MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6b9cb325f344a3cf4dab6eb4c6b8f16a197febb7c50cc12de6a4a6c0e41792d1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 6b9cb325f344a3cf4dab6eb4c6b8f16a197febb7c50cc12de6a4a6c0e41792d1
SHA3-384 hash: 7e0de30ca7b9b16a104d6ea3e6fc6497a5ef34347b4c62e274acd4e95961af8a96317ec504bbf1e35d858a9988f9aa9c
SHA1 hash: 8c15cab77c13a7dbc6afbc5efec02cb4d303bc23
MD5 hash: 4b56512a767471b7a6ff13b638f98777
humanhash: robert-tango-carbon-mountain
File name:17_binder.exe
Download: download sample
Signature FormBook
File size:172'032 bytes
First seen:2020-04-20 05:52:12 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 3072:gmiHMPcvHFlGUtPcYQD28k1cKTHkX1madJhH1BlFHZvg8Z9d0l:0/fdtkX2HTg1madHhFHZvg0
Threatray 4'439 similar samples on MalwareBazaar
TLSH 8DF3AE32D681C030E2B251B5FA7D1B7B883E0E34769594B6E3B119E06FB4895B52E31F
Reporter Racco42
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
95
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Formbook
Status:
Malicious
First seen:
2020-04-20 06:35:34 UTC
File Type:
PE (Exe)
AV detection:
43 of 48 (89.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments