MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a26f2c3365de0a5e3a9868ba0de16f81807076b54abc15625fdda5d730dd809c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: a26f2c3365de0a5e3a9868ba0de16f81807076b54abc15625fdda5d730dd809c
SHA3-384 hash: b4b709b0043016d20dcecbe2d9a0f2570885cb49674eb81e17f61c7ec872a03fa24be6966b58da6fd286f27cac2737eb
SHA1 hash: 26b6be3d4e956c111dcf23f66857557ccdb13e14
MD5 hash: 35ea728d2b7468dfc5bc162f34b81d18
humanhash: eleven-king-potato-alabama
File name:Invoice.exe
Download: download sample
Signature Formbook
File size:644'904 bytes
First seen:2020-04-28 17:19:59 UTC
Last seen:2020-04-29 18:30:43 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 7995e54627ac1ad6ac5c8088a17d235a (3 x FormBook)
ssdeep 12288:bwJGJ8Knh7XU4Y8gxwEpJ/7VPpM5d99kqtQ5frLdVBJMt+hcuIZOJ8c:bwJGqWhXi8gxwEpJ/7VEUfrLdVBJMghF
Threatray 5'098 similar samples on MalwareBazaar
TLSH 5CD40146922EB25DD56A8B3738F6302060754C31988242370E9A79C35F73ED3D9E5EBE
Reporter cocaman
Tags:exe FormBook

Code Signing Certificate

Organisation:VeriSign Time Stamping Services CA
Issuer:Thawte Timestamping CA
Algorithm:sha1WithRSAEncryption
Valid from:Dec 4 00:00:00 2003 GMT
Valid to:Dec 3 23:59:59 2013 GMT
Serial number: 47BF1995DF8D524643F7DB6D480D31A4
Intelligence: 14 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: 1C1983300C10FB262C0B2304B7BE15AABA10AE356EBBBB177583DC44774EB080
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
3
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe a26f2c3365de0a5e3a9868ba0de16f81807076b54abc15625fdda5d730dd809c

(this sample)

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
WIN_BASE_APIUses Win Base APIMSVCR110.dll::__crtTerminateProcess
WIN_USER_APIPerforms GUI ActionsUSER32.dll::CreateWindowExW

Comments