MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 72ec3dcd3d7a197c45c66605330968f86044d6a2ec37bf843e33b7f4668781f9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 72ec3dcd3d7a197c45c66605330968f86044d6a2ec37bf843e33b7f4668781f9
SHA3-384 hash: 49b2d20c6bd0c2e19f4bcc4ae1ab1c8bd8381aadb3fdb75940e162abcbcb588dfae98a1dc2bedbf4031125f8c469932d
SHA1 hash: 1e2c99582444ba27c2f9d8eb94a95f843adc1803
MD5 hash: b54062ce30398bb5289db62d80347e55
humanhash: four-florida-pizza-sweet
File name:0ap.exe
Download: download sample
Signature Formbook
File size:383'060 bytes
First seen:2020-09-08 07:23:20 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 7c2c71dfce9a27650634dc8b1ca03bf0 (160 x Loki, 58 x Formbook, 55 x Adware.Generic)
ssdeep 6144:JPCganN3t5sm1AsyHWTGHFYJd2PhTWwDJYhPQMUeSGZML1AB4ICp6vTAFIweimzE:HanRtSWYWNQBxJYhoM1ZML1ABBoKTAFZ
TLSH 0884238AB2A0CCD7E0A08AF00D7AD57C99B69E5144666E473BD07F3738711826F1E793
Reporter abuse_ch
Tags:Adware.Generic exe FormBook


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: zimbra.power.it
Sending IP: 109.168.111.151
From: lists@power.it
Reply-To: covestone@yahoo.com
Subject: Requesting Price
Attachment: 0RDER INQUIRY LIST 08009020.xlsx

FormBook payload URL:
http://coltec.ga/~zadmin/temp/0ap.exe

FormBook C2:
http://www.borez.xyz/c233/

Intelligence


File Origin
# of uploads :
1
# of downloads :
194
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a file
Sending a UDP request
Launching a process
Launching cmd.exe command interpreter
Setting browser functions hooks
Unauthorized injection to a system process
Unauthorized injection to a browser process
Threat name:
Win32.Trojan.Bluteal
Status:
Malicious
First seen:
2020-09-07 22:08:02 UTC
AV detection:
23 of 28 (82.14%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
NSIS installer
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe 72ec3dcd3d7a197c45c66605330968f86044d6a2ec37bf843e33b7f4668781f9

(this sample)

Comments