MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0638b1723d45eb9fbbf4db0428aeb59b08da4082779c361ae881445ef35bb6d4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 0638b1723d45eb9fbbf4db0428aeb59b08da4082779c361ae881445ef35bb6d4
SHA3-384 hash: 7d9f0bc4a4fb196388bde4b7403943b30a82c3665dee564bdc92446b23ad8ae567db6c2501913f135c76afca3b0339f3
SHA1 hash: 10ff1580fb137006d2e396ee9432ff4a84b409b7
MD5 hash: 9d4c81c16699da96cacc73cabaaf9fb4
humanhash: washington-east-sweet-river
File name:SecuriteInfo.com.Trojan.GenericKD.43466730.30129.29543
Download: download sample
Signature Formbook
File size:294'912 bytes
First seen:2020-07-10 17:43:59 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'666 x AgentTesla, 19'479 x Formbook, 12'209 x SnakeKeylogger)
ssdeep 6144:VBZTnj2tYxnyY0roUHrrgd3AXa3CUuQzeUO3OMx:Vfna6yBroUQd3ka3VShvx
Threatray 5'116 similar samples on MalwareBazaar
TLSH 9454F119338AC32AD96C0435C4E7223813F57F476A73EA56AFCCB288BF413879951B56
Reporter SecuriteInfoCom
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
103
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Launching a process
Launching cmd.exe command interpreter
Possible injection to a system process
Deleting of the original file
Threat name:
ByteCode-MSIL.Spyware.Noon
Status:
Malicious
First seen:
2020-07-10 09:02:06 UTC
AV detection:
24 of 29 (82.76%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: EnumeratesProcesses
Program crash
Suspicious use of SetThreadContext
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Formbook

Executable exe 0638b1723d45eb9fbbf4db0428aeb59b08da4082779c361ae881445ef35bb6d4

(this sample)

  
Delivery method
Distributed via web download

Comments