MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 535fb5862370192d9fa74321ef99aa8fe36aaf56689f48411fc7c14b9c984533. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 12


Intelligence 12 IOCs YARA 3 File information Comments

SHA256 hash: 535fb5862370192d9fa74321ef99aa8fe36aaf56689f48411fc7c14b9c984533
SHA3-384 hash: f0162ec3cacf81c529dc5d6327d0b8ed355cf2652a959c863d08f33180f9060360212d8247c3291ab432b85ecc3138fe
SHA1 hash: 7fd6aa9cf895309fca426c6decff54e17f979a8c
MD5 hash: d214a74543e7e29a6702358a3a834f70
humanhash: hamper-arkansas-missouri-cardinal
File name:SOA.exe
Download: download sample
Signature Formbook
File size:975'360 bytes
First seen:2022-07-07 08:35:27 UTC
Last seen:2022-07-07 09:56:07 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'666 x AgentTesla, 19'479 x Formbook, 12'208 x SnakeKeylogger)
ssdeep 24576:o2oYHQucPLT92UZ6NTnlKmdriqznnaXav:o2oYHQbLT927TsmdWwa
TLSH T1D625CF1DD7D5C127F2BE4AF8CEC1E0F0637CB94DA944AF2D8580ADAE6B2054993871D2
TrID 64.2% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
11.5% (.SCR) Windows screen saver (13101/52/3)
9.2% (.EXE) Win64 Executable (generic) (10523/12/4)
5.7% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
3.9% (.EXE) Win32 Executable (generic) (4505/5/1)
Reporter GovCERT_CH
Tags:exe FormBook xloader

Intelligence


File Origin
# of uploads :
2
# of downloads :
257
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a file in the %AppData% directory
Creating a file in the %temp% directory
Launching a process
Creating a process with a hidden window
Unauthorized injection to a recently created process
Creating a file
Searching for synchronization primitives
Launching cmd.exe command interpreter
Enabling autorun by creating a file
Unauthorized injection to a system process
Gathering data
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains very large strings
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Queues an APC in another process (thread injection)
Sample uses process hollowing technique
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AntiVM3
Yara detected FormBook
Yara detected Generic Downloader
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 658747 Sample: SOA.exe Startdate: 07/07/2022 Architecture: WINDOWS Score: 100 39 www.huangyirong.xyz 2->39 41 www.enterprisesearchinc.com 2->41 47 Malicious sample detected (through community Yara rule) 2->47 49 Antivirus detection for URL or domain 2->49 51 Multi AV Scanner detection for dropped file 2->51 53 11 other signatures 2->53 11 SOA.exe 6 2->11         started        signatures3 process4 file5 33 C:\Users\user\AppData\...\qssCmWgCpsfh.exe, PE32 11->33 dropped 35 C:\Users\user\AppData\Local\...\tmp1DDB.tmp, XML 11->35 dropped 37 C:\Users\user\AppData\Local\...\SOA.exe.log, ASCII 11->37 dropped 63 Uses schtasks.exe or at.exe to add and modify task schedules 11->63 65 Tries to detect virtualization through RDTSC time measurements 11->65 67 Injects a PE file into a foreign processes 11->67 15 SOA.exe 11->15         started        18 schtasks.exe 1 11->18         started        signatures6 process7 signatures8 69 Modifies the context of a thread in another process (thread injection) 15->69 71 Maps a DLL or memory area into another process 15->71 73 Sample uses process hollowing technique 15->73 75 Queues an APC in another process (thread injection) 15->75 20 explorer.exe 3 15->20 injected 24 conhost.exe 18->24         started        process9 dnsIp10 43 www.selfmadeadvantage.com 20->43 45 flash.funnels.msgsndr.com 34.68.234.4, 49892, 80 GOOGLEUS United States 20->45 55 System process connects to network (likely due to code injection or exploit) 20->55 26 chkdsk.exe 20->26         started        signatures11 process12 signatures13 57 Modifies the context of a thread in another process (thread injection) 26->57 59 Maps a DLL or memory area into another process 26->59 61 Tries to detect virtualization through RDTSC time measurements 26->61 29 cmd.exe 1 26->29         started        process14 process15 31 conhost.exe 29->31         started       
Threat name:
ByteCode-MSIL.Spyware.SnakeLogger
Status:
Malicious
First seen:
2022-07-07 06:46:34 UTC
File Type:
PE (.Net Exe)
Extracted files:
9
AV detection:
21 of 26 (80.77%)
Threat level:
  2/5
Verdict:
malicious
Label(s):
formbook
Result
Malware family:
xloader
Score:
  10/10
Tags:
family:formbook family:xloader campaign:nmd2 loader persistence rat spyware stealer suricata trojan
Behaviour
Creates scheduled task(s)
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Program Files directory
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Deletes itself
Blocklisted process makes network request
Xloader Payload
Formbook
Xloader
suricata: ET MALWARE FormBook CnC Checkin (GET)
Unpacked files
SH256 hash:
8f8d821f9b816b475e1c9f34db67d3a4e7c5e6d0a4dfc462ef67248ad0a5afea
MD5 hash:
af41a321878299875b7d3763ebe91b20
SHA1 hash:
34697adff8512e91fdcaf9f22abdf424fbc5f4b9
Detections:
win_formbook_g0 win_formbook_auto XLoader
Parent samples :
9f604ab9c007da7543c828be85e5508af9541fb039bb9e90283f84b0d6aebdc4
717ab44671da707ee8ad9e5c6e4ade18d6f47841e65a6bd0cebd56c8c1533fcf
0b8058097313b63fec637d226daa0af6abb9f68bb1d0ccb9edb39876453617be
8586e05ff7d2269e9495e76725cc561d433cb771d6af6581ae5fdcf7b8b571d9
085917245898b3d25910807103748a579b389697e79bdceb82b043f66b86a130
f361a889ba650230da217b06b0c41ced6d025c461f29e854583548461dc84668
a28592058ed33d1a46f187fb5fcccbd89b9167ed84c85755aaa8d2d3ceca9003
313566736f3e85c4303541ddf83b100fd80fefe20702cc7c3e10789942127a9e
1722230b243c441e5498ccd145a7a4f8fa00b97d2a22cb20007efb227cce45a9
6f6be5365b28b8c8bd13b442ea0c7f18bbd6cc92d1a6cea7cece4702bcc8cac9
32b04a3fc9feb6bd1b63e6ec096f2cfa0a78f07f86cb08c64f4a24ec5325c0b1
04326067e70a15d7b5139282361d1cd355b2a6c057ca7ac0e901f0a88b139aa7
970e64f4f7b5a8dd1e1f5df8470f372d27585cff9f75a0d3a596427d261bf809
262d23daa434a3eaf7afceeb9b9340f20c040eac7acb6732749c49f433e2e17f
4f4e5e5550b40c160b4dfa9f399b558d2d96ffdf49cc0c81a86a6b3942f1fd94
901b8ec8346c9ec07fb34f17b2eb18f45d6197b0cbb1d7bad6b1cf23ff0cbab1
4863509ff407e4a6389305b5555bc804aa5df9b67290feeb1e36bf68f40696e1
535fb5862370192d9fa74321ef99aa8fe36aaf56689f48411fc7c14b9c984533
f085387dd3ad9b5e949cdb80752a76f1fab4fe66c7eee38a353d0f80b80df7b7
3064b62e720763ef00cfa548424cf74aef8034f8ddc420084519b27b4e1f271e
a5c83c27bf821b97478d7a7cf53e3de83e15fb3a87ff7bdb793afc6ee8d0f64d
7833781bd55b3c69a30841ca9d10a7d8d0bc15b9fbf5cc4d81eee5e2f9591000
1b382c7ca0e34e9e294ea85dfdb722ccfe0b828ecbf5c665a605af31d7277e6f
3fa0d321b17bc7af7e98f723135bf7c3151107f4572f1a41c68f933c488c77b3
SH256 hash:
5e97ccd8dafcb36b3cb772f6a2fd425abcf221ab9ea1930e8c2618c95332f2c6
MD5 hash:
01800f6b045def8d90c649842f56d752
SHA1 hash:
f8434a4636d0772d01aac44bb3f9753a41f01d34
SH256 hash:
8bfc120443ae13cf613c0d2fd21807c29226d0bae6890107434950d5d729ea5a
MD5 hash:
d9424779475444252f4681526305142b
SHA1 hash:
a64b2544d87463aa50256d9f19a977c7c77ca88d
SH256 hash:
535fb5862370192d9fa74321ef99aa8fe36aaf56689f48411fc7c14b9c984533
MD5 hash:
d214a74543e7e29a6702358a3a834f70
SHA1 hash:
7fd6aa9cf895309fca426c6decff54e17f979a8c
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_SUSPICIOUS_EXE_RawGitHub_URL
Author:ditekSHen
Description:Detects executables containing URLs to raw contents of a Github gist
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe 535fb5862370192d9fa74321ef99aa8fe36aaf56689f48411fc7c14b9c984533

(this sample)

  
Dropped by
xloader
  
Delivery method
Distributed via e-mail attachment

Comments