MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 262d23daa434a3eaf7afceeb9b9340f20c040eac7acb6732749c49f433e2e17f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 13


Intelligence 13 IOCs YARA 2 File information Comments

SHA256 hash: 262d23daa434a3eaf7afceeb9b9340f20c040eac7acb6732749c49f433e2e17f
SHA3-384 hash: 4a2044d7e9abb869e7d786772459d4746c0ce0f23cecb4f558f097658c70fbcb425086bb8a43002d02ac7b2d96c2d67e
SHA1 hash: 5ac3f4b49ff3e062f3423d8e5e0997cf99f98135
MD5 hash: 20659bb0310bc6432c8c53ee0da7c946
humanhash: comet-sink-foxtrot-bravo
File name:payment detail.exe
Download: download sample
Signature Formbook
File size:596'480 bytes
First seen:2022-06-29 20:17:46 UTC
Last seen:2022-06-30 07:52:01 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'666 x AgentTesla, 19'479 x Formbook, 12'209 x SnakeKeylogger)
ssdeep 12288:0YvJj2egMyP7CI+vauu2iNMmq9WCsq7bPjAgDtAyJu9f:H6uu1mx9FlheyS
TLSH T1DCC49D9D3A2C31EFC857C5729E989CB4E66264AF671B5113D02329DD9A0CF87DF204B2
TrID 30.2% (.EXE) Win64 Executable (generic) (10523/12/4)
18.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
14.4% (.EXE) Win16 NE executable (generic) (5038/12/1)
12.9% (.EXE) Win32 Executable (generic) (4505/5/1)
5.9% (.EXE) Win16/32 Executable Delphi generic (2072/23)
Reporter GovCERT_CH
Tags:exe FormBook xloader

Intelligence


File Origin
# of uploads :
2
# of downloads :
279
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Unauthorized injection to a recently created process
Creating a file
Сreating synchronization primitives
Launching a process
Launching cmd.exe command interpreter
Searching for synchronization primitives
Unauthorized injection to a system process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
packed rogue
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
PE file contains section with special chars
PE file has nameless sections
Performs DNS queries to domains with low reputation
Queues an APC in another process (thread injection)
Sample uses process hollowing technique
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Yara detected AntiVM3
Yara detected FormBook
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 654679 Sample: payment detail.exe Startdate: 29/06/2022 Architecture: WINDOWS Score: 100 33 www.keepitfall.com 2->33 35 www.ht5555000123.com 2->35 37 6 other IPs or domains 2->37 45 Snort IDS alert for network traffic 2->45 47 Malicious sample detected (through community Yara rule) 2->47 49 Antivirus detection for URL or domain 2->49 51 12 other signatures 2->51 11 payment detail.exe 3 2->11         started        signatures3 process4 file5 31 C:\Users\user\...\payment detail.exe.log, ASCII 11->31 dropped 61 Injects a PE file into a foreign processes 11->61 15 payment detail.exe 11->15         started        18 payment detail.exe 11->18         started        signatures6 process7 signatures8 63 Modifies the context of a thread in another process (thread injection) 15->63 65 Maps a DLL or memory area into another process 15->65 67 Sample uses process hollowing technique 15->67 69 Queues an APC in another process (thread injection) 15->69 20 explorer.exe 15->20 injected process9 dnsIp10 39 www.casewp.com 154.55.240.104, 49828, 80 COGENT-174US United States 20->39 41 www.wasserlounge.com 20->41 43 2 other IPs or domains 20->43 53 System process connects to network (likely due to code injection or exploit) 20->53 24 msdt.exe 20->24         started        signatures11 process12 signatures13 55 Modifies the context of a thread in another process (thread injection) 24->55 57 Maps a DLL or memory area into another process 24->57 59 Tries to detect virtualization through RDTSC time measurements 24->59 27 cmd.exe 1 24->27         started        process14 process15 29 conhost.exe 27->29         started       
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2022-06-29 14:52:05 UTC
File Type:
PE (.Net Exe)
Extracted files:
10
AV detection:
20 of 26 (76.92%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
formbook
Result
Malware family:
xloader
Score:
  10/10
Tags:
family:formbook family:xloader campaign:nmd2 loader persistence rat spyware stealer suricata trojan
Behaviour
Gathers network information
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Drops file in Program Files directory
Suspicious use of SetThreadContext
Deletes itself
Reads user/profile data of web browsers
Checks computer location settings
Adds policy Run key to start application
Xloader Payload
Formbook
Xloader
suricata: ET MALWARE FormBook CnC Checkin (GET)
suricata: ET MALWARE FormBook CnC Checkin (POST) M2
Unpacked files
SH256 hash:
8f8d821f9b816b475e1c9f34db67d3a4e7c5e6d0a4dfc462ef67248ad0a5afea
MD5 hash:
af41a321878299875b7d3763ebe91b20
SHA1 hash:
34697adff8512e91fdcaf9f22abdf424fbc5f4b9
Detections:
win_formbook_g0 win_formbook_auto XLoader
Parent samples :
9f604ab9c007da7543c828be85e5508af9541fb039bb9e90283f84b0d6aebdc4
717ab44671da707ee8ad9e5c6e4ade18d6f47841e65a6bd0cebd56c8c1533fcf
0b8058097313b63fec637d226daa0af6abb9f68bb1d0ccb9edb39876453617be
8586e05ff7d2269e9495e76725cc561d433cb771d6af6581ae5fdcf7b8b571d9
085917245898b3d25910807103748a579b389697e79bdceb82b043f66b86a130
f361a889ba650230da217b06b0c41ced6d025c461f29e854583548461dc84668
a28592058ed33d1a46f187fb5fcccbd89b9167ed84c85755aaa8d2d3ceca9003
313566736f3e85c4303541ddf83b100fd80fefe20702cc7c3e10789942127a9e
1722230b243c441e5498ccd145a7a4f8fa00b97d2a22cb20007efb227cce45a9
6f6be5365b28b8c8bd13b442ea0c7f18bbd6cc92d1a6cea7cece4702bcc8cac9
32b04a3fc9feb6bd1b63e6ec096f2cfa0a78f07f86cb08c64f4a24ec5325c0b1
04326067e70a15d7b5139282361d1cd355b2a6c057ca7ac0e901f0a88b139aa7
970e64f4f7b5a8dd1e1f5df8470f372d27585cff9f75a0d3a596427d261bf809
262d23daa434a3eaf7afceeb9b9340f20c040eac7acb6732749c49f433e2e17f
4f4e5e5550b40c160b4dfa9f399b558d2d96ffdf49cc0c81a86a6b3942f1fd94
901b8ec8346c9ec07fb34f17b2eb18f45d6197b0cbb1d7bad6b1cf23ff0cbab1
4863509ff407e4a6389305b5555bc804aa5df9b67290feeb1e36bf68f40696e1
535fb5862370192d9fa74321ef99aa8fe36aaf56689f48411fc7c14b9c984533
f085387dd3ad9b5e949cdb80752a76f1fab4fe66c7eee38a353d0f80b80df7b7
3064b62e720763ef00cfa548424cf74aef8034f8ddc420084519b27b4e1f271e
a5c83c27bf821b97478d7a7cf53e3de83e15fb3a87ff7bdb793afc6ee8d0f64d
7833781bd55b3c69a30841ca9d10a7d8d0bc15b9fbf5cc4d81eee5e2f9591000
1b382c7ca0e34e9e294ea85dfdb722ccfe0b828ecbf5c665a605af31d7277e6f
3fa0d321b17bc7af7e98f723135bf7c3151107f4572f1a41c68f933c488c77b3
SH256 hash:
87be41590f7304501d380fc62c7d27e72b28fb58b2123662b4c05f73afebcb24
MD5 hash:
13001cf2a465e456be567411f0569ad7
SHA1 hash:
cc8a00bb0ae0c3fd22da6852ad83fbfea8002e87
SH256 hash:
79823e47436e129def4fba8ee225347a05b7bb27477fb1cc8be6dc9e9ce75696
MD5 hash:
39f524c1ab0eb76dfd79b2852e5e8c39
SHA1 hash:
428018e1701006744e34480b0029982a76d8a57d
SH256 hash:
262d23daa434a3eaf7afceeb9b9340f20c040eac7acb6732749c49f433e2e17f
MD5 hash:
20659bb0310bc6432c8c53ee0da7c946
SHA1 hash:
5ac3f4b49ff3e062f3423d8e5e0997cf99f98135
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe 262d23daa434a3eaf7afceeb9b9340f20c040eac7acb6732749c49f433e2e17f

(this sample)

  
Dropped by
xloader
  
Delivery method
Distributed via e-mail attachment

Comments