MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7af6387448493859c9092ddfdbf2e40622ebbe9211ea12d4f27290e842c57852. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 7af6387448493859c9092ddfdbf2e40622ebbe9211ea12d4f27290e842c57852
SHA3-384 hash: 85296442d1a7f66e6593dce6ca3a5c492426cd59b36876a094eb9cadba23f0aee027aab99e63f4a932912ee9bf5a3a6e
SHA1 hash: cdd687d5c26051d3ae8a2e19f3f144280d822099
MD5 hash: 6854510df1b22ade24370ce24893bb7a
humanhash: nuts-wolfram-table-golf
File name:alll.exe
Download: download sample
Signature FormBook
File size:1'110'312 bytes
First seen:2020-04-23 04:23:34 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 56da23509857300b597637e5411ab81e (3 x FormBook)
ssdeep 24576:R3T9RJXcYTBbuQL4BTbHcZd2yWPDC5N7Q4ZWe51LgxjoLLLaRjU:B9RJXcYTtuQURLc3zn51ZWq1cWLfJ
Threatray 5'096 similar samples on MalwareBazaar
TLSH 6835124EF93C9844FD6249F4D48ED8E95D4CEC63832402973BEA7CC7AEB1562D819C29
Reporter JoulK
Tags:FormBook

Code Signing Certificate

Organisation:VeriSign Time Stamping Services CA
Issuer:Thawte Timestamping CA
Algorithm:sha1WithRSAEncryption
Valid from:Dec 4 00:00:00 2003 GMT
Valid to:Dec 3 23:59:59 2013 GMT
Serial number: 47BF1995DF8D524643F7DB6D480D31A4
Intelligence: 14 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: 1C1983300C10FB262C0B2304B7BE15AABA10AE356EBBBB177583DC44774EB080
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-04-22 07:50:43 UTC
File Type:
PE (Exe)
Extracted files:
30
AV detection:
24 of 31 (77.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

FormBook

Executable exe 7af6387448493859c9092ddfdbf2e40622ebbe9211ea12d4f27290e842c57852

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
ole32.dll::CreateStreamOnHGlobal
GDI_PLUS_APIInterfaces with Graphicsgdiplus.dll::GdiplusStartup
gdiplus.dll::GdiplusShutdown
gdiplus.dll::GdipDeleteGraphics
gdiplus.dll::GdipAlloc
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::GetStartupInfoW
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileW
WIN_USER_APIPerforms GUI ActionsUSER32.dll::CreateWindowExW

Comments