MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1265cd7cd52561d0e688f2ea1a8a9c8ed712b4f6fb82e253424f9a6cdad5d995. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments 1

SHA256 hash: 1265cd7cd52561d0e688f2ea1a8a9c8ed712b4f6fb82e253424f9a6cdad5d995
SHA3-384 hash: 4ab1f76d5217c08e41b14a6cad84447e064b0cd55b52b76bbcee4258813a870d8d91ca624c57ce11f10a7828fbf5a71c
SHA1 hash: 045d289731c1a59fddbfdcfe83557ad4b39bf1df
MD5 hash: 87df8bdd3c538665b8b0591ef28e9d21
humanhash: may-white-freddie-red
File name:SecuriteInfo.com.UDS.Trojan-Spy.Win32.Noon.gen.25193.5020
Download: download sample
Signature Formbook
File size:328'136 bytes
First seen:2021-05-19 04:05:05 UTC
Last seen:2021-05-19 05:13:52 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 099c0646ea7282d232219f8807883be0 (476 x Formbook, 210 x Loki, 107 x AgentTesla)
ssdeep 3072:wQIURTXJi7PMYvMqPDaMNpe6wG3wfufoNzeUJoCcw3O9mcIbDqsJutdwFz2fvYP8:wsNv8lNLw878cYOMD4rwRsvYNq
Threatray 5'238 similar samples on MalwareBazaar
TLSH C3648B6B34CC4AD6E0AD06711DEDFB2CBE226E153D218E2B6E95F22D583115285F313E
Reporter SecuriteInfoCom

Intelligence


File Origin
# of uploads :
2
# of downloads :
95
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
SecuriteInfo.com.UDS.Trojan-Spy.Win32.Noon.gen.25193.5020
Verdict:
Malicious activity
Analysis date:
2021-05-19 04:06:17 UTC
Tags:
installer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a file
Sending a UDP request
Unauthorized injection to a recently created process
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
92 / 100
Signature
C2 URLs / IPs found in malware configuration
Detected unpacking (changes PE section rights)
Found malware configuration
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for submitted file
Tries to detect virtualization through RDTSC time measurements
Yara detected FormBook
Behaviour
Behavior Graph:
Gathering data
Threat name:
Win32.Spyware.Noon
Status:
Malicious
First seen:
2021-05-19 02:02:28 UTC
AV detection:
3 of 47 (6.38%)
Threat level:
  2/5
Result
Malware family:
xloader
Score:
  10/10
Tags:
family:xloader loader rat
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Loads dropped DLL
Xloader Payload
Xloader
Malware Config
C2 Extraction:
http://www.cozinhablog.com/cu6s/
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
a̵c̵c̸i̵d̷e̵n̷t̴a̷l̴r̵e̷b̸e̴l̸ commented on 2021-05-19 05:01:27 UTC

============================================================
MBC behaviors list (github.com/accidentalrebel/mbcscan):
============================================================
0) [C0032.001] Data Micro-objective::CRC32::Checksum
1) [C0026.002] Data Micro-objective::XOR::Encode Data
3) [C0045] File System Micro-objective::Copy File
4) [C0046] File System Micro-objective::Create Directory
5) [C0048] File System Micro-objective::Delete Directory
6) [C0047] File System Micro-objective::Delete File
7) [C0049] File System Micro-objective::Get File Attributes
8) [C0051] File System Micro-objective::Read File
9) [C0050] File System Micro-objective::Set File Attributes
10) [C0052] File System Micro-objective::Writes File
11) [E1510] Impact::Clipboard Modification
12) [C0036.004] Operating System Micro-objective::Create Registry Key::Registry
13) [C0036.002] Operating System Micro-objective::Delete Registry Key::Registry
14) [C0036.007] Operating System Micro-objective::Delete Registry Value::Registry
15) [C0036.003] Operating System Micro-objective::Open Registry Key::Registry
16) [C0036.005] Operating System Micro-objective::Query Registry Key::Registry
17) [C0036.006] Operating System Micro-objective::Query Registry Value::Registry
18) [C0036.001] Operating System Micro-objective::Set Registry Key::Registry
19) [C0017] Process Micro-objective::Create Process
20) [C0038] Process Micro-objective::Create Thread
21) [C0018] Process Micro-objective::Terminate Process