MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4850a766fab45d5947075658d9c6bbf4b970f0d05b082c1472b93d9a7fa3d093. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 16


Intelligence 16 IOCs YARA 7 File information Comments

SHA256 hash: 4850a766fab45d5947075658d9c6bbf4b970f0d05b082c1472b93d9a7fa3d093
SHA3-384 hash: c255e57343a9c815024058c03194d7d9c7ff58c9be09917a2634dafe5686bba81784dca51690b73203f71a3fec5154c3
SHA1 hash: 8304a2d91515ca2f1079f787de0b8a776941c2cd
MD5 hash: dad6e1001c72b68d690fedf88254f157
humanhash: moon-california-mango-whiskey
File name:4850a766fab45d5947075658d9c6bbf4b970f0d05b082c1472b93d9a7fa3d093
Download: download sample
Signature Formbook
File size:670'728 bytes
First seen:2024-04-08 13:17:07 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'658 x AgentTesla, 19'469 x Formbook, 12'208 x SnakeKeylogger)
ssdeep 12288:d0ThCmCKGvGOfdY/IDuwEtSR5l6odUBJiJuh527BOsVFkR:WTULGOfdUIDk8nk8UBJiJO5ABtV4
TLSH T1A7E4010267E86B08F87BA7F4B550411023727517BAB6D79C6FD0E0CE2AB1B414E6B71B
TrID 63.0% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
11.2% (.SCR) Windows screen saver (13097/50/3)
9.0% (.EXE) Win64 Executable (generic) (10523/12/4)
5.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
3.8% (.EXE) Win32 Executable (generic) (4504/4/1)
Reporter adrian__luca
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
285
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
4850a766fab45d5947075658d9c6bbf4b970f0d05b082c1472b93d9a7fa3d093
Verdict:
Suspicious activity
Analysis date:
2024-04-08 13:16:56 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
overlay packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Found malware configuration
Injects a PE file into a foreign processes
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Modifies the prolog of user mode functions (user mode inline hooks)
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Reads the DNS cache
Sample uses process hollowing technique
Snort IDS alert for network traffic
Tries to detect virtualization through RDTSC time measurements
Uses ipconfig to lookup or modify the Windows network settings
Yara detected AntiVM3
Yara detected FormBook
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1422327 Sample: hj3YCvtlg7.exe Startdate: 08/04/2024 Architecture: WINDOWS Score: 100 32 www.yoursweets.online 2->32 34 www.poseidoncrm.com 2->34 36 11 other IPs or domains 2->36 44 Snort IDS alert for network traffic 2->44 46 Found malware configuration 2->46 48 Malicious sample detected (through community Yara rule) 2->48 50 8 other signatures 2->50 11 hj3YCvtlg7.exe 3 2->11         started        signatures3 process4 signatures5 62 Tries to detect virtualization through RDTSC time measurements 11->62 64 Injects a PE file into a foreign processes 11->64 14 hj3YCvtlg7.exe 11->14         started        17 hj3YCvtlg7.exe 11->17         started        19 hj3YCvtlg7.exe 11->19         started        process6 signatures7 66 Modifies the context of a thread in another process (thread injection) 14->66 68 Maps a DLL or memory area into another process 14->68 70 Sample uses process hollowing technique 14->70 72 Queues an APC in another process (thread injection) 14->72 21 explorer.exe 104 1 14->21 injected process8 dnsIp9 38 www.mingshengglass.com 102.134.40.151, 49719, 80 sun-asnSC South Africa 21->38 40 oregonjobs.co 66.147.240.91, 49722, 80 UNIFIEDLAYER-AS-1US United States 21->40 42 4 other IPs or domains 21->42 52 Uses ipconfig to lookup or modify the Windows network settings 21->52 25 ipconfig.exe 21->25         started        signatures10 process11 signatures12 54 Modifies the context of a thread in another process (thread injection) 25->54 56 Reads the DNS cache 25->56 58 Maps a DLL or memory area into another process 25->58 60 Tries to detect virtualization through RDTSC time measurements 25->60 28 cmd.exe 1 25->28         started        process13 process14 30 conhost.exe 28->30         started       
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2024-03-14 10:59:05 UTC
File Type:
PE (.Net Exe)
Extracted files:
29
AV detection:
26 of 38 (68.42%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook campaign:vr01 rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Formbook payload
Formbook
Unpacked files
SH256 hash:
c10c9b0882bac6f788f48b4dabe3291b14e639e650f2b9fcb0bc174ac92ae02b
MD5 hash:
7c7fb6daa78beb69128991ff893143ed
SHA1 hash:
c01bb99984b12b84129db80eae1d5d8341a358e2
SH256 hash:
e6b25e7250cdd5f75ec51545b9105bdf202d880898ec9c4cd75c131d9262e1d0
MD5 hash:
0c01ecddd3880a71ee7b626706813efb
SHA1 hash:
37eecee4ca36bb984095155b6a3a2e640f452e0d
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
e97625746360793777ab1d7dc32d4259332c7f3c81a441eb7850234aabfdf23d
5cab510258dae33c18cd23924daefd7501ff7203ba9816704a2b0ca66508c56f
0aebca1aecba63aa6205a90f467e4c6ffb86efd928bdd7e3d7ba453eca8ffc00
af69e50524ba63cfcbaaa2de4d15434743f2f34239ad34228e4eadde55bbeae6
fc8a9c0e62e7e7df74d0d59bed35d720aca7a47021f8c55bc1bcc32fb3075a94
6a7c6a729d852d01d74832748b6571bafaefcd0bd12aced32e4fa88166af8817
9ca2b5622a36e207a1d11a748f637920d4f96d88e34b2dede0840bcce07f5788
4b39adbf8d3a4e2a5793014b4af4a4cb98d3a71c4a565dd20dc3a69928a84c72
037c7011889e43ee7456a314fbfebcc3d7abbd96aa509a34babc0d832681013f
664db26a69e4b1efb10289189887c35558bf7ca966eed02f97e523fef83f1205
fcac462e70c7009c1c8dbc15dffea8e0b8ff141fc94a95581c306d995a2748d2
2b3114ee08fb8a720819c749b1cbd68f5c8119073f34db958849b1d3eb1bdd9d
bdd4ba2aedeeebd368997ceb0a5c0372959181a08f1e5aefb4b437609630bdff
f4cefaa54034c3cfd9bf223520e2a5876ec1d161cb4a68b6b7d3e9fe892b087f
24c2781350cbe7b9de07fdd597275c2e2dde39fea4eaf007d00610044376de1f
f79941668c6679c1f5770816ce7b68a2d518caa7d7218299f7a1908cf338297a
88737e32661e323c947753fd7c8ca1abd141e7c917dc12730a5d6634be6847fc
ea8e979a9bf6fe2e8af35cedb5d639091629a2ce626f1339c7a0a48e3cc39ba2
8ecf19dca7047302513a5818cb79bcd6c4b278f92904ed1fcc7f559c72e0de7a
e9ea79b9129140cbc495137ea1c09c0686d5a5d33c43cfd1217ee2aead41237d
312783562439afa6feb4e46153051e5af5e7c15f139bac75a25afd38caaed1ce
1875aee9f50a8e2389a125c2f77998685ee0d7d7d20b7d3f1ecadf841564e654
7a20de1b4a4cd2e217be33f3297d2b38d7e7fd69ee216d58f0400160e41ff3ea
55571fa3b9f2d9a7d71c1154aac73dc3826860eaa7be12cceda40d4566ea4ce1
242ea95cfe48aaa9fca35f358ac8431cd1bd730b1ff95543a4f9d9e768115d3f
d5a0f85ffb3ee297f57ffb96a77288de2a564c5cb337b5c6c7b01da8e36545d6
285dbc8362784007c8e0a4060f48bea0818563129e5c824d34393f2c714c1a9e
ffb10236e7f77499f767e9e703c9e0a6d0b3777ff6ae06e63724f23fc7e3ea29
610224addb5b75398e556cf9780a9ad26891fa1754cbda12637903560d15dba4
959d491cbde6323dc2bf7c377a9c1e0940b988f51a3efcc0f1bd526cc0d210b4
5ca87353c4d37e66f76875a46235208796dd620ad3cb7cebc6b5e66be55b2913
d5df0f56b1209034e89de624a5ad652d070035c15f24d6b3559c34540c725b9c
590f27260d772e044dd8819c937658e02ab15050b3bf6cc3dd054c808ed3c201
89e60f82a944bb55032e88f1dff4d13242129b0bf2a3ae39aeb93904a665d4f4
8d4a83437f552b1737a406be9d9b5e4f4919a1adbf8e13f8261411d7390d604f
201cffe8bf2c15a804167c67d2a095ff655829395cb54b5c3d3c4d038efde920
224ff64e59a1b2bf45b02cb11df4f0556de0bbeb7929d37828de1c1bb8ff8772
ab5501455d6b22f8e26dd31ed265879ca6c0d3c6677793738f49360628792991
5f7a3e9cfebdb626e00af8155e710df40bab01bc5b8fcf77163cda86d23cae3d
86ea784bb86a20eff340835a0cf862d6a4a5b2309ead2c00006b65c2d8f5ebd1
0c18d82d30c57f4eb7b9ce8f7bb367b114718b077b7fd7bd838f57399c5921d0
ee591c0b19049eff4e311686e26557c5da6818438c319ed6f0df6274a56c5e05
48b161190679dd4c509ab89a5dfdfac0bdf6b557c0d77d9e4f698acf057acef8
a1a5145381a87900950867d3e6632aaf89fdedb9c898bf44fd7efbea077ab224
800fc3595eab3d807dd8199ba639d1bc6c0bdf5f1f47cf3a95c649b61056bc1c
4850a766fab45d5947075658d9c6bbf4b970f0d05b082c1472b93d9a7fa3d093
f2338f728798c729c37b627d5d75bf8691a482a4b9cc4b67ae5a5ba4b45b0c85
3d648905c51d97e4998f5e24312dae37f77dbe94279847f6a124894790881082
SH256 hash:
4a3d455993a7f85430b57c86c15226f49d4ba5869f54c8bbf6313651a3932624
MD5 hash:
249a357557fdc8174146f23b3ffdb7c1
SHA1 hash:
1dbc9dc92780b9fc29d333f67ee35742d7b6fcf3
SH256 hash:
4850a766fab45d5947075658d9c6bbf4b970f0d05b082c1472b93d9a7fa3d093
MD5 hash:
dad6e1001c72b68d690fedf88254f157
SHA1 hash:
8304a2d91515ca2f1079f787de0b8a776941c2cd
Detections:
INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AgentTesla_DIFF_Common_Strings_01
Author:schmidtsz
Description:Identify partial Agent Tesla strings
Rule name:INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438
Author:ditekSHen
Description:Detects executables signed with stolen, revoked or invalid certificates
Rule name:NET
Author:malware-lu
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_imphash
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments