ANY.RUN Interactive Sandbox
- Full browser-level visibility into phishing
- Huge database of samples and IOCs
- Interactivity in a safe environment
- Actionable Tier 1 reports
Get full visibility into malware and phishing behavior in a safe environment.
| File name: | 2025-08-01_bb50dcca5b1e69d437d89aa39db96c37_elex_mafia_stealc_tofsee.exe |
| Full analysis: | https://app.any.run/tasks/28bc4efb-2c20-4e49-8ce4-fb3d98eae91d |
| Verdict: | Malicious activity |
| Analysis date: | August 01, 2025, 02:51:21 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | BB50DCCA5B1E69D437D89AA39DB96C37 |
| SHA1: | E41C75C467C714ADCFE1F5C5205E4F6A7C5FB041 |
| SHA256: | FDD2176F61D68FD120C35083E859460451FC33BD990856AE9B3A47B1693BAD71 |
| SSDEEP: | 24576:emsYXjV7IC4QqzIHxfkwO82AyTxl22L+sUyz:lsYXjVEC4QqzIHxfkwR2AyTxE2L+sUyz |
| .exe | | | DOS Executable Generic (100) |
|---|
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2003:11:11 14:39:16+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 140288 |
| InitializedDataSize: | 356352 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x113b6 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 12.0.4518.1014 |
| ProductVersionNumber: | 12.0.4518.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Microsoft Office Word |
| FileVersion: | 12.0.4518.1014 |
| InternalName: | WinWord |
| LegalCopyright: | © 2006 Microsoft Corporation. All rights reserved. |
| LegalTrademarks1: | Microsoft® is a registered trademark of Microsoft Corporation. |
| LegalTrademarks2: | Windows® is a registered trademark of Microsoft Corporation. |
| OriginalFileName: | WinWord.exe |
| ProductName: | 2007 Microsoft Office system |
| ProductVersion: | 12.0.4518.1014 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 304 | "C:\Users\admin\AppData\Local\Temp\9F53.tmp" | C:\Users\admin\AppData\Local\Temp\9F53.tmp | — | 9F05.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 304 | "C:\Users\admin\AppData\Local\Temp\B25E.tmp" | C:\Users\admin\AppData\Local\Temp\B25E.tmp | — | B210.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 424 | "C:\Users\admin\AppData\Local\Temp\1157.tmp" | C:\Users\admin\AppData\Local\Temp\1157.tmp | — | 10E9.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 436 | "C:\Users\admin\AppData\Local\Temp\3BE6.tmp" | C:\Users\admin\AppData\Local\Temp\3BE6.tmp | 3B98.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 436 | "C:\Users\admin\AppData\Local\Temp\C990.tmp" | C:\Users\admin\AppData\Local\Temp\C990.tmp | — | C922.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 436 | "C:\Users\admin\AppData\Local\Temp\DDD3.tmp" | C:\Users\admin\AppData\Local\Temp\DDD3.tmp | — | DD75.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 436 | "C:\Users\admin\AppData\Local\Temp\3BA3.tmp" | C:\Users\admin\AppData\Local\Temp\3BA3.tmp | — | 3B35.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 | |||||||||||||||
| 440 | "C:\Users\admin\AppData\Local\Temp\F3D1.tmp" | C:\Users\admin\AppData\Local\Temp\F3D1.tmp | F354.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 440 | "C:\Users\admin\AppData\Local\Temp\2AA0.tmp" | C:\Users\admin\AppData\Local\Temp\2AA0.tmp | 2A42.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 440 | "C:\Users\admin\AppData\Local\Temp\3C63.tmp" | C:\Users\admin\AppData\Local\Temp\3C63.tmp | 3BE6.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4752 | D954.tmp | C:\Users\admin\AppData\Local\Temp\D9C1.tmp | executable | |
MD5:E5D38166B968CCD7AD7D9E65B324F944 | SHA256:9BC2F456B30880045657CE1D9CB985CFF72E644D4B2613DF054CCEBB953A646E | |||
| 4684 | DA1F.tmp | C:\Users\admin\AppData\Local\Temp\DA7C.tmp | executable | |
MD5:1B237A1681ED6CB3838AD327BF35FEED | SHA256:CD1D9804486721A6013044963C88879E75EB8A424E84FD2F5B41F7D9564C0474 | |||
| 2760 | DBB5.tmp | C:\Users\admin\AppData\Local\Temp\DC13.tmp | executable | |
MD5:B50C93BE51088AA7A9E02D4E1CF818BC | SHA256:21D4CC15ADAAEFD44B11E46A9CDD91530FCFF21A049B07F202FA7CD441788402 | |||
| 640 | DD8A.tmp | C:\Users\admin\AppData\Local\Temp\DDE7.tmp | executable | |
MD5:E68E953267E398584CE591A2A57B21DC | SHA256:CDE3E6C20DC8C2EB8041AFFD089FCF9B1185256E9DD9EDA5161CC7C0DD179C87 | |||
| 4708 | D9C1.tmp | C:\Users\admin\AppData\Local\Temp\DA1F.tmp | executable | |
MD5:631D1194886F9A46C575848DECB3977F | SHA256:62AFF1FD05D75FE1D8092BA59DA585B9035DCA2745C4B6A9F97C2E3122DBA4AA | |||
| 5436 | 2025-08-01_bb50dcca5b1e69d437d89aa39db96c37_elex_mafia_stealc_tofsee.exe | C:\Users\admin\AppData\Local\Temp\D954.tmp | executable | |
MD5:C970074453B592DE11907E8720E2428E | SHA256:8B24E5B6E47D1F0886CE51F841CD5B20915C5F0655E07F66F5EBEBB6EC560B89 | |||
| 3288 | DADA.tmp | C:\Users\admin\AppData\Local\Temp\DB28.tmp | executable | |
MD5:82E10FDCD618741E0DDDF9619BFCA0C0 | SHA256:03CC5C41DCBDF085BB45D88BF2674DC98898B85F5883BBF71C1593F93EA887EC | |||
| 6004 | DA7C.tmp | C:\Users\admin\AppData\Local\Temp\DADA.tmp | executable | |
MD5:225F4DC24C665AD5CCF93FD9853BFA73 | SHA256:9C88886DD9ADB05EC6D3253E80A32A7912B6F230B4727389769FC294CBAF0441 | |||
| 4088 | DB28.tmp | C:\Users\admin\AppData\Local\Temp\DBB5.tmp | executable | |
MD5:C0ABB4AB31BF5BC54E7518B782755C2C | SHA256:AEECC674219B9B7516F3B6D934D55B9CE9EF2B0730D067D5EA0F2DB52B3EB568 | |||
| 6176 | DC61.tmp | C:\Users\admin\AppData\Local\Temp\DCBF.tmp | executable | |
MD5:CEBC4852135B3B50778A9A1C555940B1 | SHA256:6F395A2617DE653F89B3F2498D031694AC6DB536A2CFE45EC93EBAEF82209D45 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5432 | RUXIMICS.exe | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 825 b | whitelisted |
1268 | svchost.exe | GET | 200 | 23.3.109.244:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | DE | binary | 814 b | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 23.3.109.244:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | DE | binary | 814 b | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 825 b | whitelisted |
5432 | RUXIMICS.exe | GET | 200 | 23.3.109.244:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | DE | binary | 814 b | whitelisted |
1268 | svchost.exe | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 825 b | whitelisted |
— | — | POST | 500 | 40.91.76.224:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | US | xml | 512 b | whitelisted |
— | — | POST | 500 | 40.91.76.224:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | US | xml | 512 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1268 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5944 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5432 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1268 | svchost.exe | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5944 | MoUsoCoreWorker.exe | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5432 | RUXIMICS.exe | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
1268 | svchost.exe | 23.3.109.244:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5944 | MoUsoCoreWorker.exe | 23.3.109.244:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |