MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 55cf5e68816fcdbf38c5c1b306e3fc3d1dae18b8a578b714a3bc23d728c2ef33. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 55cf5e68816fcdbf38c5c1b306e3fc3d1dae18b8a578b714a3bc23d728c2ef33
SHA3-384 hash: 6d5b1cd08d4ea88707de93271cc420d170651bcd82d3e90ab80355ee20c4f5456b3a9ade3e74f3fe2e2872ce79a5faf0
SHA1 hash: 46db3f95843ccf8cef42adeeb5a9a97dd17786a4
MD5 hash: 49be5247985b83ada416724af427bad1
humanhash: december-papa-july-texas
File name:86HTe(4).exe
Download: download sample
Signature Formbook
File size:1'054'208 bytes
First seen:2020-04-28 11:42:43 UTC
Last seen:2020-04-28 12:57:28 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 0318ec2c3e20540fe0ccf697fa352b5b (4 x FormBook, 2 x Loki, 2 x AgentTesla)
ssdeep 12288:4DYvWV4fQB0cHSs3fvMHLZT/LqMg9Oec/lC8+lEvKlJfF05Ibmu9EgeIKxAtWZg3:+400o9vY1qMWRylCba+rbd2
Threatray 4'535 similar samples on MalwareBazaar
TLSH 7925AF22B3D048B7D5760A385E1BA2B058377D776A3CA84537E43E0E1F3868579393A7
Reporter oppimaniac
Tags:FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
97
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-28 11:19:15 UTC
File Type:
PE (Exe)
Extracted files:
46
AV detection:
26 of 31 (83.87%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Formbook

Executable exe 55cf5e68816fcdbf38c5c1b306e3fc3d1dae18b8a578b714a3bc23d728c2ef33

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
SHELL_APIManipulates System Shellshell32.dll::ShellExecuteExA
shell32.dll::ShellExecuteA
shell32.dll::SHGetFileInfoA
WIN32_PROCESS_APICan Create Process and Threadskernel32.dll::CloseHandle
kernel32.dll::CreateThread
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryExA
kernel32.dll::LoadLibraryA
kernel32.dll::GetSystemInfo
kernel32.dll::GetStartupInfoA
kernel32.dll::GetDiskFreeSpaceA
kernel32.dll::GetCommandLineA
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateFileA
kernel32.dll::FindFirstFileA
version.dll::GetFileVersionInfoSizeA
version.dll::GetFileVersionInfoA
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegOpenKeyExA
advapi32.dll::RegQueryValueExA
WIN_USER_APIPerforms GUI Actionsuser32.dll::ActivateKeyboardLayout
user32.dll::CreateMenu
user32.dll::FindWindowA
user32.dll::PeekMessageA
user32.dll::CreateWindowExA

Comments