File name:

REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exe

Full analysis: https://app.any.run/tasks/0f96c564-1751-4faf-a787-6c0ed1095943
Verdict: Malicious activity
Threats:

FormBook is a data stealer that is being distributed as a MaaS. FormBook differs from a lot of competing malware by its extreme ease of use that allows even the unexperienced threat actors to use FormBook virus.

Analysis date: December 11, 2023, 17:40:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
formbook
xloader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

3B90DFED6F3D592756842AA4D649B296

SHA1:

3D04BFDA4DAD700ED494A3DC445F32886E31A6ED

SHA256:

EB2E77542E2AA39E9B1DAB537B748205B21E2F97667D6D0F4705DB08BBED0674

SSDEEP:

24576:3fFRLvJejb6Zx5oGZfpJTElutOVLuGjIunlXk+ivGkOt:3fFRLvJejOZx5oGZfpJTElutOVLu6Iu3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses Task Scheduler to run other applications

      • REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exe (PID: 3028)
    • Drops the executable file immediately after the start

      • REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exe (PID: 3028)
    • FORMBOOK has been detected (YARA)

      • DevicePairingWizard.exe (PID: 1760)
  • SUSPICIOUS

    • Application launched itself

      • REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exe (PID: 3028)
    • Reads the Internet Settings

      • REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exe (PID: 3028)
  • INFO

    • Checks supported languages

      • REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exe (PID: 3028)
      • REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exe (PID: 2316)
    • Reads the computer name

      • REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exe (PID: 3028)
    • Reads the machine GUID from the registry

      • REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exe (PID: 3028)
    • Creates files or folders in the user directory

      • REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exe (PID: 3028)
    • Create files in a temporary directory

      • REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exe (PID: 3028)
    • Manual execution by a user

      • DevicePairingWizard.exe (PID: 1760)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:12:11 04:44:59+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 649728
InitializedDataSize: 69632
UninitializedDataSize: -
EntryPoint: 0xa08ea
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.0.2.0
ProductVersionNumber: 4.0.2.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: Radio Incredibile
FileDescription: CountDown
FileVersion: 4.0.2.0
InternalName: RvoA.exe
LegalCopyright: Copyright © Radio Incredibile
LegalTrademarks: -
OriginalFileName: RvoA.exe
ProductName: CountDown
ProductVersion: 4.0.2.0
AssemblyVersion: 3.0.0.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
4
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start ref new ksa-dubai project rfq details #5688qm-988765rq-esprius-des-mwqtr.exe no specs schtasks.exe no specs ref new ksa-dubai project rfq details #5688qm-988765rq-esprius-des-mwqtr.exe no specs #FORMBOOK devicepairingwizard.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1760"C:\Windows\SysWOW64\DevicePairingWizard.exe"C:\Windows\SysWOW64\DevicePairingWizard.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Device Pairing Application
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\devicepairingwizard.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2072"C:\Windows\System32\schtasks.exe" /Create /TN "Updates\pkSpCwlcsD" /XML "C:\Users\admin\AppData\Local\Temp\tmp2158.tmp"C:\Windows\SysWOW64\schtasks.exeREF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2316"C:\Users\admin\AppData\Local\Temp\REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exe"C:\Users\admin\AppData\Local\Temp\REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exeREF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exe
User:
admin
Company:
Radio Incredibile
Integrity Level:
MEDIUM
Description:
CountDown
Exit code:
0
Version:
4.0.2.0
Modules
Images
c:\users\admin\appdata\local\temp\ref new ksa-dubai project rfq details #5688qm-988765rq-esprius-des-mwqtr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
3028"C:\Users\admin\AppData\Local\Temp\REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exe" C:\Users\admin\AppData\Local\Temp\REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exeexplorer.exe
User:
admin
Company:
Radio Incredibile
Integrity Level:
MEDIUM
Description:
CountDown
Exit code:
0
Version:
4.0.2.0
Modules
Images
c:\users\admin\appdata\local\temp\ref new ksa-dubai project rfq details #5688qm-988765rq-esprius-des-mwqtr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\mscoree.dll
Total events
211
Read events
203
Write events
8
Delete events
0

Modification events

(PID) Process:(3028) REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3028) REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3028) REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3028) REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
1
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3028REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exeC:\Users\admin\AppData\Roaming\pkSpCwlcsD.exeexecutable
MD5:3B90DFED6F3D592756842AA4D649B296
SHA256:EB2E77542E2AA39E9B1DAB537B748205B21E2F97667D6D0F4705DB08BBED0674
3028REF NEW KSA-DUBAI PROJECT RFQ DETAILS #5688QM-988765RQ-ESPRIUS-DES-MWQTR.exeC:\Users\admin\AppData\Local\Temp\tmp2158.tmpxml
MD5:E3970D3BB2BCCF2DE9E9952F86564A20
SHA256:72DEBE0F01B316B4322338CEDD36F8D8AC20DC46A3F5BD0ACCFC462754D683F3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info