File name:

810ca18964e48bd0a96234bb91bfbd37.eml

Full analysis: https://app.any.run/tasks/5754ac43-4be2-4eb9-be40-b8834d58066d
Verdict: Malicious activity
Threats:

FormBook is a data stealer that is being distributed as a MaaS. FormBook differs from a lot of competing malware by its extreme ease of use that allows even the unexperienced threat actors to use FormBook virus.

Analysis date: March 19, 2024, 11:29:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
spam
formbook
xloader
stealer
spyware
Indicators:
MIME: message/rfc822
File info: RFC 822 mail, ASCII text, with CRLF line terminators
MD5:

810CA18964E48BD0A96234BB91BFBD37

SHA1:

4D3E65E4C1FFA25F4FDCBAA302D9D6C1833B52B7

SHA256:

AF022D8AD0704ADCD3CBD2921132A4B66118619A9B9E5B33F322BE95738BCF09

SSDEEP:

12288:U79fdowuDpMTxaqoZKeLSMBx0IfokzewtPFHJ6uYNYf9LQBBXPFSX0NJ3sSs1l5O:gZuycqxxMncwtP36DF3b7FIghDf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • OUTLOOK.EXE (PID: 2124)
    • Unusual execution from MS Outlook

      • OUTLOOK.EXE (PID: 2124)
    • FORMBOOK has been detected (YARA)

      • credwiz.exe (PID: 2244)
    • Steals credentials

      • credwiz.exe (PID: 2244)
    • FORMBOOK has been detected (SURICATA)

      • credwiz.exe (PID: 2244)
    • Connects to the CnC server

      • credwiz.exe (PID: 2244)
    • Actions looks like stealing of personal data

      • credwiz.exe (PID: 2244)
  • SUSPICIOUS

    • Non-standard symbols in registry

      • OUTLOOK.EXE (PID: 2124)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2432)
      • PO-108-24.exe (PID: 2900)
    • Reads the Internet Settings

      • PO-108-24.exe (PID: 2900)
      • credwiz.exe (PID: 2244)
    • Application launched itself

      • PO-108-24.exe (PID: 2900)
    • Loads DLL from Mozilla Firefox

      • credwiz.exe (PID: 2244)
    • Process drops SQLite DLL files

      • credwiz.exe (PID: 2244)
    • Executable content was dropped or overwritten

      • credwiz.exe (PID: 2244)
  • INFO

    • The process uses the downloaded file

      • OUTLOOK.EXE (PID: 2124)
      • WinRAR.exe (PID: 2432)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2432)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2432)
      • credwiz.exe (PID: 2244)
    • Checks supported languages

      • PO-108-24.exe (PID: 2900)
      • PO-108-24.exe (PID: 1336)
    • Reads the computer name

      • PO-108-24.exe (PID: 2900)
    • Reads the machine GUID from the registry

      • PO-108-24.exe (PID: 2900)
    • Checks proxy server information

      • credwiz.exe (PID: 2244)
    • Creates files or folders in the user directory

      • credwiz.exe (PID: 2244)
    • Create files in a temporary directory

      • credwiz.exe (PID: 2244)
    • Reads security settings of Internet Explorer

      • credwiz.exe (PID: 2244)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.eml | E-Mail message (Var. 5) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start outlook.exe winrar.exe po-108-24.exe no specs po-108-24.exe no specs #FORMBOOK credwiz.exe firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1336"C:\Users\admin\AppData\Local\Temp\Rar$EXa2432.27955\PO-108-24.exe"C:\Users\admin\AppData\Local\Temp\Rar$EXa2432.27955\PO-108-24.exePO-108-24.exe
User:
admin
Company:
by adguard
Integrity Level:
MEDIUM
Description:
LoginForm
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2432.27955\po-108-24.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2124"C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" /eml "C:\Users\admin\Desktop\810ca18964e48bd0a96234bb91bfbd37.eml"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Exit code:
0
Version:
14.0.6025.1000
Modules
Images
c:\program files\microsoft office\office14\outlook.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2244"C:\Windows\System32\credwiz.exe"C:\Windows\System32\credwiz.exe
OUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Credential Backup and Restore Wizard
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\credwiz.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2432"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\FODVST2T\PO-108-24.zip"C:\Program Files\WinRAR\WinRAR.exe
OUTLOOK.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2900"C:\Users\admin\AppData\Local\Temp\Rar$EXa2432.27955\PO-108-24.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2432.27955\PO-108-24.exeWinRAR.exe
User:
admin
Company:
by adguard
Integrity Level:
MEDIUM
Description:
LoginForm
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2432.27955\po-108-24.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3028"C:\Program Files\Mozilla Firefox\Firefox.exe"C:\Program Files\Mozilla Firefox\firefox.execredwiz.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
17 555
Read events
16 906
Write events
606
Delete events
43

Modification events

(PID) Process:(2124) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(2124) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
Off
(PID) Process:(2124) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
Off
(PID) Process:(2124) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
Off
(PID) Process:(2124) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
Off
(PID) Process:(2124) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
Off
(PID) Process:(2124) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
Off
(PID) Process:(2124) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
Off
(PID) Process:(2124) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
Off
(PID) Process:(2124) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1055
Value:
Off
Executable files
2
Suspicious files
6
Text files
7
Unknown types
1

Dropped files

PID
Process
Filename
Type
2124OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVR1FA8.tmp.cvr
MD5:
SHA256:
2124OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
MD5:
SHA256:
2124OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Outlook\mapisvc.inftext
MD5:F3B25701FE362EC84616A93A45CE9998
SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
2124OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\FODVST2T\PO-108-24 (2).zipcompressed
MD5:A9438D4344DDC9B21AE8B5A2F0A051F9
SHA256:FE8F7CBAEAEC5821327BBFDBD107983FB0855416C3A34D984B06A035ED00B543
2124OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\953ED00F.datimage
MD5:E6077036E6BEED0EA2F49109073FC26D
SHA256:108463D2DB5D7685E7B0BD09949DBFF8D4917DC5F3B91A76DAF329ACE47B709C
2124OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\tmp20A3.tmpbinary
MD5:B85AE3944403D44FD318C98CDD063C5D
SHA256:FFCDD93F7781B3E1D70869C7B7FB0675BA64770C388B98129A21E6B10E339CDC
2124OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotmpgc
MD5:A3C1745493E3799E8AD5B3479FF6D302
SHA256:D63FA9543AB0DC9565A76D7237F79A1E8F6889B3DED97EC6D2AC71EB644741D9
2124OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\mso221B.tmpimage
MD5:ED3C1C40B68BA4F40DB15529D5443DEC
SHA256:039FE79B74E6D3D561E32D4AF570E6CA70DB6BB3718395BE2BF278B9E601279A
2124OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\FODVST2T\PO-108-24.zipcompressed
MD5:A9438D4344DDC9B21AE8B5A2F0A051F9
SHA256:FE8F7CBAEAEC5821327BBFDBD107983FB0855416C3A34D984B06A035ED00B543
2124OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{27A56046-3901-41B1-84D5-E35AD565AE4D}\{1C306CB1-771E-4B4B-A902-86E897877F5B}.pngimage
MD5:4C61C12EDBC453D7AE184976E95258E1
SHA256:296526F9A716C1AA91BA5D6F69F0EB92FDF79C2CB2CFCF0CEB22B7CCBC27035F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
13
DNS requests
9
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2124
OUTLOOK.EXE
GET
64.4.26.155:80
http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig
US
unknown
2244
credwiz.exe
GET
200
64.190.62.22:80
http://www.hofiw.link/m8cr/?h2KD8rx=4HePpn4beS3fj7aSnDJmhuiPeeLjC3J+ctvSlGK4ruIoYzLcS81uzdbHIdvqgP40YUYyQrK53kvl0YbMmAHxCLeSxAV+9x5Pahb9Bt+e2CySKJFvvC90OFs5O0as&On54u=fBuXah0XofUXX&wn=1
DE
html
21.2 Kb
unknown
2244
credwiz.exe
GET
200
45.33.6.223:80
http://www.sqlite.org/2016/sqlite-dll-win32-x86-3140000.zip
US
compressed
423 Kb
unknown
2124
OUTLOOK.EXE
GET
404
62.149.128.40:80
http://www.ecotecre.com/m8cr/?h2KD8rx=TgeXR0doe0VZkcD++f2Quz5n3PuMFEWrGQdjDIOIClNeRX8Qj0jZ7ANyOpXJjUi9yNdD7DNei+VBGLioi5XnbMy7zzTMv4KLpvGCnFHmgXYTr5cbFAQ4F9bqIIC+&On54u=fBuXah0XofUXX
IT
html
4.98 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2124
OUTLOOK.EXE
64.4.26.155:80
config.messenger.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2124
OUTLOOK.EXE
62.149.128.40:80
www.ecotecre.com
Aruba S.p.A.
IT
unknown
2244
credwiz.exe
45.33.6.223:80
www.sqlite.org
Linode, LLC
US
unknown
2124
OUTLOOK.EXE
64.190.62.22:80
www.hofiw.link
SEDO GmbH
DE
unknown
2244
credwiz.exe
64.190.62.22:80
www.hofiw.link
SEDO GmbH
DE
unknown
2124
OUTLOOK.EXE
217.160.0.31:80
www.erhaltungsmassage.com
IONOS SE
DE
unknown

DNS requests

Domain
IP
Reputation
config.messenger.msn.com
  • 64.4.26.155
whitelisted
www.ecotecre.com
  • 62.149.128.40
unknown
www.sqlite.org
  • 45.33.6.223
whitelisted
www.hofiw.link
  • 64.190.62.22
unknown
dns.msftncsi.com
  • 131.107.255.255
shared
www.erhaltungsmassage.com
  • 217.160.0.31
unknown

Threats

PID
Process
Class
Message
2244
credwiz.exe
A Network Trojan was detected
ET USER_AGENTS Suspicious User-Agent (Windows Explorer)
1 ETPRO signatures available at the full report
No debug info