FormBook is a data stealer that is being distributed as a MaaS. It differs from a lot of competing malware by its extreme ease of use that allows even the nobbiest threat actors to use this virus.
MALICIOUS | SUSPICIOUS | INFO |
---|---|---|
Formbook was detected
|
Uses NETSH.EXE for network configuration
|
Creates files in the user directory
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0008A900 | 0x0008B000 | IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ | 6.31451 |
.data | 0x0008C000 | 0x00001CBC | 0x00000000 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x0008E000 | 0x00005EF4 | 0x00006000 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 5.40216 |
No exports.
Click at the process to see the details.
Image |
---|
c:\windows\system32\winanr.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\explorer.exe |
c:\windows\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\explorerframe.dll |
c:\windows\system32\duser.dll |
c:\windows\system32\dui70.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\uxtheme.dll |
c:\windows\system32\powrprof.dll |
c:\windows\system32\setupapi.dll |
c:\windows\system32\cfgmgr32.dll |
c:\windows\system32\devobj.dll |
c:\windows\system32\dwmapi.dll |
c:\windows\system32\slc.dll |
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll |
c:\windows\system32\secur32.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\propsys.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\windowscodecs.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\apphelp.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\ehstorshell.dll |
c:\windows\system32\cscui.dll |
c:\windows\system32\cscdll.dll |
c:\windows\system32\cscapi.dll |
c:\windows\system32\ntshrui.dll |
c:\windows\system32\srvcli.dll |
c:\windows\system32\iconcodecservice.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\rpcrtremote.dll |
c:\windows\system32\sndvolsso.dll |
c:\windows\system32\hid.dll |
c:\windows\system32\mmdevapi.dll |
c:\windows\system32\timedate.cpl |
c:\windows\system32\atl.dll |
c:\windows\system32\winbrand.dll |
c:\windows\system32\actxprxy.dll |
c:\windows\system32\ntmarta.dll |
c:\windows\system32\wldap32.dll |
c:\windows\system32\shdocvw.dll |
c:\windows\system32\linkinfo.dll |
c:\windows\system32\userenv.dll |
c:\windows\system32\shacct.dll |
c:\windows\system32\samlib.dll |
c:\windows\system32\samcli.dll |
c:\windows\system32\netutils.dll |
c:\windows\system32\msftedit.dll |
c:\windows\system32\msls31.dll |
c:\program files\common files\microsoft shared\ink\tiptsf.dll |
c:\windows\system32\authui.dll |
c:\windows\system32\cryptui.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\gameux.dll |
c:\windows\system32\xmllite.dll |
c:\windows\system32\wer.dll |
c:\windows\system32\msiltcfg.dll |
c:\windows\system32\version.dll |
c:\windows\system32\msi.dll |
c:\windows\system32\winsta.dll |
c:\windows\system32\psapi.dll |
c:\windows\system32\networkexplorer.dll |
c:\windows\system32\winmm.dll |
c:\windows\system32\wdmaud.drv |
c:\windows\system32\ksuser.dll |
c:\windows\system32\avrt.dll |
c:\windows\system32\audioses.dll |
c:\windows\system32\msacm32.drv |
c:\windows\system32\msacm32.dll |
c:\windows\system32\midimap.dll |
c:\windows\system32\msutb.dll |
c:\windows\system32\stobject.dll |
c:\windows\system32\batmeter.dll |
c:\windows\system32\wtsapi32.dll |
c:\windows\system32\es.dll |
c:\windows\system32\prnfldr.dll |
c:\windows\system32\winspool.drv |
c:\windows\system32\dxp.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\iertutil.dll |
c:\windows\system32\syncreg.dll |
c:\windows\ehome\ehsso.dll |
c:\windows\system32\netshell.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\nlaapi.dll |
c:\windows\system32\alttab.dll |
c:\windows\system32\wpdshserviceobj.dll |
c:\windows\system32\portabledevicetypes.dll |
c:\windows\system32\portabledeviceapi.dll |
c:\program files\filezilla ftp client\fzshellext.dll |
c:\windows\system32\wintrust.dll |
c:\windows\system32\taskschd.dll |
c:\windows\system32\mssprxy.dll |
c:\windows\system32\pnidui.dll |
c:\windows\system32\qutil.dll |
c:\windows\system32\wevtapi.dll |
c:\windows\system32\dhcpcsvc6.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\dhcpcsvc.dll |
c:\windows\system32\npmproxy.dll |
c:\windows\system32\wlanapi.dll |
c:\windows\system32\wlanutil.dll |
c:\windows\system32\wwanapi.dll |
c:\windows\system32\wwapi.dll |
c:\windows\system32\qagent.dll |
c:\windows\system32\srchadmin.dll |
c:\windows\system32\sxs.dll |
c:\windows\system32\bthprops.cpl |
c:\windows\system32\ieframe.dll |
c:\windows\system32\oleacc.dll |
c:\windows\system32\synccenter.dll |
c:\windows\system32\actioncenter.dll |
c:\windows\system32\imapi2.dll |
c:\windows\system32\hgcpl.dll |
c:\windows\system32\provsvc.dll |
c:\windows\system32\netprofm.dll |
c:\windows\system32\wkscli.dll |
c:\windows\system32\fxsst.dll |
c:\windows\system32\fxsapi.dll |
c:\windows\system32\fxsresm.dll |
c:\program files\internet explorer\ieproxy.dll |
c:\windows\system32\mpr.dll |
c:\windows\system32\structuredquery.dll |
c:\windows\system32\ehstorapi.dll |
c:\windows\system32\wscinterop.dll |
c:\windows\system32\wscapi.dll |
c:\windows\system32\wscui.cpl |
c:\windows\system32\werconcpl.dll |
c:\windows\system32\framedynos.dll |
c:\windows\system32\wercplsupport.dll |
c:\windows\system32\msxml6.dll |
c:\windows\system32\hcproviders.dll |
c:\program files\winrar\rarext.dll |
c:\windows\system32\msimg32.dll |
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll |
c:\windows\system32\syncui.dll |
c:\windows\system32\synceng.dll |
c:\windows\system32\searchfolder.dll |
c:\windows\system32\naturallanguage6.dll |
c:\windows\system32\nlsdata0009.dll |
c:\windows\system32\nlslexicons0009.dll |
c:\windows\system32\thumbcache.dll |
c:\windows\system32\tquery.dll |
c:\program files\microsoft office\office14\onfilter.dll |
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll |
c:\users\admin\appdata\local\temp\order.scr |
c:\windows\system32\sfc.dll |
c:\windows\system32\sfc_os.dll |
c:\windows\system32\devrtl.dll |
c:\windows\system32\audiodg.exe |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\fwpuclnt.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\system32\wship6.dll |
c:\windows\system32\comsvcs.dll |
c:\program files\ftxlptx\helpcljhuf.exe |
Image |
---|
c:\users\admin\appdata\local\temp\order.scr |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvbvm60.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\sxs.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\version.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\apphelp.dll |
Image |
---|
c:\users\admin\appdata\local\temp\order.scr |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvbvm60.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
Image |
---|
c:\windows\system32\audiodg.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\mmdevapi.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\propsys.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\apphelp.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\ieframe.dll |
c:\windows\system32\psapi.dll |
c:\windows\system32\oleacc.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\iertutil.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\mlang.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\program files\mozilla firefox\nss3.dll |
c:\windows\system32\vaultcli.dll |
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll |
c:\windows\system32\windowscodecs.dll |
c:\program files\mozilla firefox\firefox.exe |
Image |
---|
c:\windows\system32\cmd.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\winbrand.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
Image |
---|
c:\windows\system32\dllhost.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\rpcrtremote.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\actxprxy.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\propsys.dll |
c:\windows\system32\ntmarta.dll |
c:\windows\system32\wldap32.dll |
c:\windows\system32\mssprxy.dll |
Image |
---|
c:\program files\ftxlptx\helpcljhuf.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvbvm60.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\sxs.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\version.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\apphelp.dll |
Image |
---|
c:\program files\mozilla firefox\firefox.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\program files\mozilla firefox\mozglue.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\dbghelp.dll |
c:\windows\system32\version.dll |
c:\program files\mozilla firefox\msvcp140.dll |
c:\program files\mozilla firefox\vcruntime140.dll |
c:\program files\mozilla firefox\api-ms-win-crt-runtime-l1-1-0.dll |
c:\program files\mozilla firefox\ucrtbase.dll |
c:\program files\mozilla firefox\api-ms-win-core-localization-l1-2-0.dll |
c:\program files\mozilla firefox\api-ms-win-core-processthreads-l1-1-1.dll |
c:\program files\mozilla firefox\api-ms-win-core-file-l1-2-0.dll |
c:\program files\mozilla firefox\api-ms-win-core-timezone-l1-1-0.dll |
c:\program files\mozilla firefox\api-ms-win-core-file-l2-1-0.dll |
c:\program files\mozilla firefox\api-ms-win-core-synch-l1-2-0.dll |
c:\program files\mozilla firefox\api-ms-win-crt-string-l1-1-0.dll |
c:\program files\mozilla firefox\api-ms-win-crt-heap-l1-1-0.dll |
c:\program files\mozilla firefox\api-ms-win-crt-stdio-l1-1-0.dll |
c:\program files\mozilla firefox\api-ms-win-crt-convert-l1-1-0.dll |
c:\program files\mozilla firefox\api-ms-win-crt-locale-l1-1-0.dll |
c:\program files\mozilla firefox\api-ms-win-crt-math-l1-1-0.dll |
c:\program files\mozilla firefox\api-ms-win-crt-time-l1-1-0.dll |
c:\program files\mozilla firefox\api-ms-win-crt-filesystem-l1-1-0.dll |
c:\program files\mozilla firefox\api-ms-win-crt-environment-l1-1-0.dll |
c:\program files\mozilla firefox\api-ms-win-crt-utility-l1-1-0.dll |
c:\windows\system32\ntdll.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\program files\mozilla firefox\nss3.dll |
c:\windows\system32\winmm.dll |
c:\windows\system32\wsock32.dll |
c:\program files\mozilla firefox\api-ms-win-crt-multibyte-l1-1-0.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\program files\mozilla firefox\softokn3.dll |
c:\program files\mozilla firefox\freebl3.dll |
c:\windows\system32\cryptbase.dll |
Image |
---|
c:\program files\ftxlptx\helpcljhuf.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvbvm60.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
Image |
---|
c:\windows\system32\netsh.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\credui.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\mpr.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\shlwapi.dll |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
124 | explorer.exe | GET | –– | 198.54.117.210:80 | http://www.earnsaverewrite.com/an27/?Ul9=f+o/aoqd8IgEcx1+HV4ymMAyIa1tW/At632OIwa5X/MFtAy1WtN68cROPTOAf+LlGMameA==&5j=tFBXnDRxx08t | US |
––
|
––
|
malicious |
124 | explorer.exe | GET | –– | 35.153.222.37:80 | http://www.tudopreto.com/an27/?Ul9=Jw9Bu32DHdXgmwT0+E6V7dpB7F87aMmNgE6sW0blUFvzdlvjcw1P5Uez4REPrg0saLUQ+g==&5j=tFBXnDRxx08t&sql=1 | US |
––
|
––
|
malicious |
124 | explorer.exe | POST | –– | 35.153.222.37:80 | http://www.tudopreto.com/an27/ | US |
text
––
|
––
|
malicious |
124 | explorer.exe | POST | –– | 35.153.222.37:80 | http://www.tudopreto.com/an27/ | US |
text
––
|
––
|
malicious |
124 | explorer.exe | GET | –– | 198.2.238.71:80 | http://www.281clara.com/an27/?Ul9=KjGaWduyFsOqMT7KaapBTxLEISP9NI1vh/QMr+OV4tDgHFiZv1hcbbDT4b6qNNX3CYunSw==&5j=tFBXnDRxx08t&sql=1 | CN |
––
|
––
|
malicious |
124 | explorer.exe | POST | –– | 198.2.238.71:80 | http://www.281clara.com/an27/ | CN |
text
––
|
––
|
malicious |
124 | explorer.exe | POST | –– | 198.2.238.71:80 | http://www.281clara.com/an27/ | CN |
text
––
|
––
|
malicious |
124 | explorer.exe | POST | –– | 198.2.238.71:80 | http://www.281clara.com/an27/ | CN |
text
––
|
––
|
malicious |
124 | explorer.exe | GET | 301 | 85.13.161.89:80 | http://www.neustadt-steuerberatung.com/an27/?Ul9=OURdvKc11GvwcjWg+5/ow1gVfvRIjCwTiJycxr4QzXbUoF62FbKe8E5yxDPbTPuvWxf1fg==&5j=tFBXnDRxx08t&sql=1 | DE |
html
|
|
malicious |
124 | explorer.exe | POST | –– | 85.13.161.89:80 | http://www.neustadt-steuerberatung.com/an27/ | DE |
text
––
|
––
|
malicious |
124 | explorer.exe | POST | –– | 85.13.161.89:80 | http://www.neustadt-steuerberatung.com/an27/ | DE |
text
––
|
––
|
malicious |
124 | explorer.exe | POST | –– | 85.13.161.89:80 | http://www.neustadt-steuerberatung.com/an27/ | DE |
text
––
|
––
|
malicious |
124 | explorer.exe | GET | –– | 207.150.212.3:80 | http://www.countertopmercenaries.com/an27/?Ul9=o1iMCKrwfVKywwawnFbpKuma6anurgD+Nptu8GPx3L5rj7sfDMEteI1AWpiHKGa1UIYlMQ==&5j=tFBXnDRxx08t&sql=1 | US |
––
|
––
|
malicious |
124 | explorer.exe | POST | –– | 207.150.212.3:80 | http://www.countertopmercenaries.com/an27/ | US |
text
––
|
––
|
malicious |
124 | explorer.exe | POST | –– | 207.150.212.3:80 | http://www.countertopmercenaries.com/an27/ | US |
text
––
|
––
|
malicious |
124 | explorer.exe | POST | –– | 207.150.212.3:80 | http://www.countertopmercenaries.com/an27/ | US |
text
––
|
––
|
malicious |
124 | explorer.exe | GET | 404 | 162.213.249.180:80 | http://www.mansiobbok.info/an27/?Ul9=h9MyZ+ZpXOV3phF/c4/xkV1VqOaGADn+VJs1v3YILA84QEnyiHIeDawKlC3QZQCGse6bOA==&5j=tFBXnDRxx08t | US |
html
|
|
malicious |
124 | explorer.exe | POST | 404 | 162.213.249.180:80 | http://www.mansiobbok.info/an27/ | US |
text
html
|
|
malicious |
124 | explorer.exe | POST | 404 | 162.213.249.180:80 | http://www.mansiobbok.info/an27/ | US |
text
html
|
|
malicious |
124 | explorer.exe | POST | –– | 162.213.249.180:80 | http://www.mansiobbok.info/an27/ | US |
text
––
|
––
|
malicious |
124 | explorer.exe | GET | 404 | 149.56.22.104:80 | http://www.sandcreteengineeringgroup.com/an27/?Ul9=bD8xSA5BUGx3zR7ICGfxHt/6Ummew1Kxe0Ubekgrl/l9Yd0x0i0DvXeN3dxucWupnpAIfA==&5j=tFBXnDRxx08t | CA |
html
|
|
malicious |
124 | explorer.exe | POST | –– | 149.56.22.104:80 | http://www.sandcreteengineeringgroup.com/an27/ | CA |
text
––
|
––
|
malicious |
124 | explorer.exe | POST | –– | 149.56.22.104:80 | http://www.sandcreteengineeringgroup.com/an27/ | CA |
text
––
|
––
|
malicious |
124 | explorer.exe | GET | –– | 23.20.239.12:80 | http://www.southeastart.com/an27/?Ul9=r6jj9T2pgkysj66jOnX9vzP/W68FNykrVyQLLzuRcl8ibRtwaAgFh9U6KO1d5bua+1fH8g==&5j=tFBXnDRxx08t | US |
––
|
––
|
shared |
PID | Process | IP | ASN | CN | Reputation |
---|---|---|---|---|---|
124 | explorer.exe | 198.54.117.210:80 | Namecheap, Inc. | US | malicious |
124 | explorer.exe | 35.153.222.37:80 | US | malicious | |
124 | explorer.exe | 198.2.238.71:80 | PEG TECH INC | CN | malicious |
124 | explorer.exe | 85.13.161.89:80 | Neue Medien Muennich GmbH | DE | malicious |
124 | explorer.exe | 207.150.212.3:80 | Hostway Corporation | US | malicious |
124 | explorer.exe | 162.213.249.180:80 | Namecheap, Inc. | US | malicious |
124 | explorer.exe | 149.56.22.104:80 | OVH SAS | CA | malicious |
–– | –– | 23.20.239.12:80 | Amazon.com, Inc. | US | shared |
Domain | IP | Reputation |
---|---|---|
www.earnsaverewrite.com | 198.54.117.210
198.54.117.217 198.54.117.218 198.54.117.216 198.54.117.215 198.54.117.212 198.54.117.211 |
malicious |
www.tudopreto.com | 35.153.222.37
52.72.132.249 |
malicious |
www.281clara.com | 198.2.238.71
|
malicious |
www.newquestmuscle.com | No response | unknown |
www.neustadt-steuerberatung.com | 85.13.161.89
|
malicious |
www.countertopmercenaries.com | 207.150.212.3
|
malicious |
www.mansiobbok.info | 162.213.249.180
|
malicious |
www.ovio.plus | No response | unknown |
www.yinheyule80.com | No response | unknown |
www.sandcreteengineeringgroup.com | 149.56.22.104
|
malicious |
www.southeastart.com | 23.20.239.12
|
shared |
PID | Process | Class | Message |
---|---|---|---|
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (GET) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (GET) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] TrojanSpy:FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] TrojanSpy:FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (GET) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] TrojanSpy:FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] TrojanSpy:FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (GET) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] TrojanSpy:FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] TrojanSpy:FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (GET) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] TrojanSpy:FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] TrojanSpy:FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (GET) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] TrojanSpy:FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] TrojanSpy:FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] TrojanSpy:FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (POST) |
124 | explorer.exe | A Network Trojan was detected | MALWARE [PTsecurity] FormBook CnC Checkin (GET) |
No debug info.