MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 15f6f8d6c24f2a386dfa3331b075e27e0541fcee3af502a28c49e9c3b7441d4b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 13


Intelligence 13 IOCs YARA 2 File information Comments

SHA256 hash: 15f6f8d6c24f2a386dfa3331b075e27e0541fcee3af502a28c49e9c3b7441d4b
SHA3-384 hash: d6849134bc8ee719d3ab9ec1c7ea0d03ac9692279c6b872e13b8ae628e3b51358f906dae7395d9d6bc126dc5528600d5
SHA1 hash: 666680a4c59f4c42181d6b29397f0b54cf16661d
MD5 hash: 64a4b03c8d5ab791fda907772644b993
humanhash: gee-social-echo-florida
File name:DHL Delivery Documents.exe
Download: download sample
Signature Formbook
File size:743'424 bytes
First seen:2022-04-08 09:31:16 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger)
ssdeep 12288:o5uXEw4OdZ/R5TE0ZQhympYNe3CSFcn1o0pfW9HIX0SqkIzaPS+orkzbsadStYg5:DTEDhOnekW9IX0S/80S++k/n0aH3kGpw
Threatray 14'773 similar samples on MalwareBazaar
TLSH T1A7F4F15CF721B8EED81BC3B5B9706C26BF10A427965E456B904352AD8C1C443CEA7CEB
Reporter abuse_ch
Tags:DHL exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
183
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
formbook
ID:
1
File name:
DHL Delivery Documents.exe
Verdict:
Malicious activity
Analysis date:
2022-04-08 22:11:15 UTC
Tags:
formbook trojan stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Sending a custom TCP request
Launching a process
Launching cmd.exe command interpreter
Unauthorized injection to a system process
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
control.exe obfuscated packed
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Found malware configuration
Initial sample is a PE file and has a suspicious name
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
PE file contains section with special chars
PE file has nameless sections
Queues an APC in another process (thread injection)
Sample uses process hollowing technique
Self deletion via cmd delete
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Yara detected AntiVM3
Yara detected FormBook
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 605734 Sample: DHL Delivery Documents.exe Startdate: 08/04/2022 Architecture: WINDOWS Score: 100 36 www.highwaymenstickers.com 2->36 38 www.moleculairescent.com 2->38 40 shops.myshopify.com 2->40 44 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->44 46 Multi AV Scanner detection for domain / URL 2->46 48 Found malware configuration 2->48 50 14 other signatures 2->50 11 DHL Delivery Documents.exe 3 2->11         started        signatures3 process4 file5 28 C:\Users\...\DHL Delivery Documents.exe.log, ASCII 11->28 dropped 14 DHL Delivery Documents.exe 11->14         started        process6 signatures7 60 Modifies the context of a thread in another process (thread injection) 14->60 62 Maps a DLL or memory area into another process 14->62 64 Sample uses process hollowing technique 14->64 66 Queues an APC in another process (thread injection) 14->66 17 explorer.exe 14->17 injected process8 dnsIp9 30 buchler-immo.com 81.169.145.93, 49816, 80 STRATOSTRATOAGDE Germany 17->30 32 www.agathejacquillat.com 79.170.40.4, 49798, 80 GD-EMEA-DC-LD5GB United Kingdom 17->32 34 8 other IPs or domains 17->34 42 System process connects to network (likely due to code injection or exploit) 17->42 21 cscript.exe 17->21         started        signatures10 process11 signatures12 52 Self deletion via cmd delete 21->52 54 Modifies the context of a thread in another process (thread injection) 21->54 56 Maps a DLL or memory area into another process 21->56 58 Tries to detect virtualization through RDTSC time measurements 21->58 24 cmd.exe 1 21->24         started        process13 process14 26 conhost.exe 24->26         started       
