MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 085917245898b3d25910807103748a579b389697e79bdceb82b043f66b86a130. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 14


Intelligence 14 IOCs YARA 4 File information Comments

SHA256 hash: 085917245898b3d25910807103748a579b389697e79bdceb82b043f66b86a130
SHA3-384 hash: 27bc29218d33cea0f12b5c7ca4a1b46c3c223baffeaba42d31ac39f4336343ffb3129683c294d51a997a91d0207218e8
SHA1 hash: edf38c0c4eaa77d865f25ea92fd9e09168893228
MD5 hash: d880e2de89f81c41584300562970fb92
humanhash: seventeen-batman-utah-xray
File name:Catalog.exe
Download: download sample
Signature Formbook
File size:901'120 bytes
First seen:2022-06-21 11:29:40 UTC
Last seen:2022-06-21 14:17:53 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'666 x AgentTesla, 19'479 x Formbook, 12'208 x SnakeKeylogger)
ssdeep 12288:9N52iNPf+B85FrQa0sgnFuK++JUxtESTZKNPl8Ii9D5wZ4qjdQ0IqhnizLSiGJi5:J1B+B85FhI7zxSTMxlqXB
TLSH T1CA153AAC365C75DEC86BC579CAA81C68EAA0747FD31B4147A027059D9E0CAC7EF244F2
TrID 64.2% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
11.5% (.SCR) Windows screen saver (13101/52/3)
9.2% (.EXE) Win64 Executable (generic) (10523/12/4)
5.7% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
3.9% (.EXE) Win32 Executable (generic) (4505/5/1)
Reporter GovCERT_CH
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
3
# of downloads :
290
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Unauthorized injection to a recently created process
Creating a file
Сreating synchronization primitives
Launching a process
Launching cmd.exe command interpreter
Searching for synchronization primitives
Reading critical registry keys
DNS request
Sending an HTTP GET request
Unauthorized injection to a system process
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Queues an APC in another process (thread injection)
Sample uses process hollowing technique
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Yara detected AntiVM3
Yara detected FormBook
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 649549 Sample: Catalog.exe Startdate: 21/06/2022 Architecture: WINDOWS Score: 100 36 www.brisashopping.com 2->36 38 shops.myshopify.com 2->38 46 Snort IDS alert for network traffic 2->46 48 Malicious sample detected (through community Yara rule) 2->48 50 Antivirus detection for URL or domain 2->50 52 6 other signatures 2->52 11 Catalog.exe 3 2->11         started        signatures3 process4 file5 34 C:\Users\user\AppData\...\Catalog.exe.log, ASCII 11->34 dropped 68 Tries to detect virtualization through RDTSC time measurements 11->68 15 Catalog.exe 11->15         started        signatures6 process7 signatures8 70 Modifies the context of a thread in another process (thread injection) 15->70 72 Maps a DLL or memory area into another process 15->72 74 Sample uses process hollowing technique 15->74 76 Queues an APC in another process (thread injection) 15->76 18 explorer.exe 1 15->18 injected process9 dnsIp10 40 www.shipin62.com 162.213.253.133, 49757, 80 NAMECHEAP-NETUS United States 18->40 42 www.5ibnn.com 38.40.243.203, 49767, 49768, 49769 COGENT-174US United States 18->42 44 4 other IPs or domains 18->44 54 System process connects to network (likely due to code injection or exploit) 18->54 56 Performs DNS queries to domains with low reputation 18->56 22 cmmon32.exe 1 12 18->22         started        signatures11 process12 signatures13 58 Tries to steal Mail credentials (via file / registry access) 22->58 60 Tries to harvest and steal browser information (history, passwords, etc) 22->60 62 Modifies the context of a thread in another process (thread injection) 22->62 64 2 other signatures 22->64 25 cmd.exe 2 22->25         started        28 cmd.exe 1 22->28         started        process14 signatures15 66 Tries to harvest and steal browser information (history, passwords, etc) 25->66 30 conhost.exe 25->30         started        32 conhost.exe 28->32         started        process16
