MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 313566736f3e85c4303541ddf83b100fd80fefe20702cc7c3e10789942127a9e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 14


Intelligence 14 IOCs YARA 2 File information Comments

SHA256 hash: 313566736f3e85c4303541ddf83b100fd80fefe20702cc7c3e10789942127a9e
SHA3-384 hash: 14b6bfa7f069d20cd478f9548380700bf185b2fad8dabf1aecaae8d0f22a59633e42d65dfac88ca45ad8f65bd51b13cc
SHA1 hash: 967751d740b50b1e8fc4c186243f2318e2e22251
MD5 hash: f8587437ed4fb8e204c08395314297c2
humanhash: alabama-finch-kansas-lithium
File name:Arrival notice.exe
Download: download sample
Signature Formbook
File size:664'064 bytes
First seen:2022-06-22 17:24:20 UTC
Last seen:2022-06-22 19:48:11 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'665 x AgentTesla, 19'478 x Formbook, 12'208 x SnakeKeylogger)
ssdeep 12288:gysBsKXTK3x+FIJhSn49PCnGjx06K2gw6Od8P:gysBsr6Ik2Vx068Od8
TLSH T16EE4AE211A0E267FDEFDCB786521445087F86D6DFD22C52D3FE6208E15E8B06E0A67B1
TrID 64.2% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
11.5% (.SCR) Windows screen saver (13101/52/3)
9.2% (.EXE) Win64 Executable (generic) (10523/12/4)
5.7% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
3.9% (.EXE) Win32 Executable (generic) (4505/5/1)
Reporter GovCERT_CH
Tags:exe FormBook xloader

Intelligence


File Origin
# of uploads :
3
# of downloads :
275
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a custom TCP request
Creating a window
Сreating synchronization primitives
Searching for synchronization primitives
Launching a process
Unauthorized injection to a recently created process
Creating a file
Launching cmd.exe command interpreter
Unauthorized injection to a system process
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Sample uses process hollowing technique
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Yara detected AntiVM3
Yara detected FormBook
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2022-06-22 16:26:19 UTC
File Type:
PE (.Net Exe)
Extracted files:
9
AV detection:
22 of 26 (84.62%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
formbook
Result
Malware family:
xloader
Score:
  10/10
Tags:
family:formbook family:xloader campaign:nmd2 loader persistence rat spyware stealer suricata trojan
Behaviour
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
System policy modification
Drops file in Program Files directory
Suspicious use of SetThreadContext
Checks computer location settings
Reads user/profile data of web browsers
Executes dropped EXE
Adds policy Run key to start application
Xloader Payload
Formbook
Xloader
suricata: ET MALWARE FormBook CnC Checkin (GET)
suricata: ET MALWARE FormBook CnC Checkin (POST) M2
Unpacked files
SH256 hash:
8f8d821f9b816b475e1c9f34db67d3a4e7c5e6d0a4dfc462ef67248ad0a5afea
MD5 hash:
af41a321878299875b7d3763ebe91b20
SHA1 hash:
34697adff8512e91fdcaf9f22abdf424fbc5f4b9
Detections:
win_formbook_g0 win_formbook_auto XLoader
Parent samples :
9f604ab9c007da7543c828be85e5508af9541fb039bb9e90283f84b0d6aebdc4
717ab44671da707ee8ad9e5c6e4ade18d6f47841e65a6bd0cebd56c8c1533fcf
0b8058097313b63fec637d226daa0af6abb9f68bb1d0ccb9edb39876453617be
8586e05ff7d2269e9495e76725cc561d433cb771d6af6581ae5fdcf7b8b571d9
085917245898b3d25910807103748a579b389697e79bdceb82b043f66b86a130
f361a889ba650230da217b06b0c41ced6d025c461f29e854583548461dc84668
a28592058ed33d1a46f187fb5fcccbd89b9167ed84c85755aaa8d2d3ceca9003
313566736f3e85c4303541ddf83b100fd80fefe20702cc7c3e10789942127a9e
1722230b243c441e5498ccd145a7a4f8fa00b97d2a22cb20007efb227cce45a9
6f6be5365b28b8c8bd13b442ea0c7f18bbd6cc92d1a6cea7cece4702bcc8cac9
32b04a3fc9feb6bd1b63e6ec096f2cfa0a78f07f86cb08c64f4a24ec5325c0b1
04326067e70a15d7b5139282361d1cd355b2a6c057ca7ac0e901f0a88b139aa7
970e64f4f7b5a8dd1e1f5df8470f372d27585cff9f75a0d3a596427d261bf809
262d23daa434a3eaf7afceeb9b9340f20c040eac7acb6732749c49f433e2e17f
4f4e5e5550b40c160b4dfa9f399b558d2d96ffdf49cc0c81a86a6b3942f1fd94
901b8ec8346c9ec07fb34f17b2eb18f45d6197b0cbb1d7bad6b1cf23ff0cbab1
4863509ff407e4a6389305b5555bc804aa5df9b67290feeb1e36bf68f40696e1
535fb5862370192d9fa74321ef99aa8fe36aaf56689f48411fc7c14b9c984533
f085387dd3ad9b5e949cdb80752a76f1fab4fe66c7eee38a353d0f80b80df7b7
3064b62e720763ef00cfa548424cf74aef8034f8ddc420084519b27b4e1f271e
a5c83c27bf821b97478d7a7cf53e3de83e15fb3a87ff7bdb793afc6ee8d0f64d
7833781bd55b3c69a30841ca9d10a7d8d0bc15b9fbf5cc4d81eee5e2f9591000
1b382c7ca0e34e9e294ea85dfdb722ccfe0b828ecbf5c665a605af31d7277e6f
3fa0d321b17bc7af7e98f723135bf7c3151107f4572f1a41c68f933c488c77b3
SH256 hash:
79823e47436e129def4fba8ee225347a05b7bb27477fb1cc8be6dc9e9ce75696
MD5 hash:
39f524c1ab0eb76dfd79b2852e5e8c39
SHA1 hash:
428018e1701006744e34480b0029982a76d8a57d
SH256 hash:
fba817e9e70d516970baa26899428d655e23c9345567165c2a160f482108fa4d
MD5 hash:
1a7325e5dd05f9a71969fa00db917531
SHA1 hash:
3873c760f8ac20a9347dc5d5f2ed2f804b787a08
SH256 hash:
313566736f3e85c4303541ddf83b100fd80fefe20702cc7c3e10789942127a9e
MD5 hash:
f8587437ed4fb8e204c08395314297c2
SHA1 hash:
967751d740b50b1e8fc4c186243f2318e2e22251
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe 313566736f3e85c4303541ddf83b100fd80fefe20702cc7c3e10789942127a9e

(this sample)

  
Dropped by
xloader
  
Delivery method
Distributed via e-mail attachment

Comments