MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a0239a35abbffec97c4add7ce6147247095ba18240e3c9b777d9375a6fc70c8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 7a0239a35abbffec97c4add7ce6147247095ba18240e3c9b777d9375a6fc70c8
SHA3-384 hash: ff6b9bccfc07df007e9da1317bd3c7581e9f76956302caad3423e2b8f8dd1f2e31cff8ef130fd3dbfaff26de1415faa7
SHA1 hash: 6b37e1547f2d163bf4d112a10c5a98d7d409c1eb
MD5 hash: e2fd57ade84136c1f01043be3de0b4fe
humanhash: bacon-uncle-skylark-autumn
File name:BOQ and MEP WORKS.rar
Download: download sample
Signature Formbook
File size:238'947 bytes
First seen:2022-04-04 11:41:11 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:qWy2k4XfdjP8Ux0TvHfCS/iqmgC1t7cj4dlExzGKmz0gc:vU4XFPR0TPfCQJVatgj4Tik0j
TLSH T15434239F9C08C4D6F361B2792C6A9F52B4B1D21BD687A757D02D6700FA9E4E3712B380
Reporter cocaman
Tags:FormBook rar


Avatar
cocaman
Malicious email (T1566.001)
From: ""Purchase Dept." <purchase@cool-mkt.com>" (likely spoofed)
Received: "from mail.cool-mkt.com (mail.cool-mkt.com [146.59.95.4]) "
Date: "Mon, 4 Apr 2022 07:00:10 +0000 (UTC)"
Subject: "Furjan Wadi Lusail - Barwa - Project"
Attachment: "BOQ and MEP WORKS.rar"

Intelligence


File Origin
# of uploads :
1
# of downloads :
185
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
control.exe overlay packed shell32.dll
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.FormBook
Status:
Malicious
First seen:
2022-04-04 11:30:01 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
15 of 25 (60.00%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook campaign:dn19 rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Loads dropped DLL
Blocklisted process makes network request
Executes dropped EXE
Formbook Payload
Formbook
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar 7a0239a35abbffec97c4add7ce6147247095ba18240e3c9b777d9375a6fc70c8

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
Formbook

Comments