MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d110e0d08384339b1bc38fbcad2bab177df0ad27b5f5cb2a3b88e8237052abd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 4d110e0d08384339b1bc38fbcad2bab177df0ad27b5f5cb2a3b88e8237052abd
SHA3-384 hash: 31a675f7bc07ba3f6e3bce16b1883f27c7f46c1cafcc39a1e1bd97881a31c7b9010730268b1a9704d8605e74861acc17
SHA1 hash: 82b02f449d74f1e4d73bf0380dfd496a47e03f64
MD5 hash: df3f13a2b84d1e266073fca3e9e0a491
humanhash: beryllium-texas-robert-potato
File name:9b448a056224a0238aa64eaa0017b833
Download: download sample
Signature Formbook
File size:974'336 bytes
First seen:2020-11-17 11:40:18 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'744 x AgentTesla, 19'616 x Formbook, 12'242 x SnakeKeylogger)
ssdeep 24576:+x+8GwDd47/a3+D2O5xTOLqC7XvOMR3yShPN:enDoCO2ObOeSG/Sh
Threatray 335 similar samples on MalwareBazaar
TLSH 4025D04A27D41A1BC5AF277AE0341184837CF966C3A7EB972968A0FC0CE37588D457B7
Reporter seifreed
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Launching the default Windows debugger (dwwin.exe)
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-11-17 11:42:32 UTC
AV detection:
25 of 48 (52.08%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: EnumeratesProcesses
Program crash
Unpacked files
SH256 hash:
4d110e0d08384339b1bc38fbcad2bab177df0ad27b5f5cb2a3b88e8237052abd
MD5 hash:
df3f13a2b84d1e266073fca3e9e0a491
SHA1 hash:
82b02f449d74f1e4d73bf0380dfd496a47e03f64
SH256 hash:
a2b5512fb2440dc07d716b6afb097cf29e9d648532b77c7fd7d553055c36d24e
MD5 hash:
6cc1ced8d50461f6cbe3316d255c6566
SHA1 hash:
6c4980f47f848a0170c978ad237bd2f17eefea92
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments