MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e3e778591453a54d2cbd3ab1bb4ecb69ed94222f248aac24a95fb951fc6101f0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e3e778591453a54d2cbd3ab1bb4ecb69ed94222f248aac24a95fb951fc6101f0
SHA3-384 hash: e411ec49470f5b9a110c0f8572a6623bf1d2252b786edc6f87acef02d91dfb910b0b3905cfe9c1d10c56a7ec812db18e
SHA1 hash: b4416011845816169b9083544441f5d38970e637
MD5 hash: 0f283b3857ba6909588074db54319f14
humanhash: mike-fourteen-gee-king
File name:89NTb(1).exe
Download: download sample
Signature FormBook
File size:787'968 bytes
First seen:2020-04-27 06:41:23 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 0318ec2c3e20540fe0ccf697fa352b5b (4 x FormBook, 2 x Loki, 2 x AgentTesla)
ssdeep 12288:5MwW5CcA25doqMiR3jfdKWVGKiwqd+ecWWmlvLPcw82zWNhnUHT1eM:P8C2xVrdVMpn+ePXLPvzW/w
Threatray 5'254 similar samples on MalwareBazaar
TLSH 28F4B026F2D1583BD1732A7C9D5B53A4A83A7E103F2998462BF42D4C5F387913A39387
Reporter oppimaniac
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
91
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-27 07:35:28 UTC
File Type:
PE (Exe)
Extracted files:
40
AV detection:
27 of 30 (90.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

FormBook

Executable exe e3e778591453a54d2cbd3ab1bb4ecb69ed94222f248aac24a95fb951fc6101f0

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
SHELL_APIManipulates System Shellshell32.dll::ShellExecuteExA
shell32.dll::ShellExecuteA
shell32.dll::SHGetFileInfoA
WIN32_PROCESS_APICan Create Process and Threadskernel32.dll::CloseHandle
kernel32.dll::CreateThread
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryExA
kernel32.dll::LoadLibraryA
kernel32.dll::GetSystemInfo
kernel32.dll::GetStartupInfoA
kernel32.dll::GetDiskFreeSpaceA
kernel32.dll::GetCommandLineA
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateFileA
kernel32.dll::FindFirstFileA
version.dll::GetFileVersionInfoSizeA
version.dll::GetFileVersionInfoA
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegOpenKeyExA
advapi32.dll::RegQueryValueExA
WIN_USER_APIPerforms GUI Actionsuser32.dll::ActivateKeyboardLayout
user32.dll::CreateMenu
user32.dll::FindWindowA
user32.dll::PeekMessageA
user32.dll::CreateWindowExA

Comments