MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 45cf2baa638343e087ec2c2a91e4d5767b3342cd4eb2e39907567d237cbfa701. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 45cf2baa638343e087ec2c2a91e4d5767b3342cd4eb2e39907567d237cbfa701
SHA3-384 hash: 13046acc50d46ee6f1d39858ac95e06e83f6e9ca9ab73ab08b001f28b7a7acc799328b7fc31a9478b176fbd855800fc2
SHA1 hash: dd185f292178a39cb0c9837db1a3b5b872be6b73
MD5 hash: 46345d3d4e52a84ae9484b6a9962e97f
humanhash: fix-robin-failed-jig
File name:RFQ TRQ20200413 (Closing Date 30th APRIL 2020)_pdf.exe
Download: download sample
Signature FormBook
File size:303'616 bytes
First seen:2020-04-20 19:24:04 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'740 x AgentTesla, 19'599 x Formbook, 12'241 x SnakeKeylogger)
ssdeep 3072:KlLH5WRnG8Qx9l0V1gaCMDQ4Ib4biXHHRqnwl90VOsdmd8v1+uervBwU1NGl0LtN:KXqvY+V1gaBQsiXHHOrmA+ucwU/GlcZ
Threatray 5'076 similar samples on MalwareBazaar
TLSH F25418CCE937E2B2877AD6BA4D4EE809E1FA56E925C0D4FCB8F70D45072396829C4435
Reporter jarumlus
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
93
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-04-20 10:27:00 UTC
File Type:
PE (.Net Exe)
Extracted files:
2
AV detection:
26 of 31 (83.87%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments