MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ed458c466676594e5feaee03cbd536339dc28c162a266daaccbeaaa7afdb887. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: 0ed458c466676594e5feaee03cbd536339dc28c162a266daaccbeaaa7afdb887
SHA3-384 hash: 157d5035f2c31c7c9a08e00ca6e7a3221e1f92c16041fd0c9a150795545b22530fb2c82ab23d435aaddcbbcfbcf68fb0
SHA1 hash: 6b3d06ca8cae93194c6d46cf775c862bf9e632d4
MD5 hash: 3521f6a638e39ddf9b83abfbe5e062d6
humanhash: queen-two-kentucky-november
File name:SecuriteInfo.com.W32.Injector.AIC.genEldorado.3990.32484
Download: download sample
Signature Formbook
File size:235'257 bytes
First seen:2021-05-20 23:11:47 UTC
Last seen:2021-05-21 12:53:35 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 099c0646ea7282d232219f8807883be0 (476 x Formbook, 210 x Loki, 107 x AgentTesla)
ssdeep 6144:Ds980XuNY9s4j4NyE37j6hwD4QvcqBR6kMJgUPqARKou:y80eNYs4MMELj6hZQRB0FiwKr
Threatray 5'249 similar samples on MalwareBazaar
TLSH 5F341274E8F0C8A3D4056A321D72CB46CB35E72C1715116F2B610FBE79637B2A99328A
Reporter SecuriteInfoCom
Tags:FormBook

Intelligence


File Origin
# of uploads :
3
# of downloads :
116
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
SecuriteInfo.com.W32.Injector.AIC.genEldorado.3990.32484
Verdict:
Malicious activity
Analysis date:
2021-05-21 00:38:24 UTC
Tags:
installer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a file
Sending a UDP request
Modifying a system executable file
Unauthorized injection to a recently created process
Creating a window
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
C2 URLs / IPs found in malware configuration
Detected unpacking (changes PE section rights)
Found malware configuration
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Tries to detect virtualization through RDTSC time measurements
Yara detected FormBook
Behaviour
Behavior Graph:
Threat name:
Win32.Spyware.Noon
Status:
Malicious
First seen:
2021-05-20 21:36:23 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  2/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Loads dropped DLL
Formbook Payload
Formbook
Malware Config
C2 Extraction:
http://www.knighttechinca.com/dxe/
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments