MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 413bf66fb3f4c507d5e04fcd975056619d5874af3b92fa59eb9db52d18e2928b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 14


Intelligence 14 IOCs YARA 20 File information Comments

SHA256 hash: 413bf66fb3f4c507d5e04fcd975056619d5874af3b92fa59eb9db52d18e2928b
SHA3-384 hash: 6d15c10f8965478ac01b2ca19e58d8b33c7fd69f4b75061efb15038fe07025c493b8ebc92af0d3947430597b959b011a
SHA1 hash: 285801b501260e75c3209ae12d28f18a2b1f58d9
MD5 hash: a1232480db8e2d0251e25aa560451012
humanhash: iowa-five-berlin-august
File name:r6WrUcBg7ToYT8S.exe
Download: download sample
Signature Formbook
File size:793'096 bytes
First seen:2024-04-04 05:13:57 UTC
Last seen:2024-04-04 06:17:49 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'740 x AgentTesla, 19'599 x Formbook, 12'241 x SnakeKeylogger)
ssdeep 12288:70GPu5sb+o7nJ/IzjIE+vFq803U/bdzkITh08MgRxLWvyEhEoqg/BkSaZoAlYBvY:70GPl+o7nJKjaEk/JzxSARxLWaQEoqc4
TLSH T15BF4BFED7650B6EFC867C9768AA42C64EB2174B7530FD203A06706A89D0DA97CF141F3
TrID 67.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
9.7% (.EXE) Win64 Executable (generic) (10523/12/4)
6.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.1% (.EXE) Win32 Executable (generic) (4504/4/1)
Reporter lowmal3
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
305
Origin country :
DE DE
Vendor Threat Intelligence
Malware family:
formbook
ID:
1
File name:
413bf66fb3f4c507d5e04fcd975056619d5874af3b92fa59eb9db52d18e2928b.exe
Verdict:
Malicious activity
Analysis date:
2024-04-04 05:18:58 UTC
Tags:
formbook xloader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
overlay packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Deletes itself after installation
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found direct / indirect Syscall (likely to bypass EDR)
Injects a PE file into a foreign processes
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Queues an APC in another process (thread injection)
Snort IDS alert for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Yara detected AntiVM3
Yara detected FormBook
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1419882 Sample: r6WrUcBg7ToYT8S.exe Startdate: 04/04/2024 Architecture: WINDOWS Score: 100 28 www.eh28mf3cdv.xyz 2->28 30 xiaoyue.zhuangkou.com 2->30 32 12 other IPs or domains 2->32 42 Snort IDS alert for network traffic 2->42 44 Malicious sample detected (through community Yara rule) 2->44 46 Multi AV Scanner detection for submitted file 2->46 50 4 other signatures 2->50 10 r6WrUcBg7ToYT8S.exe 3 2->10         started        signatures3 48 Performs DNS queries to domains with low reputation 28->48 process4 signatures5 62 Detected unpacking (changes PE section rights) 10->62 64 Detected unpacking (overwrites its own PE header) 10->64 66 Injects a PE file into a foreign processes 10->66 13 r6WrUcBg7ToYT8S.exe 10->13         started        process6 signatures7 68 Maps a DLL or memory area into another process 13->68 16 NeIHelIDmLSzUju.exe 13->16 injected process8 signatures9 40 Found direct / indirect Syscall (likely to bypass EDR) 16->40 19 isoburn.exe 13 16->19         started        process10 signatures11 52 Tries to steal Mail credentials (via file / registry access) 19->52 54 Tries to harvest and steal browser information (history, passwords, etc) 19->54 56 Deletes itself after installation 19->56 58 3 other signatures 19->58 22 NeIHelIDmLSzUju.exe 19->22 injected 26 firefox.exe 19->26         started        process12 dnsIp13 34 www.quickstart.design 46.28.106.211, 49716, 80 WEDOSCZ Czech Republic 22->34 36 elenagilherrero.com 84.32.84.32, 49726, 49727, 49728 NTT-LT-ASLT Lithuania 22->36 38 7 other IPs or domains 22->38 60 Found direct / indirect Syscall (likely to bypass EDR) 22->60 signatures14
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2024-04-03 16:39:25 UTC
File Type:
PE (.Net Exe)
Extracted files:
9
AV detection:
23 of 37 (62.16%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
formbook
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of UnmapMainImage
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Unpacked files
SH256 hash:
a59378ca16dc6ffbc07d8716889f4cb3a8d769068a9e58fd288f99afb9e66552
MD5 hash:
059c1b7332fc4ff2f21a2ef20fa093f1
SHA1 hash:
a41f80e695241d25971b7f26b7cd90e3f9d983ea
SH256 hash:
1ae5ee514b7d71a3b8d5fe7182c901b0529acbc013fa4e25dcfccfeff75732f6
MD5 hash:
6c46476fb561195ddf67ae3c0861cb27
SHA1 hash:
280e9938a135fcb522e181ffb1211f73c28d871d
SH256 hash:
71dab87ac5b7b80468ef8ccb16b74b39cc862b7fb9a6e430e4cd7e375dbe6c27
MD5 hash:
df9e546ebe70f8307bc8e6ad3aa08f0f
SHA1 hash:
d649fef8643e0a0c870519420522d5ca23dd7382
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
498b4a265a27f8362fea4fcf15a184b220475c891249c892406030eb3b245c00
79e473fb7f021d7b394ac013c2abcca1a094a918b6f2edb48c0ed18d7b3b7460
53ffe79bd4c176d257a5b0a5a147ecaa522356d3ea80ab83dc6f8c55bd545c08
2d4255b15429696714b3c6e55077d3d95cfbc71a746406385cc4ba5025eb6a45
da6f3f1f642c13d2b7bf4c86e2686c5e1b606dbe0838423998c15742940545e9
a48b8a6ca726f32569a7e2041803898a902437ee7724da53accfb6dc52fa8a87
c94be0d3693316359c2e48e43baf51dff4f0b8d5efab6050962a09ef46ead4dc
24798002b81be4c9b37539e1abea61cccb014cbd427fe1a27d6822e1ffedc7d9
9fc2770fbd67c9b6f9f244ac6ac0fa8810c3d50e08c7d77b332bf1447ab77fab
2c8008052d15b5a7a61808357f2085226f7f9bc9619bb2040c27024a6423b9d2
1ba9c4dfbdfb55f6588c8887006f2851716eb6e53eb2bd1bccd591aa9e182da7
413bf66fb3f4c507d5e04fcd975056619d5874af3b92fa59eb9db52d18e2928b
38f97adf003d63f84a6c5bc35c9d9096901e7292e763bd9fbeabdafa1aa5fa78
12f1562e82415f8f320bc830dc6047870ea78ceb7e827af394dbe428d8ebc930
450160aa7afe149bc82992b2dd8f44fdaf64fcaec24d7b9c8522251f538a7636
859876f4be1e8206802a3468eb52a143bf5bc15724c0b66b70d98edd79c06a08
f48dfafeefb4b36315d6b8f987df1026d29c102bd24703a08cc4d4d41a483505
5408e8b840c407984e92034c26e937b1785c5f4b6762b14f2f7a31cec4d982d8
74a07ee3f0060987ebcb09e588ac1299a9d2a19e2f4139385f7880c229e2c8cf
da1903e676a7609f931a23ef7a653af4c1be9ef5242a80bdca67cb076d372bfd
cf432fc47407df80dcf984cf5d8d1a6aaed7c8c2a4c9b3a76627b4194bb9c782
73c44dbb7ece4e2fee17409d2d0ebcc82a77dd86c7ab0c9da9d8453cab59fbcc
c161b936b669673a3441c19755270abebe800846e8a01be9477e634d91b44635
191239a61c70ba900694d294a164f4a162b84d11672871fbb5389967bbf52c7e
ff2ae4fd71daa1a98edd5f88b743a5daa5fb29f70b87dee08fec25313a3640f1
554b40336bad24df88cbde544cdf20d553d02ce7fee5dab9a82318d7c21471e0
bc5f1294caaee05297ad1547f2f6ec4a309c16f7caf906f21038269d72f54957
15df84ca3a0c112b7ab461d6ee7603fcec8e24da91d4042d3ab018f87530b6ac
32aeea1990475960922b9a0bbda5a7edc864a3c70e4b8c5e84b16e269ea6fc7c
677f5939951053c165cdff92b6fa68d53748365869a978b77c2a501a46d1c4c8
67a792fced715c64610c55d8c01b16d66080c10004ed572e664c324468afdd7d
02a5ec5d9037cdd26b3f1ade8ea4028fbd0947284bfb3d7649e065d22db0ef91
704427aa451d261a1a92a6e834a1ee2be50971a012e711f9f660403904a9622c
6fd8e845cfa1bf8f809f0f372c2d4e955c6a3b6c0e88fb8f474a2645f587ecf0
9f6eb9b6b3bf92a75e32208dd51ce6307fa5ccdae27f02f0c7e2712544c2c04f
8506e0fdcf9ce49bd939a62bacd3e4d1af3522d72e660382684b1e4d1bb8e6b7
8fb359ccf3a3b6a0eff8204f9ee27c2dc41b3270721716192a7ef9253453b59b
8f53280f0b7807f08cf03152768d385200db1ad864b256fd9e7decbc846b05a2
70517116e2400906af6125849ac27b66159a45f6f1782178351e82bfe5ba205c
1711d935991cb37bd208dec08aefb47cf049baa4aa465d3188feccd8d330e72d
b1a574a7a0aad03e9f0a8470fd53013c565e67461ff21fc79e1bb6205974adb1
190504e991bb8bb608cf87db9ee7c7549999a17970251490ce85282f85cb49aa
f4eaa74eb268a58cff6f5d37607758bd49cc00af060da799857ae10cfd59efb2
8243f0400ffe13c6d332e0ab70af833ae44e446a5419f411a5c2586c86c51277
2a0a27371b6f4d355c3264fcc668d8a0fe1af7ebb8b19dca3b5cdf20a3282d65
f486a970c3228b346008eb169500d373560ea047084818b77357ba68bfa960af
8f02ecb26530c0a13b7f00020ebca144fc271fe36a5caaba1f4b3270e8e0023c
bd7f924e17174165e42ee077f973be26f07c6653ff33951ff9c53fb7cc833bae
1dea51f5680fedc83402ccb9401ae907c9493ef8625a76fe6f6cd9f475021e6a
a433dfdb99b293b73898ac05be0fbf6baa9d79976655b0c51ba5a5a0066a2632
b1f7d2a6fee6eb162c9e154b565ee6fe95c6e03fa15bef35d8c14663b844087c
da86da7fc086aa8262222feed9f4cd4df4c4538e77d90a7c160b1c794f298b92
ef8ad9042176ddf7dae5199f0135c2efabf224a45ac52f0ebc054b7ee9806c04
efb67364fa543ceddc607094c10c4b71f3baac1f45de5c2c759c489f97a64ec2
47cf473f0a0c146e5ae4a37b987c297be41d82af40d53e4dc750ca9b66fa7ea6
9d1f9f7012962df24baa3c3ac0816333abecf2a433953f68dab7e7673fac59aa
4b4c3585bbf95af33fac18ae92347069e2b732626cc6c7984ebfef92ea0a89b0
31fea186e7379793d1d9b37d2a981ed0fb05d40ee7d62e227eac695106ebbe2f
d23bd1fbaae83547ec6aba06ad8b4eef5119bd4a0f66634a6726b6ccd5dc3c78
dd14afafbf11a0251a0c5c56b3ef8b0be205cd4ed5d70fe77df7fdc90a039a4a
36ea8608df9b009caf566d4309832531c532d9eaf5c28b5b1657acf54c471209
95e4dd6cc5a341f4440a113e0a832175aa2f5baafd9c7483255a18088e1c2764
44ba13a119d19891a586d95310d8a51e9440fe2c1659b397d5795ecab37e3eeb
SH256 hash:
bc39c3ba2ef220300f37e0ccffd84e387eaa28c831859c3588cdfdeec243b0c5
MD5 hash:
e4c53cafec45a303e00d4d7702b02822
SHA1 hash:
bf21964cd02330655a1eb04fb83ece35899977bf
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
5d7b1224c77b4413e49156de8a050fdcfbfc5cc75b3d73c13abd67475ddabd3c
70f27cc87397701a73835625b0ee8caf3ef97b506554f2a7f65c2c08afd264f7
f7e3d289131a067c332064bd6f6cb7d336f0fb0476af14eea1d1b1a7127493a9
c1ecdc617db839e561aa5318e3458ce0f0db30386f8b9cb5586314b2e75a8a7d
54a4891d6753b4acaa07bb6c01aebcb44a0140ffc05ccdc53785a74365969585
2843aae844d0b90a78597dc383828ef6d67ecc6e3d5e689ca4567bc823383b72
994e690703864150e91ac5f4d3cd5264d45e2ecc182424bd5285cbf935cb855d
37c4f4f899e08371042e4b4cc03b87297989ad424c62228a7a50293f2ea7de22
921d900f4ba05b2c93f5ca8076861ea60f698eecc36e4fd6013a415592e3272d
82048072a8cf203444037aa1f037b305437c7a273811a2287f2a5addb2cbcb41
c7a16881f8c69d16a9b0bdcbfdd5c4aada81eba19521d1c03ee7f6005f7d6629
78b15621d0319e8b7a105e1aa9a1927fb434bfce29e2a4f56051f552e393f08a
12c7ec6f047ebf12cb9f142bb71fb0de5a61de79286776440b5814c94d93e2e4
9f70d8532d4c8655671ecb52609c6ba9e8e34dc0b08cbb92ca795b59a9bdc862
ce213fe45b524d85486c2f3956e17a333b2d8ecbf1d73078bf56014cc1c7702c
31462fecb3ea50e9d958b14e99acf10b91ef3207224f82a90c6b15f0f1d1285a
7f610fb90140292d4a5dfcb4bd0e691833307a428714f6381fefaa6c39bc5bed
94279f693b7bb1c21594d96e572ebc15e6aea416816b03d677a3875ebb84a99b
413bf66fb3f4c507d5e04fcd975056619d5874af3b92fa59eb9db52d18e2928b
8243f0400ffe13c6d332e0ab70af833ae44e446a5419f411a5c2586c86c51277
9d4ba0d30577e0398c95e01ff42e2ea2f2f02dcb50ff3202f6077de094e7a439
46c5c413b31c08c49b03d6de4ddb926863d66a7d0b39b7b30cb340d2cb963ad0
cd00f31be2b7bb08d5e499cbe39d3ab9d5aac66ba0a5e5ffc3e97bd9cc598fc1
8ab205dc4d6f7c232cf9e2047a6abf4b2bb6425258cefeaf9b05e922c8229c6a
32b7561a0ed879b965b01f99cf9cd249f533104462bbec8ff65a4607f61d75ec
d302ca49fbe8a59c391e8de2ba44683dbff2e9b97fd136b9dea96f4354defb62
3edd3fe6434d631459584bfef13f646c14866e7d99121a3067d10f1e330b28e6
18f2d604285e3f9987eb47ae56cda190d11ae271a5ac05f0413b2c988ae241e1
5702612caa2cfd626ce28bb1e173d884d5314e0922bca28d979e7bf5158441e2
SH256 hash:
0da795b0dfe80951a75284171f298f697f20c4a14fc340aba8c1379f51954ad7
MD5 hash:
fe4cda0709a9dcc15760c2b6694fec17
SHA1 hash:
86f3444112ef5b421cfa397565120ec7b38ba81a
SH256 hash:
413bf66fb3f4c507d5e04fcd975056619d5874af3b92fa59eb9db52d18e2928b
MD5 hash:
a1232480db8e2d0251e25aa560451012
SHA1 hash:
285801b501260e75c3209ae12d28f18a2b1f58d9
Detections:
INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__GlobalFlags
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Active
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438
Author:ditekSHen
Description:Detects executables signed with stolen, revoked or invalid certificates
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:maldoc_getEIP_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_imphash
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe 413bf66fb3f4c507d5e04fcd975056619d5874af3b92fa59eb9db52d18e2928b

(this sample)

  
Delivery method
Distributed via e-mail attachment

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments