File name:

RFQ # QUOTATION_PMT - No. 2025500408 MF471.pdf.zip.zip

Full analysis: https://app.any.run/tasks/6c568490-14d8-41e0-b0a6-d22179fd19a0
Verdict: Malicious activity
Threats:

A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.

Analysis date: July 14, 2025, 06:42:31
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
evasion
snake
keylogger
telegram
netreactor
stealer
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

EEE67769A8FCC85210EAC34FF2C75DD9

SHA1:

6EB7797BC23C5868C4A7861A018D59E1CFEBB4B6

SHA256:

CEF38586F9D6F68E983D5DCD34FDB2903B7232612941279293C1BFF03A3A218E

SSDEEP:

24576:4PB2yg+YMuha2Nyo0M3nWqvSu49cKpNtevtRcYfgk/qkIAW8R:4PB2yg+5uha2Nyo0M3nWGSu49cKpNteb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 4084)
    • Actions looks like stealing of personal data

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 4084)
    • SNAKEKEYLOGGER has been detected (SURICATA)

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 4084)
    • SNAKE has been detected (YARA)

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 4084)
  • SUSPICIOUS

    • Application launched itself

      • WinRAR.exe (PID: 6724)
      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 2780)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6724)
    • Checks for external IP

      • svchost.exe (PID: 2200)
      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 4084)
    • The process verifies whether the antivirus software is installed

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 4084)
    • Process communicates with Telegram (possibly using it as an attacker's C2 server)

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 4084)
    • Connects to SMTP port

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 4084)
    • Contacting a server suspected of hosting an CnC

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 4084)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2680)
    • Checks supported languages

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 2780)
      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 1028)
      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 4084)
    • Disables trace logs

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 4084)
    • Reads the software policy settings

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 4084)
    • Checks proxy server information

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 4084)
    • Manual execution by a user

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 2780)
      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 1028)
    • Reads the computer name

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 2780)
      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 1028)
      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 4084)
    • Reads the machine GUID from the registry

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 2780)
      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 4084)
      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 1028)
    • .NET Reactor protector has been detected

      • RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe (PID: 2780)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

SnakeKeylogger

(PID) Process(4084) RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
Keys
DES6fc98cd68a1aab8b
Options
SMTP Userinfo@gaziotomasyon.com.tr
SMTP PasswordGo&2024!
SMTP Hostmail.gaziotomasyon.com.tr
SMTP SendToreportinbox165@gmail.com
SMTP Port587
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2025:07:14 06:42:16
ZipCRC: 0x87a0df62
ZipCompressedSize: 690463
ZipUncompressedSize: 690236
ZipFileName: tmp0uj173ziRFQ # QUOTATION_PMT - No. 2025500408 MF471.pdf.zip
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
7
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe rfq # quotation_pmt - no. 2025500408 mf471.exe no specs rfq # quotation_pmt - no. 2025500408 mf471.exe no specs #SNAKE rfq # quotation_pmt - no. 2025500408 mf471.exe svchost.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1028"C:\Users\admin\Desktop\RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe" C:\Users\admin\Desktop\RFQ # QUOTATION_PMT - No. 2025500408 MF471.exeexplorer.exe
User:
admin
Company:
Strategic Development Corporation
Integrity Level:
MEDIUM
Description:
Secure Mode
Exit code:
0
Version:
1.6.1908.0
Modules
Images
c:\users\admin\desktop\rfq # quotation_pmt - no. 2025500408 mf471.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
2200C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2680"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIb6724.17173\tmp0uj173ziRFQ # QUOTATION_PMT - No. 2025500408 MF471.pdf.zip"C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2780"C:\Users\admin\Desktop\RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe" C:\Users\admin\Desktop\RFQ # QUOTATION_PMT - No. 2025500408 MF471.exeexplorer.exe
User:
admin
Company:
Strategic Development Corporation
Integrity Level:
MEDIUM
Description:
Secure Mode
Exit code:
0
Version:
1.6.1908.0
Modules
Images
c:\users\admin\desktop\rfq # quotation_pmt - no. 2025500408 mf471.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
4084"C:\Users\admin\Desktop\RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe"C:\Users\admin\Desktop\RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
User:
admin
Company:
Strategic Development Corporation
Integrity Level:
MEDIUM
Description:
Secure Mode
Version:
1.6.1908.0
Modules
Images
c:\users\admin\desktop\rfq # quotation_pmt - no. 2025500408 mf471.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
SnakeKeylogger
(PID) Process(4084) RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
Keys
DES6fc98cd68a1aab8b
Options
SMTP Userinfo@gaziotomasyon.com.tr
SMTP PasswordGo&2024!
SMTP Hostmail.gaziotomasyon.com.tr
SMTP SendToreportinbox165@gmail.com
SMTP Port587
4664C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6724"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\RFQ # QUOTATION_PMT - No. 2025500408 MF471.pdf.zip.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
8 681
Read events
8 648
Write events
33
Delete events
0

Modification events

(PID) Process:(6724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(6724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(6724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\RFQ # QUOTATION_PMT - No. 2025500408 MF471.pdf.zip.zip
(PID) Process:(6724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6724) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
1
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2680WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2680.17783\RFQ # QUOTATION_PMT - No. 2025500408 MF471.exeexecutable
MD5:33E4A094EA19ADF93C29382DD8A9F0C1
SHA256:535D4A8CF82A5F7DE2E7D506D67ADDFBFD0418B5E2D14F5F242482BBA6B693C7
6724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb6724.17173\tmp0uj173ziRFQ # QUOTATION_PMT - No. 2025500408 MF471.pdf.zipcompressed
MD5:AB2F4E14E8A7EBFD5E2B41A3470493ED
SHA256:74125922D0D43D659E2346D92C8BFEA6361074A33F6A63155F4EBA6BB39E420F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
26
DNS requests
22
Threats
22

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
2.16.241.14:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
814 b
whitelisted
6400
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
420 b
whitelisted
6400
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
408 b
whitelisted
2876
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
4084
RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
GET
200
132.226.247.73:80
http://checkip.dyndns.org/
BR
html
106 b
whitelisted
4084
RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
GET
200
132.226.247.73:80
http://checkip.dyndns.org/
BR
html
106 b
whitelisted
4084
RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
GET
200
132.226.247.73:80
http://checkip.dyndns.org/
BR
html
106 b
whitelisted
4084
RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
GET
200
132.226.247.73:80
http://checkip.dyndns.org/
BR
html
106 b
whitelisted
4084
RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
GET
200
132.226.247.73:80
http://checkip.dyndns.org/
BR
html
106 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3964
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
2.16.241.14:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
2876
svchost.exe
20.190.160.5:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2876
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.46
whitelisted
crl.microsoft.com
  • 2.16.241.14
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.52.120.96
whitelisted
login.live.com
  • 20.190.160.5
  • 20.190.160.22
  • 40.126.32.68
  • 40.126.32.138
  • 20.190.160.64
  • 20.190.160.17
  • 20.190.160.128
  • 40.126.32.74
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.48
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
checkip.dyndns.org
  • 132.226.247.73
  • 193.122.6.168
  • 132.226.8.169
  • 193.122.130.0
  • 158.101.44.242
whitelisted

Threats

PID
Process
Class
Message
2200
svchost.exe
Device Retrieving External IP Address Detected
ET DYN_DNS External IP Lookup Domain in DNS Query (checkip .dyndns .org)
2200
svchost.exe
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Address Lookup Domain (reallyfreegeoip .org)
2200
svchost.exe
Misc activity
ET INFO External IP Address Lookup Domain in DNS Lookup (reallyfreegeoip .org)
4084
RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
4084
RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
Misc activity
ET INFO External IP Lookup Service Domain (reallyfreegeoip .org) in TLS SNI
4084
RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
4084
RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
Device Retrieving External IP Address Detected
ET INFO 404/Snake/Matiex Keylogger Style External IP Check
4084
RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
4084
RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
4084
RFQ # QUOTATION_PMT - No. 2025500408 MF471.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup - checkip.dyndns.org
No debug info