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2022-06-21 05:04:15 UTC
File Type:
PE (.Net Exe)
Extracted files:
22
AV detection:
20 of 26 (76.92%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
formbook
Result
Malware family:
xloader
Score:
  10/10
Tags:
family:formbook family:xloader campaign:nmd2 loader persistence rat spyware stealer suricata trojan
Behaviour
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Drops file in Program Files directory
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Deletes itself
Reads user/profile data of web browsers
Xloader Payload
Formbook
Xloader
suricata: ET MALWARE FormBook CnC Checkin (GET)
suricata: ET MALWARE FormBook CnC Checkin (POST) M2
Unpacked files
SH256 hash:
8f8d821f9b816b475e1c9f34db67d3a4e7c5e6d0a4dfc462ef67248ad0a5afea
MD5 hash:
af41a321878299875b7d3763ebe91b20
SHA1 hash:
34697adff8512e91fdcaf9f22abdf424fbc5f4b9
Detections:
win_formbook_g0 win_formbook_auto
Parent samples :
9f604ab9c007da7543c828be85e5508af9541fb039bb9e90283f84b0d6aebdc4
717ab44671da707ee8ad9e5c6e4ade18d6f47841e65a6bd0cebd56c8c1533fcf
0b8058097313b63fec637d226daa0af6abb9f68bb1d0ccb9edb39876453617be
8586e05ff7d2269e9495e76725cc561d433cb771d6af6581ae5fdcf7b8b571d9
085917245898b3d25910807103748a579b389697e79bdceb82b043f66b86a130
f361a889ba650230da217b06b0c41ced6d025c461f29e854583548461dc84668
a28592058ed33d1a46f187fb5fcccbd89b9167ed84c85755aaa8d2d3ceca9003
313566736f3e85c4303541ddf83b100fd80fefe20702cc7c3e10789942127a9e
1722230b243c441e5498ccd145a7a4f8fa00b97d2a22cb20007efb227cce45a9
6f6be5365b28b8c8bd13b442ea0c7f18bbd6cc92d1a6cea7cece4702bcc8cac9
32b04a3fc9feb6bd1b63e6ec096f2cfa0a78f07f86cb08c64f4a24ec5325c0b1
04326067e70a15d7b5139282361d1cd355b2a6c057ca7ac0e901f0a88b139aa7
970e64f4f7b5a8dd1e1f5df8470f372d27585cff9f75a0d3a596427d261bf809
262d23daa434a3eaf7afceeb9b9340f20c040eac7acb6732749c49f433e2e17f
4f4e5e5550b40c160b4dfa9f399b558d2d96ffdf49cc0c81a86a6b3942f1fd94
901b8ec8346c9ec07fb34f17b2eb18f45d6197b0cbb1d7bad6b1cf23ff0cbab1
4863509ff407e4a6389305b5555bc804aa5df9b67290feeb1e36bf68f40696e1
535fb5862370192d9fa74321ef99aa8fe36aaf56689f48411fc7c14b9c984533
f085387dd3ad9b5e949cdb80752a76f1fab4fe66c7eee38a353d0f80b80df7b7
3064b62e720763ef00cfa548424cf74aef8034f8ddc420084519b27b4e1f271e
a5c83c27bf821b97478d7a7cf53e3de83e15fb3a87ff7bdb793afc6ee8d0f64d
7833781bd55b3c69a30841ca9d10a7d8d0bc15b9fbf5cc4d81eee5e2f9591000
1b382c7ca0e34e9e294ea85dfdb722ccfe0b828ecbf5c665a605af31d7277e6f
3fa0d321b17bc7af7e98f723135bf7c3151107f4572f1a41c68f933c488c77b3
SH256 hash:
f034d79c31e9e3ca760aa3f4ec9a00e8a2418dcf1d4be3cb1d436d5516baaae6
MD5 hash:
6dcb75c3a2360e2aae004665f8da61cb
SHA1 hash:
a5c65331d389f1e2b201890b53a1984e04f9b8cc
SH256 hash:
79823e47436e129def4fba8ee225347a05b7bb27477fb1cc8be6dc9e9ce75696
MD5 hash:
39f524c1ab0eb76dfd79b2852e5e8c39
SHA1 hash:
428018e1701006744e34480b0029982a76d8a57d
SH256 hash:
085917245898b3d25910807103748a579b389697e79bdceb82b043f66b86a130
MD5 hash:
d880e2de89f81c41584300562970fb92
SHA1 hash:
edf38c0c4eaa77d865f25ea92fd9e09168893228
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:exploit_any_poppopret
Author:Jeff White [karttoon@gmail.com] @noottrak
Description:Identify POP -> POP -> RET opcodes for quick ROP Gadget creation in target binaries.
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe 085917245898b3d25910807103748a579b389697e79bdceb82b043f66b86a130

(this sample)

  
Dropped by
formbook
  
Delivery method
Distributed via e-mail attachment

Comments