MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 173e2bfd47ffa24de5fbfe5e293d5d0e76d7be2f69709f2098422d24d2421a77. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 15


Intelligence 15 IOCs YARA 7 File information Comments

SHA256 hash: 173e2bfd47ffa24de5fbfe5e293d5d0e76d7be2f69709f2098422d24d2421a77
SHA3-384 hash: 0fc246e83d4fa6b7038ba9d789619f83fab36ed85c2790d38d5e57bc98af97adb6e443655a78223e4cfa1f15b6db7f4f
SHA1 hash: c89a55f6a9f898290e81c5b91a48616eab801dc7
MD5 hash: 21aa7fa7eca0a285e99093c03fa50981
humanhash: oscar-wolfram-music-cup
File name:SecuriteInfo.com.Trojan.PackedNET.2698.18590.6852
Download: download sample
Signature Formbook
File size:664'072 bytes
First seen:2024-02-22 12:41:23 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'661 x AgentTesla, 19'474 x Formbook, 12'208 x SnakeKeylogger)
ssdeep 12288:Vws/RY5Ujd53LlvPsmu3eesjKxy01pGEe9V/ia6J2H4xlS2hoNF2wyskR:pgKarfMCy01pG9i3hlhhoNS
Threatray 901 similar samples on MalwareBazaar
TLSH T1DBE4237137989B71E66D1FF23529C512EBB1A02A7D32E78C2ED8A0C711C2BE54714E0B
TrID 63.0% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
11.2% (.SCR) Windows screen saver (13097/50/3)
9.0% (.EXE) Win64 Executable (generic) (10523/12/4)
5.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
3.8% (.EXE) Win32 Executable (generic) (4504/4/1)
Reporter SecuriteInfoCom
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
322
Origin country :
FR FR
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade overlay packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook, PureLog Stealer
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Found malware configuration
Injects a PE file into a foreign processes
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Tries to detect virtualization through RDTSC time measurements
Yara detected AntiVM3
Yara detected FormBook
Yara detected PureLog Stealer
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Trojan.Taskun
Status:
Malicious
First seen:
2024-02-22 10:29:40 UTC
File Type:
PE (.Net Exe)
Extracted files:
10
AV detection:
18 of 24 (75.00%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook campaign:cz30 rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Formbook payload
Formbook
Unpacked files
SH256 hash:
f65ce16ee371858f7f379b2b570014c2583792d768e9f501a1aedf258cb1ea78
MD5 hash:
c71b1896d6c2373f06eaaed49bb61860
SHA1 hash:
fb5daf2dfdc97a1cdc0f2bedb2249ce3fb53ea95
SH256 hash:
cbf850de6b8cc91ee4e74d4dbdd766625b16d879aea24b652dbbe2c6515e3f68
MD5 hash:
7c3050fa273a71f8971ede53989c6c94
SHA1 hash:
ae55b59f5157b8a9b1e26c79ace60c93e468926f
SH256 hash:
d70e4033db330c128a0fed627f2bb0faee896f86112e6f4170adefc9a580dff1
MD5 hash:
ec2a8446d2bb3f4a4bd67c0fab01fd3d
SHA1 hash:
72adabdb9c297f0cad6708f40b90f90c894e387c
SH256 hash:
ec592062c41d26d7046ab135fbabaf80e69900ba940ca654261cda17109f8769
MD5 hash:
09f7fb78314d30bf7c69d72caa9da978
SHA1 hash:
5536e0f86fe6e36f11e5ba03a8f559675dd82f30
SH256 hash:
173e2bfd47ffa24de5fbfe5e293d5d0e76d7be2f69709f2098422d24d2421a77
MD5 hash:
21aa7fa7eca0a285e99093c03fa50981
SHA1 hash:
c89a55f6a9f898290e81c5b91a48616eab801dc7
Detections:
INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AgentTesla_DIFF_Common_Strings_01
Author:schmidtsz
Description:Identify partial Agent Tesla strings
Rule name:INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438
Author:ditekSHen
Description:Detects executables signed with stolen, revoked or invalid certificates
Rule name:NET
Author:malware-lu
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_imphash
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments