MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 28eb771845a5d55d5b5549cbc0b8b45fcc928e3e2e18013d7e3c84c592f86578. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments 1

SHA256 hash: 28eb771845a5d55d5b5549cbc0b8b45fcc928e3e2e18013d7e3c84c592f86578
SHA3-384 hash: a4d1d2f2205a2302d7a798b94dce0d22ca2485cc6fdd1996a0fe44b544f2e805305daf43ab6fa37a36cfcacd9282c22d
SHA1 hash: 80ffba92565cc1ad32bdea2d22ec230bd18e81ba
MD5 hash: 042403c1a171697a0cda836a3d3c309a
humanhash: shade-carbon-two-lactose
File name:SecuriteInfo.com.generic.ml.2703.19971
Download: download sample
Signature Formbook
File size:217'689 bytes
First seen:2021-05-18 01:06:22 UTC
Last seen:2021-05-18 05:36:21 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 099c0646ea7282d232219f8807883be0 (476 x Formbook, 210 x Loki, 107 x AgentTesla)
ssdeep 3072:LQIURTXJvgjMgrcJJvBhu+wZveiFVamB6DunfqQy2TvQPtVPd47eVK+x5u00xO7U:LsBgGXGebmEKnfqQlkdMQ70G7VDeBn
Threatray 5'192 similar samples on MalwareBazaar
TLSH CD24123DA6E4DC37C41A16B12572E5B4FABA77050901829B73655FAE5E70083CB2B0EF
Reporter SecuriteInfoCom
Tags:FormBook

Intelligence


File Origin
# of uploads :
3
# of downloads :
169
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
SecuriteInfo.com.generic.ml.2703.19971
Verdict:
Malicious activity
Analysis date:
2021-05-18 01:25:25 UTC
Tags:
installer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a file
Sending a custom TCP request
Modifying a system executable file
Unauthorized injection to a recently created process
Sending a UDP request
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
92 / 100
Signature
C2 URLs / IPs found in malware configuration
Detected unpacking (changes PE section rights)
Found malware configuration
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for domain / URL
Tries to detect virtualization through RDTSC time measurements
Yara detected FormBook
Behaviour
Behavior Graph:
Threat name:
Win32.Spyware.Noon
Status:
Malicious
First seen:
2021-05-18 00:49:18 UTC
AV detection:
3 of 47 (6.38%)
Threat level:
  2/5
Result
Malware family:
xloader
Score:
  10/10
Tags:
family:xloader loader rat
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Loads dropped DLL
Xloader Payload
Xloader
Malware Config
C2 Extraction:
http://www.onyxcomputing.com/u8nw/
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
a̵c̵c̸i̵d̷e̵n̷t̴a̷l̴r̵e̷b̸e̴l̸ commented on 2021-05-18 02:04:50 UTC

============================================================
MBC behaviors list (github.com/accidentalrebel/mbcscan):
============================================================
0) [C0032.001] Data Micro-objective::CRC32::Checksum
1) [C0026.002] Data Micro-objective::XOR::Encode Data
3) [C0045] File System Micro-objective::Copy File
4) [C0046] File System Micro-objective::Create Directory
5) [C0048] File System Micro-objective::Delete Directory
6) [C0047] File System Micro-objective::Delete File
7) [C0049] File System Micro-objective::Get File Attributes
8) [C0051] File System Micro-objective::Read File
9) [C0050] File System Micro-objective::Set File Attributes
10) [C0052] File System Micro-objective::Writes File
11) [E1510] Impact::Clipboard Modification
12) [C0036.004] Operating System Micro-objective::Create Registry Key::Registry
13) [C0036.002] Operating System Micro-objective::Delete Registry Key::Registry
14) [C0036.007] Operating System Micro-objective::Delete Registry Value::Registry
15) [C0036.003] Operating System Micro-objective::Open Registry Key::Registry
16) [C0036.005] Operating System Micro-objective::Query Registry Key::Registry
17) [C0036.006] Operating System Micro-objective::Query Registry Value::Registry
18) [C0036.001] Operating System Micro-objective::Set Registry Key::Registry
19) [C0017] Process Micro-objective::Create Process
20) [C0038] Process Micro-objective::Create Thread
21) [C0018] Process Micro-objective::Terminate Process