MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0c32394238d4d1a1865110e6f226475422a241176c28f909f114204bf9af9a92. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 15
| SHA256 hash: | 0c32394238d4d1a1865110e6f226475422a241176c28f909f114204bf9af9a92 |
|---|---|
| SHA3-384 hash: | b336c425b94244977f85d4861652c19e415bb5f2daa8a028a0de5290a77937a6879aa65476840bfc99c81c177cc60ca5 |
| SHA1 hash: | 28925de0cf9d51eda64675b2a65ccce827281992 |
| MD5 hash: | 88c859493ca347915350b2926078ef29 |
| humanhash: | tango-undress-illinois-spaghetti |
| File name: | copia de pago.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 1'106'944 bytes |
| First seen: | 2022-08-15 06:55:32 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 05a9d8c66fbf9bfc3e87bc3c4fdb70c1 (3 x DBatLoader, 1 x Formbook) |
| ssdeep | 12288:Si7F6Nplegmje3ETxMN+lw+wZXDBehk4nSz7eIa3fg3yVqKoSV3f4zjlJ:hZ6RmjeUONOkpdQk4nSzViVqKoSq |
| TLSH | T17C359E26B1F7EC32C25784BBEF02E564C89D7D09BE7CF48527A42B9E2E71D604458293 |
| TrID | 28.5% (.SCR) Windows screen saver (13101/52/3) 22.9% (.EXE) Win64 Executable (generic) (10523/12/4) 14.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 9.8% (.EXE) Win32 Executable (generic) (4505/5/1) 6.5% (.MZP) WinArchiver Mountable compressed Archive (3000/1) |
| File icon (PE): | |
| dhash icon | b2b0aca6a6baf66a (4 x RemcosRAT, 4 x DBatLoader, 1 x Formbook) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
# of uploads :
1
# of downloads :
243
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
formbook
ID:
1
File name:
copia de pago.exe
Verdict:
Malicious activity
Analysis date:
2022-08-15 07:02:41 UTC
Tags:
formbook trojan stealer
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Detection:
n/a
Result
Verdict:
Malware
Maliciousness:
Behaviour
Сreating synchronization primitives
Creating a window
Sending a custom TCP request
DNS request
Creating a file
Launching cmd.exe command interpreter
Creating a process with a hidden window
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Unauthorized injection to a system process
Result
Malware family:
n/a
Score:
6/10
Tags:
n/a
Behaviour
MalwareBazaar
CheckScreenResolution
CheckCmdLine
Verdict:
Likely Malicious
Threat level:
7.5/10
Confidence:
100%
Tags:
keylogger overlay
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Verdict:
Malicious
Result
Threat name:
DBatLoader, FormBook
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Creates a thread in another existing process (thread injection)
Injects a PE file into a foreign processes
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Tries to detect virtualization through RDTSC time measurements
Writes to foreign memory regions
Yara detected DBatLoader
Yara detected FormBook
Yara detected UAC Bypass using ComputerDefaults
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.FormBook
Status:
Malicious
First seen:
2022-08-10 10:57:51 UTC
File Type:
PE (Exe)
Extracted files:
38
AV detection:
23 of 26 (88.46%)
Threat level:
5/5
Detection(s):
Suspicious file
Verdict:
malicious
Label(s):
formbook
Result
Malware family:
xloader
Score:
10/10
Tags:
family:formbook family:modiloader family:xloader campaign:uj3c loader persistence rat spyware stealer trojan
Behaviour
Modifies Internet Explorer settings
Modifies system certificate store
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Program Files directory
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Reads user/profile data of web browsers
Executes dropped EXE
Xloader payload
Formbook
ModiLoader, DBatLoader
Xloader
Unpacked files
SH256 hash:
6e4aba5f91f4d01295db6a25820bccf96e982c11dc19eac820ec094e8bc5b5b2
MD5 hash:
32cd4b21204a9e867088e41a0be8f6aa
SHA1 hash:
21f622535ca5ed8c0670382c420d380ba4a41799
Detections:
win_dbatloader_g1
Parent samples :
925e3fe8b8f4fa60dcfc261154c3fc8a6d296efcdb83ab1a18e710fa150090f1
7d5c7b03dcc7496b6dfb7f5726b3901d48da7ed3dd8e6d171db278e7ba9902b0
8043ea1eec1337542f54a3da01248f048588f43c2f5a434d425775dbb3ddd6b3
6b8b620534b94530ba467af917e0365640b83b1edd8a39eaa00ebf441e2e34c0
d09e0e3cdb3fa52dcea7852176dc97aac0741e85b22bd088fd0bf0633e3f3bbb
0454c0078d232502c16596fb561e698d11c2d68c1905d68a9578385a6a116a00
bc061c3fc38da5c64b98ca941334021a3588891eed56ba0458f5f3ca6b364081
c7046054dfa14ba59f91b14d7039a7d4bff88e62cb0b9bfaf6b3eb247662d5ce
9e58ee070798a5d3826b827e575d87746ffc1c10c1d07240263b35cf95a9f449
8b7641fa594fce9205916ac35de0c043177580e9469770f5e39adf0a72b858c4
da94505a95c11c751468743c7eb6cef882f99c6c5ad4ca0b24b4c3e36d0ea11c
e0b0ea6e18a229592ade98b150d52359b60a7169fc60952e4b5e098ce83a563a
ccf73ee5de39b84ab80990fc250259b3262abe80c2ed84c4284f78d05b0f5e4e
6a147da6ac0eec13aeaf08e385f27f58132562980c1ff628f4a4dc98ed70e202
efe38e24a3e9e5e0b6728cd3c25e36b51dee90ec0587b908a03335cf0f6757cb
3752b7276189f276a42e2ee99480c513f8a57554991644a98c7460671ec9d3c8
c830a445d79d79573e7da5f3a94fe72aa74d07fbcbb84d759915461202be06d8
bb51ea0bd2ae770fb729c3e84f1dd896e65312768893412fec620847a98cd8b5
a1ab4430d2f436338e690327acc1869f2d0717d63093281337c33c6b99c602f9
0c32394238d4d1a1865110e6f226475422a241176c28f909f114204bf9af9a92
3366a4efc3ab34464c6372c24a2d10c4919cab1d75223f4d7ab9d03299f68ed7
58bbb797b31decdd5f9d260a27fc96728c8151753b7533263f692c9ea8f0c349
4637f2930df07d5ed81ccc672ca39782c5ec2d8e77e9aba269128986a2fda5ea
81b969f8c2a9ced7707abce96338c925995da376e96841727982c59362f0eb30
7d5c7b03dcc7496b6dfb7f5726b3901d48da7ed3dd8e6d171db278e7ba9902b0
8043ea1eec1337542f54a3da01248f048588f43c2f5a434d425775dbb3ddd6b3
6b8b620534b94530ba467af917e0365640b83b1edd8a39eaa00ebf441e2e34c0
d09e0e3cdb3fa52dcea7852176dc97aac0741e85b22bd088fd0bf0633e3f3bbb
0454c0078d232502c16596fb561e698d11c2d68c1905d68a9578385a6a116a00
bc061c3fc38da5c64b98ca941334021a3588891eed56ba0458f5f3ca6b364081
c7046054dfa14ba59f91b14d7039a7d4bff88e62cb0b9bfaf6b3eb247662d5ce
9e58ee070798a5d3826b827e575d87746ffc1c10c1d07240263b35cf95a9f449
8b7641fa594fce9205916ac35de0c043177580e9469770f5e39adf0a72b858c4
da94505a95c11c751468743c7eb6cef882f99c6c5ad4ca0b24b4c3e36d0ea11c
e0b0ea6e18a229592ade98b150d52359b60a7169fc60952e4b5e098ce83a563a
ccf73ee5de39b84ab80990fc250259b3262abe80c2ed84c4284f78d05b0f5e4e
6a147da6ac0eec13aeaf08e385f27f58132562980c1ff628f4a4dc98ed70e202
efe38e24a3e9e5e0b6728cd3c25e36b51dee90ec0587b908a03335cf0f6757cb
3752b7276189f276a42e2ee99480c513f8a57554991644a98c7460671ec9d3c8
c830a445d79d79573e7da5f3a94fe72aa74d07fbcbb84d759915461202be06d8
bb51ea0bd2ae770fb729c3e84f1dd896e65312768893412fec620847a98cd8b5
a1ab4430d2f436338e690327acc1869f2d0717d63093281337c33c6b99c602f9
0c32394238d4d1a1865110e6f226475422a241176c28f909f114204bf9af9a92
3366a4efc3ab34464c6372c24a2d10c4919cab1d75223f4d7ab9d03299f68ed7
58bbb797b31decdd5f9d260a27fc96728c8151753b7533263f692c9ea8f0c349
4637f2930df07d5ed81ccc672ca39782c5ec2d8e77e9aba269128986a2fda5ea
81b969f8c2a9ced7707abce96338c925995da376e96841727982c59362f0eb30
SH256 hash:
0c32394238d4d1a1865110e6f226475422a241176c28f909f114204bf9af9a92
MD5 hash:
88c859493ca347915350b2926078ef29
SHA1 hash:
28925de0cf9d51eda64675b2a65ccce827281992
Malware family:
XLoader
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.