Threat name:
Win32.Spyware.Noon
Status:
Malicious
First seen:
2022-04-08 09:32:07 UTC
File Type:
PE (.Net Exe)
Extracted files:
11
AV detection:
19 of 41 (46.34%)
Threat level:
  2/5
Result
Malware family:
xloader
Score:
  10/10
Tags:
family:xloader campaign:ok4e loader rat
Behaviour
Suspicious use of WriteProcessMemory
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Program crash
Suspicious use of SetThreadContext
Blocklisted process makes network request
Xloader Payload
Xloader
Unpacked files
SH256 hash:
6f1bdc148ef8191b2feba9973d53788f383ed9e900895e2185996d9c19807b68
MD5 hash:
b77200269aff132c89ff539252190aff
SHA1 hash:
6016d8604b778f66023cadda92d0f955a56e47f5
Detections:
win_formbook_g0 win_formbook_auto
Parent samples :
48b9bb721ab60fa9fc9feecef6c4e513b4bfc2049c72f187bdea927b20aa3898
3e302b7a1b7d9862a5917a03e08205d8016cb2974566725e16926f4e6cff9c6b
0d491a763b98f614a83b7f8c5fea244501316466da80f3387032e8554fbfefb7
0c592b998752863f20e1d0e4b452ea6d9e1bebcd7194260c4a2ae1840b248318
5b8f4d48c5ed6fad8b945600c34a6e0ca41d0a5b41ed8e52f58f1aa2eed82dd7
053bb1a8c163bd121cd9b9a48f1c9667e7c0937fc50da002a0e15790e815a22d
54cc6af930a87396d79412dc99f2104387f359a4893cfa1b5466fcb808eb30a6
6fb859be1f19ec66d032758b38eade770aedc4f60b2341284ff407647980852b
b6f17a86e93f3c7794b4d735b18057bc6f964a2cd97975114d106c75c06d4568
722ec64df826265e6c801596ada5cff67ea31d529d20b9ecf8d877a9af7d2149
0bbc4ad8c179c0f2e1c2a1b501f1baa3637bdf27d598c63f30f739d3e58a0004
0035f11e3163f3a2dd3d94c08beefc7d1c2fa17abc210526ddc336bbc8d10d0d
9f085df3f1da75ba799ca984603fe267f891be8e6ac24c52b907cc97e6879467
752debbb1c582ce0e31ce252082dcbb65ae5df035cd761a2529a5aff4611f5c5
040cff08509278893e4e0bf0f731a1a1797d2518610135500e03c02fc8b6e7d1
cdd772fd3c4299298b8e84472d0b2c20531885a77cfad41495d56337c567a88b
dc36fc5d4c108d54e3a2a4a5309f87093f484e4bc928158c0a749417052f6f56
2905097f141a3b1cd4ecfab488bdf6b776cf6e714c36e28e201ecde6389f558a
ec2fec19768b0cb797d08cdc4c1de72faeab5550bde249633e6fbb5c00771199
8c1de309eaa9d9a48f92587f93f88304ae1aa48aee62e7ede11893f1ca61775e
15f6f8d6c24f2a386dfa3331b075e27e0541fcee3af502a28c49e9c3b7441d4b
a7ac2a87561e223d21c2a885ba2622ad249008a8f889dafa8ba4b953ed659905
c8c237f5b4d985add596774c36156c4fa9ee54d44ec544528c64b1c10bd163ea
1e5c0d7950b6161f50a7a58d2874df7548e95a5ce4ed81f9c4c6485c064731e9
e11a2c34058934a35cdfe1008e77d46a817ce145edb106e620584179db7bc285
fb918766cda71e3ebc8fc418590b36351b567553f61a7388b92637138b8bae3e
922445967d9f0fd85ea49040191928dd0ac2e34c35eec90411e7c5bc227b21eb
SH256 hash:
9f3a8e0697cffb3690eec5d01f46818f5f8072563012b18b4078cfe2cb21e14a
MD5 hash:
2103575654f13490462d21f431dd6432
SHA1 hash:
f0fa83c47182932af5cf19e83fbb1cc98d608c73
SH256 hash:
793f03f973d08ffe4aa0c0399e4f78cf1f47ae17ae550220284943e60778329f
MD5 hash:
a280a14353fe0a20ee3fbbcf689c6b97
SHA1 hash:
c57428c98e064498da3aad2c397249567fb563c8
SH256 hash:
e11871df824c3130e35f2c94d672404e18ebefddf3172d166f2e640ad3686c73
MD5 hash:
4379771ccd9b927712ef2505214161df
SHA1 hash:
6636b7b80e279de67c60b52277f566463afebf8e
SH256 hash:
15f6f8d6c24f2a386dfa3331b075e27e0541fcee3af502a28c49e9c3b7441d4b
MD5 hash:
64a4b03c8d5ab791fda907772644b993
SHA1 hash:
666680a4c59f4c42181d6b29397f0b54cf16661d
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe 15f6f8d6c24f2a386dfa3331b075e27e0541fcee3af502a28c49e9c3b7441d4b

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments