MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 58668792e64783e46ee3ffe3749e75cf5e65e02486a25840ba70c0c1f06a944a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 58668792e64783e46ee3ffe3749e75cf5e65e02486a25840ba70c0c1f06a944a
SHA3-384 hash: adf24a903d79952e18bdc0a22fc95e0cbc0f047dc059f2695397473b74122a6f4810173fc116fc8c8bdbfb48acf5f891
SHA1 hash: abad3d58d980b46862ff880562c92a315ddb4dd6
MD5 hash: 58467b23b0fafd5f24963cdeb8bf4465
humanhash: victor-september-seventeen-mobile
File name:58467b23b0fafd5f24963cdeb8bf4465
Download: download sample
Signature Formbook
File size:717'312 bytes
First seen:2020-11-17 12:42:50 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'662 x AgentTesla, 19'474 x Formbook, 12'208 x SnakeKeylogger)
ssdeep 12288:MArOGu+4RbwYzsEmLeNixxXqMEtKeuLvV+zKmULpYpYZgX3/SxpadGgz:VrGVEtWif6MEtYvMKm5X3/Sxpadt
TLSH 35E4F10473CC4B15C5BF1BFAF93000D68BB6D7C395BADBAD5848A6AE18C27416E113B6
Reporter seifreed
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Creating a window
Launching the default Windows debugger (dwwin.exe)
Threat name:
Win32.Trojan.Ymacco
Status:
Malicious
First seen:
2020-11-10 09:19:33 UTC
AV detection:
23 of 28 (82.14%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: EnumeratesProcesses
Program crash
Unpacked files
SH256 hash:
58668792e64783e46ee3ffe3749e75cf5e65e02486a25840ba70c0c1f06a944a
MD5 hash:
58467b23b0fafd5f24963cdeb8bf4465
SHA1 hash:
abad3d58d980b46862ff880562c92a315ddb4dd6
SH256 hash:
84d787cfac285686800428f4ab624114cd7b198f1fa26e53e2606d43422eb756
MD5 hash:
f9a1cd3acc35d4dccca733db16e52321
SHA1 hash:
2d7b63c156d172b41cbe1f80cac441d99e4280fc
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments