MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 55a07d9b6fcf1c45c55afbf847da7fff3d76b7c8c699739d76ab07640bf02daa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 55a07d9b6fcf1c45c55afbf847da7fff3d76b7c8c699739d76ab07640bf02daa
SHA3-384 hash: b673c7d0fc5b452522a3096822177cfacb8ab9617c29069c88061905ccc659131ace931f8704923a2668759e26dd325c
SHA1 hash: e7d90f48c4a41bffea2373d720f046bdfb6a7aaa
MD5 hash: 5e08f455f00ca755b48302d923cc1f0e
humanhash: vegan-maine-maryland-seven
File name:874473429570a727e95e1015ca23b188
Download: download sample
Signature Formbook
File size:273'408 bytes
First seen:2020-11-17 11:39:06 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 192058f2810235b0efae8de0f7b55742 (4 x Formbook)
ssdeep 6144:laSxn4JdM81Yn9MCCxtTAfwgwn12d7r1o9nlzlgS+0o:txX91GIwgwn1K6Blq35
Threatray 2'940 similar samples on MalwareBazaar
TLSH D844E035B8C3C4B2C45501395515EBA0DB3EBD711AB8EC82F7593AAD8E733D26619283
Reporter seifreed
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Unauthorized injection to a recently created process
Launching a process
Launching cmd.exe command interpreter
DNS request
Sending an HTTP GET request
Unauthorized injection to a system process
Threat name:
Win32.Spyware.Stelega
Status:
Malicious
First seen:
2020-11-17 11:40:08 UTC
AV detection:
25 of 29 (86.21%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
55a07d9b6fcf1c45c55afbf847da7fff3d76b7c8c699739d76ab07640bf02daa
MD5 hash:
5e08f455f00ca755b48302d923cc1f0e
SHA1 hash:
e7d90f48c4a41bffea2373d720f046bdfb6a7aaa
SH256 hash:
810e49cfa84ab5921f3ac51aa5f0bba28dea8c300b209bbd226116333fbb3e8a
MD5 hash:
e3c2de6d08fcdd86b7f9ab0bdeeae64e
SHA1 hash:
763241fc9d5c586889bb038ac85e5ef8cbd29211
Detections:
win_formbook_g0 win_formbook_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments