MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0a01299cae838e8920ce78f846e94890d3a08619316aacfe34f9deb0b364d69c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 15
| SHA256 hash: | 0a01299cae838e8920ce78f846e94890d3a08619316aacfe34f9deb0b364d69c |
|---|---|
| SHA3-384 hash: | 2e527e7908157e4a36bd63bc908431e7100b1d9074fa327c7e3a6ee9a3c20b9fc15312914dfda5d888dc995efc2e0ed3 |
| SHA1 hash: | ede3e1794545f9039260be883334a70e245abd38 |
| MD5 hash: | 7b44bcbc214c78715d0f590b1635dfa9 |
| humanhash: | mountain-bluebird-uncle-emma |
| File name: | 7b44bcbc214c78715d0f590b1635dfa9.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 552'635 bytes |
| First seen: | 2024-08-20 11:19:16 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 099c0646ea7282d232219f8807883be0 (476 x Formbook, 210 x Loki, 107 x AgentTesla) |
| ssdeep | 12288:oHANG3RciXGMbmAumsfKRsOB0IcvnO1gq6NgXH:oHxc2mVfV5IcvnO1R+g3 |
| Threatray | 3'461 similar samples on MalwareBazaar |
| TLSH | T1ACC4E0A7B4040441E9892630DF76EEB00F665EAD99F0940D9BE8BC2377FF4CB552942B |
| TrID | 92.7% (.EXE) NSIS - Nullsoft Scriptable Install System (846567/2/133) 3.4% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 1.1% (.EXE) Win64 Executable (generic) (10523/12/4) 0.7% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 0.5% (.EXE) Win16 NE executable (generic) (5038/12/1) |
| File icon (PE): | |
| dhash icon | f0909a9edad2e0da (6 x GuLoader, 4 x Formbook, 1 x SnakeKeylogger) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
4f64511b423d79682dfad8f6b516516d32e801f0031f07b7e3c6c19798a64b95
6846492babd6809fcbf6d1a30ebd47db29061bc23237069ff85a86b406b1abb0
a15402c5f869a1c02421742c27dd71c2448bb037d391a6bf130be06b2f976e2f
a1d8420052bbdcaf3d318427bfe57edf5cc330fb14aaa5f4a597fac220c2a6de
cfdf477d386cab73129ac775a953d693466176d4d4854d06d580125a8f20f9e6
0d42799a7602de1d76ef3b39ceff5075b95dd1e3891332987d525a07ef5c5f0f
a632daf4953367bf3024b3e84d13b5beb03d77719cca10b155355e474b3173e3
11e5030403c99dfa27a1c41a8a3abf2408324166735b081a7db038c9a3ec357d
41e0f6ad541e5253c451b3d51976df257813e85c443ab1b863b3acf6c078b38c
0a01299cae838e8920ce78f846e94890d3a08619316aacfe34f9deb0b364d69c
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | Detect_SliverFox_String |
|---|---|
| Author: | huoji |
| Description: | Detect files is `SliverFox` malware |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_NX | Missing Non-Executable Memory Protection | critical |
| CHECK_PIE | Missing Position-Independent Executable (PIE) Protection | high |
Reviews
| ID | Capabilities | Evidence |
|---|---|---|
| COM_BASE_API | Can Download & Execute components | ole32.dll::CoCreateInstance |
| SHELL_API | Manipulates System Shell | SHELL32.dll::ShellExecuteA SHELL32.dll::SHFileOperationA SHELL32.dll::SHGetFileInfoA |
| WIN32_PROCESS_API | Can Create Process and Threads | KERNEL32.dll::CreateProcessA KERNEL32.dll::CloseHandle KERNEL32.dll::CreateThread |
| WIN_BASE_API | Uses Win Base API | KERNEL32.dll::LoadLibraryA KERNEL32.dll::LoadLibraryExA KERNEL32.dll::GetDiskFreeSpaceA KERNEL32.dll::GetCommandLineA |
| WIN_BASE_IO_API | Can Create Files | KERNEL32.dll::CopyFileA KERNEL32.dll::CreateDirectoryA KERNEL32.dll::CreateFileA KERNEL32.dll::DeleteFileA KERNEL32.dll::MoveFileA KERNEL32.dll::GetWindowsDirectoryA |
| WIN_REG_API | Can Manipulate Windows Registry | ADVAPI32.dll::RegCreateKeyExA ADVAPI32.dll::RegDeleteKeyA ADVAPI32.dll::RegOpenKeyExA ADVAPI32.dll::RegQueryValueExA ADVAPI32.dll::RegSetValueExA |
| WIN_USER_API | Performs GUI Actions | USER32.dll::AppendMenuA USER32.dll::EmptyClipboard USER32.dll::FindWindowExA USER32.dll::OpenClipboard USER32.dll::PeekMessageA USER32.dll::CreateWindowExA |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.