MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 77839da1c15d6390080afe07320af399a007d5b69bf4fcdf63fc71e795929cf7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 77839da1c15d6390080afe07320af399a007d5b69bf4fcdf63fc71e795929cf7
SHA3-384 hash: 6a152015984678566a8561314717044d0e523e5cf660d5f8b818f6731cb11bdd082e74388668313328c7c22f09e4a110
SHA1 hash: 51876a7d7d2d4599c8b83ab1f5717b6dfbe052fa
MD5 hash: 56054118970c3b3649834dd5d42c7a1e
humanhash: oregon-oven-mexico-ink
File name:89NTb(2).exe
Download: download sample
Signature FormBook
File size:816'128 bytes
First seen:2020-04-27 15:26:46 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c0ad2c2ea9dc28bf0db406d9effa5ddd (3 x AgentTesla, 3 x FormBook, 3 x Loki)
ssdeep 12288:E0tjFefQXfJr2rr5unYAwGcHyMqdnFIIl075zvzdv/i2drNMPTV8/hi2ysEy3fdl:E4RXhAvAwGj/Xl0tz5XiJO42SOl
Threatray 2'221 similar samples on MalwareBazaar
TLSH E605AF23F2A08877D1B2163C9D1B93A8583ABD113D24BE4E3BE51D4C5F353913926E9B
Reporter oppimaniac
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

FormBook

Executable exe 77839da1c15d6390080afe07320af399a007d5b69bf4fcdf63fc71e795929cf7

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
MULTIMEDIA_APICan Play Multimediawinmm.dll::mciGetErrorStringA
winmm.dll::mciSendCommandA
WIN32_PROCESS_APICan Create Process and Threadskernel32.dll::CloseHandle
kernel32.dll::CreateThread
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryExA
kernel32.dll::LoadLibraryA
kernel32.dll::GetSystemInfo
kernel32.dll::GetStartupInfoA
kernel32.dll::GetDiskFreeSpaceA
kernel32.dll::GetCommandLineA
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateFileA
kernel32.dll::FindFirstFileA
kernel32.dll::GetTempPathA
version.dll::GetFileVersionInfoSizeA
version.dll::GetFileVersionInfoA
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegOpenKeyExA
advapi32.dll::RegQueryInfoKeyA
advapi32.dll::RegQueryValueExA
WIN_USER_APIPerforms GUI Actionsuser32.dll::ActivateKeyboardLayout
user32.dll::CreateMenu
user32.dll::FindWindowA
user32.dll::PeekMessageA
user32.dll::CreateWindowExA

Comments