File name:

dacb9aad48869f1349e62dd30eb4aca9eaff7355e67c1611616cd23c0b823934

Full analysis: https://app.any.run/tasks/157bb850-9e0c-4fa8-bd38-e8e5e4e8483e
Verdict: Malicious activity
Threats:

FormBook is a data stealer that is being distributed as a MaaS. FormBook differs from a lot of competing malware by its extreme ease of use that allows even the unexperienced threat actors to use FormBook virus.

Analysis date: September 03, 2025, 17:21:47
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
formbook
xloader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

135B23D07B760C07B340E87030D40C7C

SHA1:

A0F877913BBCBA46BB3CC5B6479FDC2593335281

SHA256:

DACB9AAD48869F1349E62DD30EB4ACA9EAFF7355E67C1611616CD23C0B823934

SSDEEP:

6144:ZGRp+6pX4N2x4173hKbycsk1UEkV8GAPcGPWGAmwmObm:0Rp+6+xtKbZzUj8GccRGEmO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • FORMBOOK has been detected (YARA)

      • dacb9aad48869f1349e62dd30eb4aca9eaff7355e67c1611616cd23c0b823934.exe (PID: 2468)
  • SUSPICIOUS

    • Executes application which crashes

      • dacb9aad48869f1349e62dd30eb4aca9eaff7355e67c1611616cd23c0b823934.exe (PID: 2468)
  • INFO

    • Checks supported languages

      • dacb9aad48869f1349e62dd30eb4aca9eaff7355e67c1611616cd23c0b823934.exe (PID: 2468)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 1100)
    • Checks proxy server information

      • WerFault.exe (PID: 1100)
    • Reads the software policy settings

      • WerFault.exe (PID: 1100)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | DOS Executable Generic (100)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:07:08 01:02:57+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 264192
InitializedDataSize: -
UninitializedDataSize: -
EntryPoint: 0x14c0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1100C:\WINDOWS\SysWOW64\WerFault.exe -u -p 2468 -s 228C:\Windows\SysWOW64\WerFault.exe
dacb9aad48869f1349e62dd30eb4aca9eaff7355e67c1611616cd23c0b823934.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
2380C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2468"C:\Users\admin\AppData\Local\Temp\dacb9aad48869f1349e62dd30eb4aca9eaff7355e67c1611616cd23c0b823934.exe" C:\Users\admin\AppData\Local\Temp\dacb9aad48869f1349e62dd30eb4aca9eaff7355e67c1611616cd23c0b823934.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\users\admin\appdata\local\temp\dacb9aad48869f1349e62dd30eb4aca9eaff7355e67c1611616cd23c0b823934.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
Total events
3 311
Read events
3 311
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
6
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
1100WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_dacb9aad48869f13_36e1da358726a248e05731524d24ffce43e5f1f_06c45bff_bec03b50-8ee6-43de-9dd7-0c1eff053189\Report.wer
MD5:
SHA256:
1100WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERD722.tmp.WERInternalMetadata.xmlxml
MD5:C41BE63F8933568955E15ADB6C02DE42
SHA256:F7A8FCBF1FC21DB020CA53097A2C56120843558266E2ECCB578233F2BEEB7127
1100WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERD6F2.tmp.dmpbinary
MD5:0F2155DF289330829822CB3FDBE7066B
SHA256:303B5DD868A8D54D401B6717C67CB836819F36AF68FD4132AA25DBA96196F711
1100WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERD752.tmp.xmlxml
MD5:EB4DAF33AEFDCD3FAF880051E912F69E
SHA256:40ED6AB0D359B3A8AFFF324EC26E92BE805E9D0CFA9D8E4D3882A4767D80EB31
1100WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEbinary
MD5:399B8A260A3FE6BB6F2D2DAE89FB82BB
SHA256:0DC7CEC07635BC159BA8B7FB1D7FC9AA00DE1C0C045BD688351878B65EAFF57B
1100WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785binary
MD5:D310523737A0D4D05066857AC157F458
SHA256:0A0520D498306689AFA3CAC09ACE82E09229108FC9FABA5A906291D077004484
1100WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:21219FBF144EBDBB1F3D546A726BEE2D
SHA256:739A802008C43F9F6055D2EED137ED154854F5C52D8325A1EC33FB9AA8C270E6
1100WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\21253908F3CB05D51B1C2DA8B681A785binary
MD5:EA415D83F89018D9502A1FB45F323D8D
SHA256:DE6A177135BD49423B8F38CAD3587A9774BE215F57BE90EA2FBC89FACEC6E366
1100WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\dacb9aad48869f1349e62dd30eb4aca9eaff7355e67c1611616cd23c0b823934.exe.2468.dmpbinary
MD5:66F65283AEC16703D6C8E2F4661A1065
SHA256:D33555D194620815784D441A4A45F492991C1E2625A0D94BE5BE94CF04589A8E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
30
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6936
svchost.exe
GET
200
23.38.59.250:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
814 b
whitelisted
1100
WerFault.exe
GET
200
2.18.244.211:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
FR
binary
825 b
whitelisted
1100
WerFault.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
814 b
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
2.18.244.211:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
FR
binary
825 b
whitelisted
6504
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
6504
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
407 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5476
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6936
svchost.exe
40.126.31.3:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6936
svchost.exe
23.38.59.250:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5944
MoUsoCoreWorker.exe
2.18.244.211:80
crl.microsoft.com
Akamai International B.V.
FR
whitelisted
5944
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 172.217.18.14
whitelisted
login.live.com
  • 40.126.31.3
  • 40.126.31.71
  • 40.126.31.73
  • 40.126.31.128
  • 20.190.159.64
  • 40.126.31.131
  • 20.190.159.0
  • 20.190.159.23
whitelisted
ocsp.digicert.com
  • 23.38.59.250
whitelisted
crl.microsoft.com
  • 2.18.244.211
  • 2.18.244.223
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
watson.events.data.microsoft.com
  • 135.234.160.246
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 74.178.76.128
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info