MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 24c2781350cbe7b9de07fdd597275c2e2dde39fea4eaf007d00610044376de1f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 15


Intelligence 15 IOCs YARA 23 File information Comments

SHA256 hash: 24c2781350cbe7b9de07fdd597275c2e2dde39fea4eaf007d00610044376de1f
SHA3-384 hash: 06d042a99457cc89040ab777613287162987a6e8c5fb4f6d53f4fbd5452976c7f57a4ae7d2c0a3f7de0b83175c688aee
SHA1 hash: e89c4273faba28deadd721966fc60a8a68ca403b
MD5 hash: 54de81030fb41e854ea930a7c81f6b83
humanhash: fix-diet-mississippi-early
File name:SecuriteInfo.com.TrojanLoader.MSIL.DaVinci.Heur.10545.24748
Download: download sample
Signature Formbook
File size:694'272 bytes
First seen:2024-03-13 17:21:59 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'649 x AgentTesla, 19'454 x Formbook, 12'202 x SnakeKeylogger)
ssdeep 12288:YHwgGwdCKTk+RmjeJ731UtZVZHyp64/Go+RNeB6BQFrv02m8Buk+:4GwdCuFyq7lUtZvHyp64Me0qXJ
Threatray 3 similar samples on MalwareBazaar
TLSH T1E8E412406538AF23D5BD83F1917261908BF638BB6425F7092DC260CF396AF6DAA11F53
TrID 63.0% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
11.2% (.SCR) Windows screen saver (13097/50/3)
9.0% (.EXE) Win64 Executable (generic) (10523/12/4)
5.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
3.8% (.EXE) Win32 Executable (generic) (4504/4/1)
Reporter SecuriteInfoCom
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
475
Origin country :
FR FR
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
24c2781350cbe7b9de07fdd597275c2e2dde39fea4eaf007d00610044376de1f.exe
Verdict:
Suspicious activity
Analysis date:
2024-03-13 17:24:32 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Adding an exclusion to Microsoft Defender
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
MSIL Injector
Verdict:
Malicious
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
92 / 100
Signature
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Injects a PE file into a foreign processes
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Yara detected AntiVM3
Yara detected FormBook
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1408521 Sample: SecuriteInfo.com.TrojanLoad... Startdate: 13/03/2024 Architecture: WINDOWS Score: 92 20 Malicious sample detected (through community Yara rule) 2->20 22 Multi AV Scanner detection for submitted file 2->22 24 Yara detected FormBook 2->24 26 4 other signatures 2->26 7 SecuriteInfo.com.TrojanLoader.MSIL.DaVinci.Heur.10545.24748.exe 4 2->7         started        process3 signatures4 28 Adds a directory exclusion to Windows Defender 7->28 30 Injects a PE file into a foreign processes 7->30 10 powershell.exe 23 7->10         started        12 SecuriteInfo.com.TrojanLoader.MSIL.DaVinci.Heur.10545.24748.exe 7->12         started        process5 process6 14 WmiPrvSE.exe 10->14         started        16 conhost.exe 10->16         started        18 WerFault.exe 19 16 12->18         started       
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2024-03-13 15:11:14 UTC
File Type:
PE (.Net Exe)
Extracted files:
9
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Suspicious use of SetThreadContext
Checks computer location settings
Unpacked files
SH256 hash:
d98d93710c75552ce9d5bff0ae6ab1c1f95502324310cfd0318be6efd83a4896
MD5 hash:
bb37255de5f854b794c222c69e0a029c
SHA1 hash:
a97b28fe9bdb3c9242222dfe27ce416d2f2632ef
SH256 hash:
dddf23c8e78b081c5f1cb7cbe18b7466f91abcb7f4a0e5f6ba91b285d9346791
MD5 hash:
42395301981d9ed7a9d094ee83c78b70
SHA1 hash:
6c68437332c59fdc3a45df351cb6aa07d709ab47
SH256 hash:
c10c9b0882bac6f788f48b4dabe3291b14e639e650f2b9fcb0bc174ac92ae02b
MD5 hash:
7c7fb6daa78beb69128991ff893143ed
SHA1 hash:
c01bb99984b12b84129db80eae1d5d8341a358e2
SH256 hash:
ac9479fee61233626a45acaae0db16902a59d9f2073779c81b785fbba2e46b82
MD5 hash:
28e59e8b2c9751bc433ac9d7889ff873
SHA1 hash:
7e69e1906d051f66717e00e404a19f14fe0ab21f
SH256 hash:
e6b25e7250cdd5f75ec51545b9105bdf202d880898ec9c4cd75c131d9262e1d0
MD5 hash:
0c01ecddd3880a71ee7b626706813efb
SHA1 hash:
37eecee4ca36bb984095155b6a3a2e640f452e0d
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
e97625746360793777ab1d7dc32d4259332c7f3c81a441eb7850234aabfdf23d
5cab510258dae33c18cd23924daefd7501ff7203ba9816704a2b0ca66508c56f
0aebca1aecba63aa6205a90f467e4c6ffb86efd928bdd7e3d7ba453eca8ffc00
af69e50524ba63cfcbaaa2de4d15434743f2f34239ad34228e4eadde55bbeae6
fc8a9c0e62e7e7df74d0d59bed35d720aca7a47021f8c55bc1bcc32fb3075a94
6a7c6a729d852d01d74832748b6571bafaefcd0bd12aced32e4fa88166af8817
9ca2b5622a36e207a1d11a748f637920d4f96d88e34b2dede0840bcce07f5788
4b39adbf8d3a4e2a5793014b4af4a4cb98d3a71c4a565dd20dc3a69928a84c72
037c7011889e43ee7456a314fbfebcc3d7abbd96aa509a34babc0d832681013f
664db26a69e4b1efb10289189887c35558bf7ca966eed02f97e523fef83f1205
fcac462e70c7009c1c8dbc15dffea8e0b8ff141fc94a95581c306d995a2748d2
2b3114ee08fb8a720819c749b1cbd68f5c8119073f34db958849b1d3eb1bdd9d
bdd4ba2aedeeebd368997ceb0a5c0372959181a08f1e5aefb4b437609630bdff
f4cefaa54034c3cfd9bf223520e2a5876ec1d161cb4a68b6b7d3e9fe892b087f
24c2781350cbe7b9de07fdd597275c2e2dde39fea4eaf007d00610044376de1f
f79941668c6679c1f5770816ce7b68a2d518caa7d7218299f7a1908cf338297a
88737e32661e323c947753fd7c8ca1abd141e7c917dc12730a5d6634be6847fc
ea8e979a9bf6fe2e8af35cedb5d639091629a2ce626f1339c7a0a48e3cc39ba2
8ecf19dca7047302513a5818cb79bcd6c4b278f92904ed1fcc7f559c72e0de7a
e9ea79b9129140cbc495137ea1c09c0686d5a5d33c43cfd1217ee2aead41237d
312783562439afa6feb4e46153051e5af5e7c15f139bac75a25afd38caaed1ce
1875aee9f50a8e2389a125c2f77998685ee0d7d7d20b7d3f1ecadf841564e654
7a20de1b4a4cd2e217be33f3297d2b38d7e7fd69ee216d58f0400160e41ff3ea
55571fa3b9f2d9a7d71c1154aac73dc3826860eaa7be12cceda40d4566ea4ce1
242ea95cfe48aaa9fca35f358ac8431cd1bd730b1ff95543a4f9d9e768115d3f
d5a0f85ffb3ee297f57ffb96a77288de2a564c5cb337b5c6c7b01da8e36545d6
285dbc8362784007c8e0a4060f48bea0818563129e5c824d34393f2c714c1a9e
ffb10236e7f77499f767e9e703c9e0a6d0b3777ff6ae06e63724f23fc7e3ea29
610224addb5b75398e556cf9780a9ad26891fa1754cbda12637903560d15dba4
959d491cbde6323dc2bf7c377a9c1e0940b988f51a3efcc0f1bd526cc0d210b4
5ca87353c4d37e66f76875a46235208796dd620ad3cb7cebc6b5e66be55b2913
d5df0f56b1209034e89de624a5ad652d070035c15f24d6b3559c34540c725b9c
590f27260d772e044dd8819c937658e02ab15050b3bf6cc3dd054c808ed3c201
89e60f82a944bb55032e88f1dff4d13242129b0bf2a3ae39aeb93904a665d4f4
8d4a83437f552b1737a406be9d9b5e4f4919a1adbf8e13f8261411d7390d604f
201cffe8bf2c15a804167c67d2a095ff655829395cb54b5c3d3c4d038efde920
224ff64e59a1b2bf45b02cb11df4f0556de0bbeb7929d37828de1c1bb8ff8772
ab5501455d6b22f8e26dd31ed265879ca6c0d3c6677793738f49360628792991
5f7a3e9cfebdb626e00af8155e710df40bab01bc5b8fcf77163cda86d23cae3d
86ea784bb86a20eff340835a0cf862d6a4a5b2309ead2c00006b65c2d8f5ebd1
0c18d82d30c57f4eb7b9ce8f7bb367b114718b077b7fd7bd838f57399c5921d0
ee591c0b19049eff4e311686e26557c5da6818438c319ed6f0df6274a56c5e05
48b161190679dd4c509ab89a5dfdfac0bdf6b557c0d77d9e4f698acf057acef8
a1a5145381a87900950867d3e6632aaf89fdedb9c898bf44fd7efbea077ab224
800fc3595eab3d807dd8199ba639d1bc6c0bdf5f1f47cf3a95c649b61056bc1c
4850a766fab45d5947075658d9c6bbf4b970f0d05b082c1472b93d9a7fa3d093
f2338f728798c729c37b627d5d75bf8691a482a4b9cc4b67ae5a5ba4b45b0c85
3d648905c51d97e4998f5e24312dae37f77dbe94279847f6a124894790881082
SH256 hash:
24c2781350cbe7b9de07fdd597275c2e2dde39fea4eaf007d00610044376de1f
MD5 hash:
54de81030fb41e854ea930a7c81f6b83
SHA1 hash:
e89c4273faba28deadd721966fc60a8a68ca403b
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AgentTesla_DIFF_Common_Strings_01
Author:schmidtsz
Description:Identify partial Agent Tesla strings
Rule name:DebuggerCheck__GlobalFlags
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Active
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Formbook
Author:kevoreilly
Description:Formbook Payload
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:maldoc_getEIP_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Windows_Trojan_Formbook
Author:@malgamy12
Rule name:Windows_Trojan_Formbook_1112e116
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/formbook-adopts-cab-less-approach
Rule name:win_formbook_w0
Author:@malgamy12

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments