MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 52ebab8afd7a067a659f8488eeaf316ba5e09caef4cdd7060883adef4496239d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 52ebab8afd7a067a659f8488eeaf316ba5e09caef4cdd7060883adef4496239d
SHA3-384 hash: 7d694d3ae619300fb46dda3fa8cecdf867b0246399ecd61beb7232336dd9d208d92d111141176fbb3f87447667695427
SHA1 hash: 5cd788e33d68e69a5f58d181c360bfce8da9b0ad
MD5 hash: 98efed27ec917688596a6e07adacda88
humanhash: india-victor-november-orange
File name:vbc.exe
Download: download sample
Signature FormBook
File size:984'576 bytes
First seen:2020-04-16 08:35:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2d09135f1522bbaeed6a8943bd4997f6 (1 x FormBook)
ssdeep 12288:uC4q+Cc6MmSppualvGcyfTvvyeywBUTE6beLG1MlER5DRW/BBKX:R+dmwvGcyfTC8qTE6aLRER5NW/BwX
Threatray 5'116 similar samples on MalwareBazaar
TLSH BE255A7A6E309235EF322171F59BDAE99519AD2C6C50434FF285F2240BFD2506738F2A
Reporter paleoarchean
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
91
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

Executable exe 52ebab8afd7a067a659f8488eeaf316ba5e09caef4cdd7060883adef4496239d

(this sample)

  
Dropped by
GULoader
  
Delivery method
Distributed via e-mail attachment

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CLSIDFromProgID
ole32.dll::CoCreateInstance
ole32.dll::CoFreeUnusedLibraries
GDI_PLUS_APIInterfaces with Graphicsgdiplus.dll::GdipAlloc
MULTIMEDIA_APICan Play MultimediaAVIFIL32.dll::AVIStreamGetFrameOpen
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
KERNEL32.dll::CreateThread
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::GetVolumeInformationW
KERNEL32.dll::GetSystemInfo
KERNEL32.dll::GetStartupInfoA
KERNEL32.dll::GetStartupInfoW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WriteConsoleW
KERNEL32.dll::WriteConsoleA
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleCP
KERNEL32.dll::GetConsoleMode
KERNEL32.dll::GetConsoleOutputCP
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileA
KERNEL32.dll::CreateFileW
SHLWAPI.dll::PathRemoveFileSpecW
KERNEL32.dll::GetFileAttributesW
KERNEL32.dll::FindFirstFileW
WIN_CRYPT_APIUses Windows Crypt APIADVAPI32.dll::CryptAcquireContextA
ADVAPI32.dll::CryptDecrypt
ADVAPI32.dll::CryptEncrypt
ADVAPI32.dll::CryptExportKey
ADVAPI32.dll::CryptGenKey
ADVAPI32.dll::CryptImportKey
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegCreateKeyExA
ADVAPI32.dll::RegCreateKeyExW
ADVAPI32.dll::RegDeleteKeyW
ADVAPI32.dll::RegOpenKeyW
ADVAPI32.dll::RegOpenKeyExW
ADVAPI32.dll::RegQueryInfoKeyA
WIN_SOCK_APIUses Network to send and receive dataWS2_32.dll::WSAEventSelect
WIN_USER_APIPerforms GUI ActionsUSER32.dll::AppendMenuW
USER32.dll::PeekMessageW
USER32.dll::CreateWindowExW

Comments