MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 03200425032e7246493cae751e77c4dc2f2bfdb14cddfea1ab34f051eaaf5290. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 03200425032e7246493cae751e77c4dc2f2bfdb14cddfea1ab34f051eaaf5290
SHA3-384 hash: 1d47b7133afb1f97d0e7672ea561aa704bc37cded25e678453e6787c039a3a2ca5d096a1323fa6ef7460cfdd668956f5
SHA1 hash: 0f5a4fa7de63aeb12a0085cf9fbf91898721f0e8
MD5 hash: df546ce4cc52cbbd6d6ff0e11afffd06
humanhash: bulldog-three-massachusetts-river
File name:DRAFT DOCUMENTS.pdf.exe
Download: download sample
Signature FormBook
File size:407'552 bytes
First seen:2020-03-22 15:13:45 UTC
Last seen:2020-03-22 16:39:46 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger)
ssdeep 6144:/MelVs2Xw7VRZSTJLq5myuNlXl1IDcjKk6+uXBkIoaihHNkBDpjjHQDXJ12nuT:zxOGtLcmyylXDIcGke2ea63HQDXJ12u
Threatray 5'089 similar samples on MalwareBazaar
TLSH F284BFAA7150325DC42EF4FAC5100C925661AC675707E26701F732BE49BEAA3CF246BE
Reporter cocaman
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
91
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

Executable exe 03200425032e7246493cae751e77c4dc2f2bfdb14cddfea1ab34f051eaaf5290

(this sample)

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments