MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9862798fc67e4230e1339ab641fbedb31c66fb3cb3eceb27207531246a1a875. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: b9862798fc67e4230e1339ab641fbedb31c66fb3cb3eceb27207531246a1a875
SHA3-384 hash: afff13c5f278bcc078f2b55d12848180b5da15efcc5dadbe7f1c17b54015797a685f0fa0643eb5e3fe8516675b11b6c1
SHA1 hash: 29b1e26b1955f3484a17496b9ddffaa000424b40
MD5 hash: 390502c1987ee7be792c3505d91f7e85
humanhash: tennis-monkey-ohio-autumn
File name:Payment Notification.pdf.exe
Download: download sample
Signature FormBook
File size:843'672 bytes
First seen:2020-05-13 16:44:07 UTC
Last seen:2020-05-13 18:22:38 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 05f73cbcbd651d5f7262e511f4576d22 (3 x FormBook)
ssdeep 24576:g12ZXTvKVZwUq9uIk6666666666A6666666666v6666666666r6666666666l:fZXLKVZwUKfk6666666666A666666669
Threatray 5'095 similar samples on MalwareBazaar
TLSH B805D32C401EDEC8E6CDC17FC660C4F8A9AD6C71D2826E9304F57F29F5BB596CA1A841
Reporter abuse_ch
Tags:exe FormBook

Code Signing Certificate

Organisation:VeriSign Time Stamping Services Signer - G2
Issuer:VeriSign Time Stamping Services CA
Algorithm:sha1WithRSAEncryption
Valid from:Jun 15 00:00:00 2007 GMT
Valid to:Jun 14 23:59:59 2012 GMT
Serial number: 3825D7FAF861AF9EF490E726B5D65AD5
Intelligence: 44 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: 8815DFF787F21FA8106760CB89C5B4493F4BD45E2CE801D2A4FE1F61DEE0C039
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: panel.staycreative.es
Sending IP: 178.33.118.10
From: <noreply@fnb.co.za>
Subject: Payment Notification
Attachment: Payment Notification.zip (contains "Payment Notification.pdf.exe")

Intelligence


File Origin
# of uploads :
2
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-13 17:36:36 UTC
File Type:
PE (Exe)
Extracted files:
25
AV detection:
23 of 31 (74.19%)
Threat level:
  2/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Suspicious use of UnmapMainImage
Suspicious use of SetThreadContext
Deletes itself
Formbook Payload
Formbook
Malware Config
C2 Extraction:
http://www.regulars5.com/ms20/
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

Executable exe b9862798fc67e4230e1339ab641fbedb31c66fb3cb3eceb27207531246a1a875

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments