MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 205522a02f43a8477a1ed81ea1dff4f5b914afbc01f68ac082e5bf76d73fe8b2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 11
| SHA256 hash: | 205522a02f43a8477a1ed81ea1dff4f5b914afbc01f68ac082e5bf76d73fe8b2 |
|---|---|
| SHA3-384 hash: | befcb10a43f4ce1428fae2d65187ed3cb87acea3d553099b0ce3dcc5983b04a06bfbdbb1e40756e7b4cd9c1f7a4e1df3 |
| SHA1 hash: | bceaa61ac23166feec0ce2e659c215c4cefce507 |
| MD5 hash: | e49d68f98d7594cd39722a29e32933c6 |
| humanhash: | lactose-texas-alaska-burger |
| File name: | Estimate from Construction Materials Technologies Pty Ltd.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 554'496 bytes |
| First seen: | 2020-10-08 13:08:19 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 12288:XSivlLmcmILdT5WCjocglmY8uBvg01jL:XhLBmulnoWYr |
| Threatray | 2'535 similar samples on MalwareBazaar |
| TLSH | 1CC48C732445886EDD660A714C7941F0BAA61ECE3F53890E72AE330D0D7271763EA66F |
| Reporter | |
| Tags: | exe FormBook |
abuse_ch
Malspam distributing unidentified malware:HELO: saxamarketing.com
Sending IP: 199.217.115.34
From: Construction Materials Technologies <quickbooks@notification.intuit.com>
Subject: Quote - Estimate from Construction Materials Technologies (Pty) Ltd.
Attachment: Estimate from Construction Materials Technologies Pty Ltd.gz (contains "Estimate from Construction Materials Technologies Pty Ltd.exe")
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
37fa0d1153831bdf8c08560d18a83afc2ccede848883819536eb81497c63229f
0c3afc73b1560d5d817104a616325e9f7a825e6b0158dfa0469b423c8bfbdf64
b7f9546fa9fb928d856b69a70174d693a84c641ad193e88e48c07cdb92751e03
7843242690547cf0b4ebea118783c903b99c3a211f1775db3cf24b09fbe2454a
7538931bad1762c44d0d66ea730a3ca6c5acb18d326f3a2f5bffa1f81864354e
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | Formbook |
|---|---|
| Author: | JPCERT/CC Incident Response Group |
| Description: | detect Formbook in memory |
| Reference: | internal research |
| Rule name: | win_formbook_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | autogenerated rule brought to you by yara-signator |
| Rule name: | win_formbook_g0 |
|---|---|
| Author: | Slavo Greminger, SWITCH-CERT |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
be0041bd012c8c093497d25a0f087d04
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.