MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3dc50d4418b7d64dcbb6c364e49b19cf8bc06ed7d2cc6566658ab3bac8a8c347. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 3dc50d4418b7d64dcbb6c364e49b19cf8bc06ed7d2cc6566658ab3bac8a8c347
SHA3-384 hash: e9918f9620e90b16c2e552383e1eda762d930cca4fde865dfd173efb563b2b9522eed0303febd597b60989ebd5b61ebe
SHA1 hash: e30a5debea7fe4da21f71ffe1fbfcbedbdb50fcc
MD5 hash: 874473429570a727e95e1015ca23b188
humanhash: maryland-kitten-violet-alanine
File name:3dc50d4418b7d64dcbb6c364e49b19cf8bc06ed7d2cc6566658ab3bac8a8c347
Download: download sample
Signature Formbook
File size:273'408 bytes
First seen:2020-11-10 10:59:24 UTC
Last seen:2024-07-24 13:21:41 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 192058f2810235b0efae8de0f7b55742 (4 x Formbook)
ssdeep 6144:Bx/xeffMs81Yn9MCCxtTAfwgwn12d7r1o9nlzlgS+0o:jxO91GIwgwn1K6Blq35
Threatray 2'883 similar samples on MalwareBazaar
TLSH 6A44E035B8C3C4B2C45501395515DBA0DB7EBD712AB8EC83F35A3AAD8E333D26619283
Reporter seifreed
Tags:FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Unauthorized injection to a recently created process
Launching a process
Launching cmd.exe command interpreter
DNS request
Sending an HTTP GET request
Unauthorized injection to a system process
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Spyware.Stelega
Status:
Malicious
First seen:
2020-11-10 11:01:14 UTC
AV detection:
25 of 29 (86.21%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
3dc50d4418b7d64dcbb6c364e49b19cf8bc06ed7d2cc6566658ab3bac8a8c347
MD5 hash:
874473429570a727e95e1015ca23b188
SHA1 hash:
e30a5debea7fe4da21f71ffe1fbfcbedbdb50fcc
SH256 hash:
810e49cfa84ab5921f3ac51aa5f0bba28dea8c300b209bbd226116333fbb3e8a
MD5 hash:
e3c2de6d08fcdd86b7f9ab0bdeeae64e
SHA1 hash:
763241fc9d5c586889bb038ac85e5ef8cbd29211
Detections:
win_formbook_g0 win_formbook_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments