specs CMSTPLUA solicitud de orden de compra oc 26003850.exe no specs powershell.exe no specs conhost.exe no specs solicitud de orden de compra oc 26003850.exe no specs solicitud de orden de compra oc 26003850.exe no specs solicitud de orden de compra oc 26003850.exe no specs taskkill.exe no specs conhost.exe no specs #FORMBOOK systray.exe no specs cmd.exe no specs conhost.exe no specs winrar.exe no specs winrar.exe #FORMBOOK explorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
1108C:\WINDOWS\system32\OpenWith.exe -EmbeddingC:\Windows\System32\OpenWith.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2828"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\pamela.doria@minerasancristobal.com.zipC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2952\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3048"C:\Windows\SysWOW64\systray.exe"C:\Windows\SysWOW64\systray.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Systray .exe stub
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\systray.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
Formbook
(PID) Process(3048) systray.exe
C2 (1)www.finance77-laudantium.pro/ge47/
Decoy C2 (64)venloria.us
bythebellboxing.com
dakarcocktail.com
wrqgd.xyz
furbabyfortune.shop
thousandoaksbsalandscaping.com
fixitfuego.online
contexception.com
bosslifesa.com
happybusiness.fr
pokerdom-kasinos-site.ru
getscalespilot.co
eqtreporting.com
jefyd.top
taskforcebot.com
spectrumcomercial.com
43dqb.top
ncooleyrealty.com
usemention.ai
droppingjulzz.com
neurowellnesslab.site
twgxcc.art
h38zn.top
duo240.top
myleadsgen.co
maedso.com
park-promote-portability.xyz
appliancerookies.shop
biforin.com
assessoriabr.com
dtu92.top
nettflex.site
911itg.com
valentinar.ru
hup30.top
chipskk.com
bethq.work
naturalstone.store
marineinsurer.one
dojcatena.com
sydneyjoos.com
aitooling.ru
j3152xx.cc
cutoffwheelsrus.com
pepxly.makeup
inscritos20266.online
projectyola.click
c8un2-bz0ox-ecsxpp.xyz
souldiggin.com
lillyandlark.com
adrisex.com
zavixaro.shop
4554.tw
heyarefamily.store
topclickgaming735.info
yinboxops.co
uj3gb7q.shop
clawbytes.xyz
mt9sx9.asia
i4feaqo5h.xyz
12points.se
carolinabiscaro.net
continuumclothing.com
ozenziraat.com
Strings (79)USERNAME
LOCALAPPDATA
USERPROFILE
APPDATA
TEMP
ProgramFiles
CommonProgramFiles
ALLUSERSPROFILE
/c copy "
/c del "
\Run
\Policies
\Explorer
\Registry\User
\Registry\Machine
\SOFTWARE\Microsoft\Windows\CurrentVersion
Office\15.0\Outlook\Profiles\Outlook\
NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\
\SOFTWARE\Mozilla\Mozilla
\Mozilla
Username:
Password:
formSubmitURL
usernameField
encryptedUsername
encryptedPassword
\logins.json
\signons.sqlite
\Microsoft\Vault\
SELECT encryptedUsername, encryptedPassword, formSubmitURL FROM moz_logins
\Google\Chrome\User Data\Default\Login Data
SELECT origin_url, username_value, password_value FROM logins
.exe
.com
.scr
.pif
.cmd
.bat
ms
win
gdi
mfc
vga
igfx
user
help
config
update
regsvc
chkdsk
systray
audiodg
certmgr
autochk
taskhost
colorcpl
services
IconCache
ThumbCache
Cookies
SeDebugPrivilege
SeShutdownPrivilege
\BaseNamedObjects
config.php
POST
HTTP/1.1
Host:
Connection: close
Content-Length:
Cache-Control: no-cache
Origin: http://
User-Agent: Mozilla Firefox/4.0
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://
Accept-Language: en-US
Accept-Encoding: gzip, deflate dat=
f-start
f-end
3076/c del "C:\Users\admin\Desktop\Solicitud de orden de compra OC 26003850.exe"C:\Windows\SysWOW64\cmd.exesystray.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
4056"C:\Users\admin\Desktop\Solicitud de orden de compra OC 26003850.exe" C:\Users\admin\Desktop\Solicitud de orden de compra OC 26003850.exeexplorer.exe
User:
admin
Company:
Antigravity
Integrity Level:
MEDIUM
Description:
AvalancheRunner
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\solicitud de orden de compra oc 26003850.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
4696C:\WINDOWS\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\twinapi.dll
c:\windows\system32\oleaut32.dll
4704C:\WINDOWS\SysWOW64\DllHost.exe /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7}C:\Windows\SysWOW64\dllhost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ucrtbase.dll
c:\windows\syswow64\combase.dll
4712"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\pamela.doria@minerasancristobal.com.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5420"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\pamela.doria@minerasancristobal.com.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
4
Suspicious files
17
Text files
33
Unknown types
0

Dropped files

PID
Process
Filename
Type
7176OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook1.pst
MD5:
SHA256:
4696explorer.exeC:\Users\admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dattext
MD5:E49C56350AEDF784BFE00E444B879672
SHA256:A8BD235303668981563DFB5AAE338CB802817C4060E2C199B7C84901D57B7E1E
7176OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbresbinary
MD5:97AA747A78D23E9781A6A75929DB81E2
SHA256:C6D5148460F1451120B6497D3ECA6B485C5FAB1B22E3CCB2A9770059A650519B
7176OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\C8350D72.datimage
MD5:6EC69A42C6539834E874CD9B3BE52070
SHA256:015F0D8037663C4FC370D1BC1925A20A37965F244926E02C1811CE973BF8D32D
7176OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\C0129997-CEBE-49A9-8BDE-4287459CBF12xml
MD5:4F2223FE9A614EE5846778F30EEEC054
SHA256:7068E26FB9CC3904A8698CF1302D222DF2F6F97AEA012C50CE8340DA15F65FFF
2828WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb2828.46838\b5fd0f98-26a0-1820-5047-4f74c50cac7c.emlbinary
MD5:1294DE037D77D0AE880F3AC5216498C2
SHA256:BBF8AE8CFAB1043064FFF736DA7886D1C2484CD0587FFB3C70432EBA4C11257A
7176OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\olk2278.tmpbinary
MD5:95DBDB3818756A4DE874A99589C613C8
SHA256:5693E1D80C1300967DFB6A97F1735DA13BE9A0D33169D4A9CE547426FB625EF2
2828WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb2828.46838\b5fd0f98-26a0-1820-5047-4f74c50cac7c.eml:OECustomPropertybinary
MD5:F6070E55637A0A0FD1B44541E0C887A2
SHA256:D32E86DE66C7206F30D6C795F6BCEDD50332CF6A819E1140B58A9A47F3F20301
7176OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotmbinary
MD5:8234EDFDC8FAB2A9B720181B081E3091
SHA256:AD8F0868EA1695F8315D13F62258CCB58E8B45187B921AC3979B493A6AFF816C
7176OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\5475cb191e478c39370a215b2da98a37e9dc813d.tbresbinary
MD5:5674BD993636C519AB622D95786D1808
SHA256:C993C318976A69F3ACC717809D52E7BA64FEE059E751464AF6AFE3A5E8C16911
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
132
TCP/UDP connections
55
DNS requests
43
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7176
OUTLOOK.EXE
GET
200
52.123.128.14:443
https://ecs.office.com/config/v2/Office/outlook/16.0.16026.20146/Production/CC?&Clientid=%7bD61AB268-C26A-439D-BB15-2A0DEDFCA6A3%7d&Application=outlook&Platform=win32&Version=16.0.16026.20146&MsoVersion=16.0.16026.20002&SDX=fa000000002.2.0.1907.31003&SDX=fa000000005.1.0.1909.30011&SDX=fa000000006.1.0.1909.13002&SDX=fa000000008.1.0.1908.16006&SDX=fa000000009.1.0.1908.6002&SDX=fa000000016.1.0.1810.13001&SDX=fa000000029.1.0.1906.25001&SDX=fa000000033.1.0.1908.24001&SDX=wa104381125.1.0.1810.9001&ProcessName=outlook.exe&Audience=Production&Build=ship&Architecture=x64&Language=en-US&SubscriptionLicense=false&PerpetualLicense=2019&LicenseCategory=6&LicenseSKU=Professional2019Retail&OsVersion=10.0&OsBuild=19045&Channel=CC&InstallType=C2R&SessionId=%7b1237B80A-8AFB-4498-A5B8-FAF3F405D7DE%7d&LabMachine=false
US
text
341 Kb
whitelisted
7176
OUTLOOK.EXE
GET
200
23.11.40.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAsMayxGaRewR3PGR9SvwMg%3D
NL
binary
471 b
whitelisted
7176
OUTLOOK.EXE
POST
200
52.110.17.40:443
https://roaming.svc.cloud.microsoft/rs/RoamingSoapService.svc
US
text
654 b
whitelisted
7176
OUTLOOK.EXE
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBR0TBEVYklX7A9yLoLD9hqmCWDxFgQU3pGGSLehMVkx8UtfB6nciHnaqHYCEzMAAAAPMyBlN%2B5Crk8AAAAAAA8%3D
US
binary
2.23 Kb
whitelisted
7176
OUTLOOK.EXE
GET
200
52.111.231.13:443
https://messaging.lifecycle.office.com/getcustommessage16?app=6&ui=en-US&src=BizBar&messagetype=BizBar&hwid=04111-083-043729&ver=16.0.16026&lc=en-US&platform=10%3A0%3A19045%3A2%3A0%3A0%3A256%3A1%3A&productid=%7B1717C1E0-47D3-4899-A6D3-1022DB7415E0%7D%3A00411-10830-43729-AA720%3AOffice%2019%2C%20Office19Professional2019R_Retail%20edition&clientsessionid=%7B1237B80A-8AFB-4498-A5B8-FAF3F405D7DE%7D&datapropertybag=%7B%22Audience%22%3A%22Production%22%2C%22AudienceGroup%22%3A%22Production%22%2C%22AudienceChannel%22%3A%22CC%22%2C%22Flight%22%3A%22ofsh6c2b1tla1a31%2Cofcrui4yvdulbf31%2Cofhpex3jznepoo31%2Cofpioygfqmufst31%22%7D
US
text
542 b
unknown
7176
OUTLOOK.EXE
POST
200
72.145.35.44:443
https://editor.svc.cloud.microsoft/NlEditor/CloudSuggest/V1
US
text
155 b
whitelisted
5276
MoUsoCoreWorker.exe
GET
304
48.209.138.189:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
5316
svchost.exe
POST
200
40.126.32.136:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
whitelisted
5316
svchost.exe
POST
400
40.126.32.136:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
7884
SIHClient.exe
GET
304
74.178.76.128:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
48.209.138.168:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.209.138.168:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8044
svchost.exe
2.16.164.51:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8044
svchost.exe
23.59.18.102:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3428
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7176
OUTLOOK.EXE
52.110.17.68:443
officeclient.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7176
OUTLOOK.EXE
52.123.128.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 48.209.138.168
  • 48.209.138.189
  • 48.209.6.48
whitelisted
crl.microsoft.com
  • 2.16.164.51
  • 2.16.164.32
  • 2.16.164.74
  • 2.16.164.34
  • 2.16.164.49
  • 2.16.164.89
  • 2.16.164.41
  • 2.16.164.48
  • 2.16.164.58
  • 2.16.241.12
  • 2.16.241.19
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
www.microsoft.com
  • 23.59.18.102
  • 88.221.169.152
whitelisted
google.com
  • 142.251.14.102
  • 142.251.14.138
  • 142.251.14.100
  • 142.251.14.113
  • 142.251.14.139
  • 142.251.14.101
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
officeclient.microsoft.com
  • 52.110.17.68
  • 52.110.17.18
  • 52.110.17.54
  • 52.110.17.48
whitelisted
ecs.office.com
  • 52.123.128.14
  • 52.123.129.14
whitelisted
roaming.svc.cloud.microsoft
  • 52.110.17.40
  • 52.110.17.43
  • 52.110.17.67
  • 52.110.17.49
whitelisted
ocsp.digicert.com
  • 23.11.40.157
  • 172.66.2.5
  • 162.159.142.9
whitelisted

Threats

PID
Process
Class
Message
5276
MoUsoCoreWorker.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
4696
explorer.exe
Malware Command and Control Activity Detected
ET MALWARE FormBook CnC Checkin (GET)
2232
svchost.exe
Misc activity
INFO [ANY.RUN] .cc TLD domain request
4696
explorer.exe
Malware Command and Control Activity Detected
ET MALWARE FormBook CnC Checkin (GET)
4696
explorer.exe
Malware Command and Control Activity Detected
ET MALWARE FormBook CnC Checkin (GET)
4696
explorer.exe
Malware Command and Control Activity Detected
ET MALWARE FormBook CnC Checkin (GET)
No debug info