MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 32b9acce63789d2b83866bca1e45f827835ce2f8c2c61fe79d809c441153058d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 32b9acce63789d2b83866bca1e45f827835ce2f8c2c61fe79d809c441153058d
SHA3-384 hash: 2bd0e6514099549819fe9f7bde5b6e642cb902ba884455164e00e75229121297cfe1ffe21c794f4df2fc324533644cdf
SHA1 hash: 8ad5c092af3e983469ac079c00a46fa3ca6d1a61
MD5 hash: 7549215e56d8bb0cbf1e5954607db3aa
humanhash: fillet-cardinal-echo-avocado
File name:egesi.exe
Download: download sample
Signature Formbook
File size:722'944 bytes
First seen:2020-04-09 07:35:17 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 109c5912df9a73e05e81620809756113 (2 x AgentTesla, 1 x Formbook)
ssdeep 12288:o2m9mygck7g4++RWR7imOxL80hHtlYZWkQhRqZduskLmczmunC:32TgBtmRfOV3HtmZWkKRsbkhmu
Threatray 5'111 similar samples on MalwareBazaar
TLSH 20F4B0E2F7E05933C16716395C0B677CA83AFE1329692A831BE51C4C9F39782356B187
Reporter jarumlus
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-09 03:59:23 UTC
File Type:
PE (Exe)
Extracted files:
8
AV detection:
29 of 31 (93.55%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Formbook

Executable exe 32b9acce63789d2b83866bca1e45f827835ce2f8c2c61fe79d809c441153058d

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and Threadskernel32.dll::CloseHandle
kernel32.dll::CreateThread
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryExA
kernel32.dll::LoadLibraryA
kernel32.dll::GetSystemInfo
kernel32.dll::GetStartupInfoA
kernel32.dll::GetDiskFreeSpaceA
kernel32.dll::GetCommandLineA
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateFileA
kernel32.dll::GetFileAttributesA
kernel32.dll::FindFirstFileA
version.dll::GetFileVersionInfoSizeA
version.dll::GetFileVersionInfoA
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegOpenKeyExA
advapi32.dll::RegQueryValueExA
WIN_USER_APIPerforms GUI Actionsuser32.dll::ActivateKeyboardLayout
user32.dll::CreateMenu
user32.dll::FindWindowA
user32.dll::PeekMessageA
user32.dll::CreateWindowExA

Comments