MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2302aa79bb34eb683a91324995a9fb366bbbe55dffb53deee00b842e75ad19c0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 2302aa79bb34eb683a91324995a9fb366bbbe55dffb53deee00b842e75ad19c0
SHA3-384 hash: 6777d88e0da080fa54cec5f4c11266da49d8b6cb23c60ab700332746d7e3736aea840852a3e00a406bb6b189de3b4565
SHA1 hash: 161acc2265031f3c3265adc1ed395053714de9e1
MD5 hash: f41ef32e23a964f1d170176678da1e24
humanhash: zebra-carolina-washington-equal
File name:SecuriteInfo.com.Trojan.PWS.Siggen2.48024.27824.18796
Download: download sample
Signature Formbook
File size:823'808 bytes
First seen:2020-04-28 15:55:48 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c0ad2c2ea9dc28bf0db406d9effa5ddd (3 x AgentTesla, 3 x FormBook, 3 x Loki)
ssdeep 12288:U0tjFefQXfJr2rr5unYAwGcHyMqdnFIIl075zvzdv/i2drNMPTV8/DLalLcqc+fy:U4RXhAvAwGj/Xl0tz5XiJOeYQDLLY
Threatray 5'122 similar samples on MalwareBazaar
TLSH 3005BF23B1E08877C1B2D63C9D1B93A89B3ABD113D349E4A3BF51D4C5E34791392629B
Reporter SecuriteInfoCom
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
93
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-27 19:07:37 UTC
File Type:
PE (Exe)
Extracted files:
92
AV detection:
29 of 31 (93.55%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Formbook

Executable exe 2302aa79bb34eb683a91324995a9fb366bbbe55dffb53deee00b842e75ad19c0

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
MULTIMEDIA_APICan Play Multimediawinmm.dll::mciGetErrorStringA
winmm.dll::mciSendCommandA
WIN32_PROCESS_APICan Create Process and Threadskernel32.dll::CloseHandle
kernel32.dll::CreateThread
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryExA
kernel32.dll::LoadLibraryA
kernel32.dll::GetSystemInfo
kernel32.dll::GetStartupInfoA
kernel32.dll::GetDiskFreeSpaceA
kernel32.dll::GetCommandLineA
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateFileA
kernel32.dll::FindFirstFileA
kernel32.dll::GetTempPathA
version.dll::GetFileVersionInfoSizeA
version.dll::GetFileVersionInfoA
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegOpenKeyExA
advapi32.dll::RegQueryInfoKeyA
advapi32.dll::RegQueryValueExA
WIN_USER_APIPerforms GUI Actionsuser32.dll::ActivateKeyboardLayout
user32.dll::CreateMenu
user32.dll::FindWindowA
user32.dll::PeekMessageA
user32.dll::CreateWindowExA

Comments