MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 44665e986b18ac11dfc0d8226d232b436310ae04126362e26d9b59cb85b2827d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 14


Intelligence 14 IOCs YARA 3 File information Comments

SHA256 hash: 44665e986b18ac11dfc0d8226d232b436310ae04126362e26d9b59cb85b2827d
SHA3-384 hash: cc433b8489fd2ad45bf4359e80a230954e82025009a4412ed68be4224092f274e2cbe3007b9312b24521369c866c5c92
SHA1 hash: 07d05cb3ed305be4bc00100de8ce1c955c0f0971
MD5 hash: d8bcc7fec4316837552ab05d31e9c555
humanhash: colorado-seventeen-cola-paris
File name:d8bcc7fec4316837552ab05d31e9c555.exe
Download: download sample
Signature Formbook
File size:763'392 bytes
First seen:2023-04-20 05:28:49 UTC
Last seen:2023-05-13 22:49:08 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'740 x AgentTesla, 19'597 x Formbook, 12'241 x SnakeKeylogger)
ssdeep 12288:nZZAXdHMH91DzZAsMaISA2gONZnRjBoQYBV/st2dHo5StoMZU+9P2rzLuRN0o:ZZeHMd1DtABaISA25jnxs/st8Amr2rfk
Threatray 2'724 similar samples on MalwareBazaar
TLSH T18BF4E195B766E792C2683D3D42A660782FB089C7F516C939FDC8115D3F26BC91E8038B
TrID 63.0% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
11.2% (.SCR) Windows screen saver (13097/50/3)
9.0% (.EXE) Win64 Executable (generic) (10523/12/4)
5.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
3.8% (.EXE) Win32 Executable (generic) (4505/5/1)
File icon (PE):PE icon
dhash icon 0070696969696000 (12 x Formbook, 9 x AgentTesla, 5 x Loki)
Reporter abuse_ch
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
247
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
d8bcc7fec4316837552ab05d31e9c555.exe
Verdict:
No threats detected
Analysis date:
2023-04-20 05:31:52 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Found malware configuration
Injects a PE file into a foreign processes
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Modifies the prolog of user mode functions (user mode inline hooks)
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Queues an APC in another process (thread injection)
Sample uses process hollowing technique
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Tries to detect virtualization through RDTSC time measurements
Yara detected FormBook
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 850604 Sample: L31iIkH8kz.exe Startdate: 20/04/2023 Architecture: WINDOWS Score: 100 36 Snort IDS alert for network traffic 2->36 38 Found malware configuration 2->38 40 Malicious sample detected (through community Yara rule) 2->40 42 7 other signatures 2->42 10 L31iIkH8kz.exe 3 2->10         started        process3 file4 28 C:\Users\user\AppData\...\L31iIkH8kz.exe.log, ASCII 10->28 dropped 54 Tries to detect virtualization through RDTSC time measurements 10->54 56 Injects a PE file into a foreign processes 10->56 14 L31iIkH8kz.exe 10->14         started        signatures5 process6 signatures7 58 Modifies the context of a thread in another process (thread injection) 14->58 60 Maps a DLL or memory area into another process 14->60 62 Sample uses process hollowing technique 14->62 64 Queues an APC in another process (thread injection) 14->64 17 explorer.exe 5 1 14->17 injected process8 dnsIp9 30 containermurah.xyz 202.52.146.209, 49697, 80 GMEDIA-AS-IDGlobalMediaTeknologiPTID Indonesia 17->30 32 www.containermurah.xyz 17->32 34 www.bookra-ck.com 17->34 44 System process connects to network (likely due to code injection or exploit) 17->44 46 Performs DNS queries to domains with low reputation 17->46 21 cscript.exe 17->21         started        signatures10 process11 signatures12 48 Modifies the context of a thread in another process (thread injection) 21->48 50 Maps a DLL or memory area into another process 21->50 52 Tries to detect virtualization through RDTSC time measurements 21->52 24 cmd.exe 1 21->24         started        process13 process14 26 conhost.exe 24->26         started       
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2023-04-20 05:29:11 UTC
File Type:
PE (.Net Exe)
Extracted files:
20
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook campaign:gtt8 rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Formbook payload
Formbook
Unpacked files
SH256 hash:
e811c7f5003f7ad8afff2dc585e2f70789486c016fb562ed7042398ed768de29
MD5 hash:
2f8e388ddef1cb2290916f78999be660
SHA1 hash:
3a6a5b1f7dac5e2640524ed1a1b98f8668cd2ef1
Detections:
FormBook win_formbook_w0 win_formbook_auto win_formbook_g0
Parent samples :
6afbb9ebc94ae5fbc1a98207af3ce84dec75c243605ebbd6b15b721165e4130a
44665e986b18ac11dfc0d8226d232b436310ae04126362e26d9b59cb85b2827d
a83adc88feb896f4fa1b09b3d5043fd506f9de5f6d695f7e18bb3d84019abb85
7f0a83fb59c743687b2076967768f0cea1a7772390d25bcd25ebee31caeaaa8f
4f3beb04e0d4713530c2f9c369c300186ab01d902f060a904e5648490e8ba708
120694aadf1eb3c014ff05aea81661da85e34080d23ee2570b98d88b504b1819
757371fd80dda17d1844c472bead62365e29e5f902e32afad9bc0120346220d5
067bea125f176d75cabed99b0bc6bd3a3957baf3a361d6d3848911446e48d1b1
cbdac32d6f43a1f03a26cc2fcc6ea13586f0d7f85764c1626cc71ce30bc0434b
c65c02745d240718672933e9ad25b6a65d1d61ce7c5d317d6447732490434357
44a297e5ccf344c0422f4f80b2c490f2650bf44c142f131378b2eb6a6507bc9b
044c6038df71898680d1927a2a3251d58925ab0b91a5cc17ffc6599fe155f9c4
33b5ccf1b3b48e22ab607320e0bb143ad0ac2a9770b0e385c0365366de472ceb
e843a90ec56b0efbd176b3856d811875e24b98ae6fdf77985e1b77916ab4259b
61141d9453d13d203de8255903f1aec9fea4906616f000cca0b906a58d754cca
5165efed390a7710ab87e8256f51ec07dbc9b63e8cf55e104a9230530b813cb0
abbf85558290e3fa302f88f51243e5216f24c9bc4fce64a0f616db3be2c46e8e
c930599e45ce9f8d2d1ffcce335e47b1beef8119dabef13eefe381927a4f6719
a1a882d7abefdec8678649330339a2f080a777450da1be5110b88e81a8ea38cc
854e56653a2b80660cffe69f84e3d3d956667c9176ab80de7e5d02959bfde099
540c181beb778359eea5bd699310b2cebd8017d5286d408b1abf12e1228b7b9d
90315c352a9820703d29e4dcd9360660dd23bbfac585030993404076b998e45c
6f6635f95155f37d66c295977e973d28b681fb57fc50caf361e5e13f1037008a
96c283a9edad7bf16f772d34c7b137d5403be1dbc96589f7d57d71a0fd89c02f
13714cb6b152e5d8ef04df8c5cf8f59cc8a1414de5be33b52d784e928a67ab0f
ddcb2d701db3ee66e73e1583e248895e4d2fbf8b372f336d1cb585f1352612b2
SH256 hash:
21f0154b51a09767f94922b81f5fcd15cf4a6390ab7314e40d0e17b2dcdfe6ba
MD5 hash:
c926563698de3a89ad20474c85122f73
SHA1 hash:
ed1a3b2527ace111e6f39880c7ee3965f301330d
SH256 hash:
6dba28bec6943cd0c3a1491c61022f90c763075fefbec16993f76c5391fda4fb
MD5 hash:
c2758f27cff562e95801cf5c1a92db0a
SHA1 hash:
8cc8e2863fce337ceacb257e2bbd991b4c4f21c3
SH256 hash:
5e5c8fe4e53980a98b48fe6b19155edf0f0d285ed899c61dbf4f880583ddf1d2
MD5 hash:
b3bbc5461d12f07ea893bf415dfe7c89
SHA1 hash:
40c3156c471d2afe3fd88c7d20cf93e5782e1bd6
SH256 hash:
6028318fd853a581cf83f1258ea93416cb92ace50909b43918c1088dc1054dd0
MD5 hash:
f18955c03132b80265c46006f6b447a6
SHA1 hash:
1baee9e03100a033026780d5146a00594dc89a9a
SH256 hash:
44665e986b18ac11dfc0d8226d232b436310ae04126362e26d9b59cb85b2827d
MD5 hash:
d8bcc7fec4316837552ab05d31e9c555
SHA1 hash:
07d05cb3ed305be4bc00100de8ce1c955c0f0971
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Formbook

Executable exe 44665e986b18ac11dfc0d8226d232b436310ae04126362e26d9b59cb85b2827d

(this sample)

  
Delivery method
Distributed via web download

Comments