MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 455f9457f0b901603911b305f2fdab9186a395cf31e9aa8f3a29243a369a8f52. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 455f9457f0b901603911b305f2fdab9186a395cf31e9aa8f3a29243a369a8f52
SHA3-384 hash: c0f861b6f0c5ddc85e67d13db37b698c40c343918a853b136ff5752ae327dd02fff73790b404574e530a3a3501899a74
SHA1 hash: 58c7e8e4682b204da0e67fd353396751d7645282
MD5 hash: d327a9f240d44bc10bad47ef5a44c091
humanhash: washington-papa-mango-london
File name:utasarmsinc.ru_live__ukbros001.exe
Download: download sample
Signature Formbook
File size:569'344 bytes
First seen:2020-03-18 19:25:20 UTC
Last seen:2020-03-18 20:46:24 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 947188728563e6823efefc5693b7a96f (1 x Formbook)
ssdeep 6144:tMAn/7FyKyG6hna3mao72GBi5vvFqgsHl8OfRA4daxm15ij:tMAnqhnAro72/5vvFqnHuOSli0j
Threatray 4'826 similar samples on MalwareBazaar
TLSH 29C4573CE67C952AF8AC857B36F1C4BA64C39D38A03664C87D3E7C8696B760D2DD1901
Reporter ov3rflow1
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaSetSystemError
MSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef
MSVBVM60.DLL::__vbaErrorOverflow

Comments