MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8243f0400ffe13c6d332e0ab70af833ae44e446a5419f411a5c2586c86c51277. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 18


Intelligence 18 IOCs YARA 17 File information Comments

SHA256 hash: 8243f0400ffe13c6d332e0ab70af833ae44e446a5419f411a5c2586c86c51277
SHA3-384 hash: 989f4a55dcbc36ffdd65641b5b19c3475c4bf7c3ff5001d2f020c8a09a02009e4ce756fda7bb8dbd6aa476ace165a28a
SHA1 hash: a20251798e3b226bf69fc57938ec5672767e72b3
MD5 hash: 0c72285fcd2eda1574978a9b01f5d58b
humanhash: golf-social-connecticut-lake
File name:SecuriteInfo.com.Win32.CrypterX-gen.28316.31463
Download: download sample
Signature Formbook
File size:769'024 bytes
First seen:2024-04-05 11:32:05 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'647 x AgentTesla, 19'451 x Formbook, 12'201 x SnakeKeylogger)
ssdeep 12288:e722e4FyGUH9mz9l9eGQtjFhA7ANHEaHD8069jvG3M6GJYEwCzLHYf4RE+ZOdKMD:x2R4HA9l9ePhdN1HAP6MHJzRdeWTj+ne
Threatray 2'193 similar samples on MalwareBazaar
TLSH T18FF4BFAC365079EFC86BCD76CA982C64EA6064BB530BC243901715ED9E0DA9BCF145F3
TrID 67.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
9.7% (.EXE) Win64 Executable (generic) (10523/12/4)
6.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.1% (.EXE) Win32 Executable (generic) (4504/4/1)
Reporter SecuriteInfoCom
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
294
Origin country :
FR FR
Vendor Threat Intelligence
Malware family:
agenttesla
ID:
1
File name:
8243f0400ffe13c6d332e0ab70af833ae44e446a5419f411a5c2586c86c51277.exe
Verdict:
Malicious activity
Analysis date:
2024-04-05 11:38:13 UTC
Tags:
evasion agenttesla stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Launching a process
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Using the Windows Management Instrumentation requests
DNS request
Connection attempt
Sending a custom TCP request
Sending an HTTP GET request
Reading critical registry keys
Stealing user critical data
Adding an exclusion to Microsoft Defender
Enabling autorun by creating a file
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
AgentTesla
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Check if machine is in data center or colocation facility
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Contains functionality to log keystrokes (.Net Source)
Detected unpacking (changes PE section rights)
Found malware configuration
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Scheduled temp file as task from temp location
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AgentTesla
Yara detected AntiVM3
Yara detected Generic Downloader
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1420809 Sample: SecuriteInfo.com.Win32.Cryp... Startdate: 05/04/2024 Architecture: WINDOWS Score: 100 42 mail.hoangtruongphat.com 2->42 44 ip-api.com 2->44 46 api.ipify.org 2->46 54 Found malware configuration 2->54 56 Malicious sample detected (through community Yara rule) 2->56 58 Sigma detected: Scheduled temp file as task from temp location 2->58 60 9 other signatures 2->60 8 SecuriteInfo.com.Win32.CrypterX-gen.28316.31463.exe 7 2->8         started        12 ZDtRxZXKIPq.exe 5 2->12         started        signatures3 process4 file5 38 C:\Users\user\AppData\...\ZDtRxZXKIPq.exe, PE32 8->38 dropped 40 C:\Users\user\AppData\Local\Temp\tmp261.tmp, XML 8->40 dropped 62 Detected unpacking (changes PE section rights) 8->62 64 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 8->64 66 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 8->66 72 4 other signatures 8->72 14 SecuriteInfo.com.Win32.CrypterX-gen.28316.31463.exe 15 2 8->14         started        18 powershell.exe 23 8->18         started        20 powershell.exe 23 8->20         started        22 schtasks.exe 1 8->22         started        68 Multi AV Scanner detection for dropped file 12->68 70 Machine Learning detection for dropped file 12->70 24 ZDtRxZXKIPq.exe 12->24         started        26 schtasks.exe 12->26         started        signatures6 process7 dnsIp8 48 mail.hoangtruongphat.com 125.212.217.248, 49716, 49721, 587 VIETEL-AS-APViettelGroupVN Viet Nam 14->48 50 ip-api.com 208.95.112.1, 49714, 49720, 80 TUT-ASUS United States 14->50 52 api.ipify.org 104.26.13.205, 443, 49712, 49718 CLOUDFLARENETUS United States 14->52 28 conhost.exe 18->28         started        30 WmiPrvSE.exe 18->30         started        32 conhost.exe 20->32         started        34 conhost.exe 22->34         started        74 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 24->74 76 Tries to steal Mail credentials (via file / registry access) 24->76 78 Tries to harvest and steal browser information (history, passwords, etc) 24->78 36 conhost.exe 26->36         started        signatures9 process10
Threat name:
ByteCode-MSIL.Trojan.Barys
Status:
Malicious
First seen:
2024-04-05 09:45:20 UTC
File Type:
PE (.Net Exe)
Extracted files:
10
AV detection:
16 of 38 (42.11%)
Threat level:
  5/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla keylogger spyware stealer trojan
Behaviour
Creates scheduled task(s)
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Looks up external IP address via web service
Checks computer location settings
Reads WinSCP keys stored on the system
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
AgentTesla
Unpacked files
SH256 hash:
71dab87ac5b7b80468ef8ccb16b74b39cc862b7fb9a6e430e4cd7e375dbe6c27
MD5 hash:
df9e546ebe70f8307bc8e6ad3aa08f0f
SHA1 hash:
d649fef8643e0a0c870519420522d5ca23dd7382
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
498b4a265a27f8362fea4fcf15a184b220475c891249c892406030eb3b245c00
79e473fb7f021d7b394ac013c2abcca1a094a918b6f2edb48c0ed18d7b3b7460
53ffe79bd4c176d257a5b0a5a147ecaa522356d3ea80ab83dc6f8c55bd545c08
2d4255b15429696714b3c6e55077d3d95cfbc71a746406385cc4ba5025eb6a45
da6f3f1f642c13d2b7bf4c86e2686c5e1b606dbe0838423998c15742940545e9
a48b8a6ca726f32569a7e2041803898a902437ee7724da53accfb6dc52fa8a87
c94be0d3693316359c2e48e43baf51dff4f0b8d5efab6050962a09ef46ead4dc
24798002b81be4c9b37539e1abea61cccb014cbd427fe1a27d6822e1ffedc7d9
9fc2770fbd67c9b6f9f244ac6ac0fa8810c3d50e08c7d77b332bf1447ab77fab
2c8008052d15b5a7a61808357f2085226f7f9bc9619bb2040c27024a6423b9d2
1ba9c4dfbdfb55f6588c8887006f2851716eb6e53eb2bd1bccd591aa9e182da7
413bf66fb3f4c507d5e04fcd975056619d5874af3b92fa59eb9db52d18e2928b
38f97adf003d63f84a6c5bc35c9d9096901e7292e763bd9fbeabdafa1aa5fa78
12f1562e82415f8f320bc830dc6047870ea78ceb7e827af394dbe428d8ebc930
450160aa7afe149bc82992b2dd8f44fdaf64fcaec24d7b9c8522251f538a7636
859876f4be1e8206802a3468eb52a143bf5bc15724c0b66b70d98edd79c06a08
f48dfafeefb4b36315d6b8f987df1026d29c102bd24703a08cc4d4d41a483505
5408e8b840c407984e92034c26e937b1785c5f4b6762b14f2f7a31cec4d982d8
74a07ee3f0060987ebcb09e588ac1299a9d2a19e2f4139385f7880c229e2c8cf
da1903e676a7609f931a23ef7a653af4c1be9ef5242a80bdca67cb076d372bfd
cf432fc47407df80dcf984cf5d8d1a6aaed7c8c2a4c9b3a76627b4194bb9c782
73c44dbb7ece4e2fee17409d2d0ebcc82a77dd86c7ab0c9da9d8453cab59fbcc
c161b936b669673a3441c19755270abebe800846e8a01be9477e634d91b44635
191239a61c70ba900694d294a164f4a162b84d11672871fbb5389967bbf52c7e
ff2ae4fd71daa1a98edd5f88b743a5daa5fb29f70b87dee08fec25313a3640f1
554b40336bad24df88cbde544cdf20d553d02ce7fee5dab9a82318d7c21471e0
bc5f1294caaee05297ad1547f2f6ec4a309c16f7caf906f21038269d72f54957
15df84ca3a0c112b7ab461d6ee7603fcec8e24da91d4042d3ab018f87530b6ac
32aeea1990475960922b9a0bbda5a7edc864a3c70e4b8c5e84b16e269ea6fc7c
677f5939951053c165cdff92b6fa68d53748365869a978b77c2a501a46d1c4c8
67a792fced715c64610c55d8c01b16d66080c10004ed572e664c324468afdd7d
02a5ec5d9037cdd26b3f1ade8ea4028fbd0947284bfb3d7649e065d22db0ef91
704427aa451d261a1a92a6e834a1ee2be50971a012e711f9f660403904a9622c
6fd8e845cfa1bf8f809f0f372c2d4e955c6a3b6c0e88fb8f474a2645f587ecf0
9f6eb9b6b3bf92a75e32208dd51ce6307fa5ccdae27f02f0c7e2712544c2c04f
8506e0fdcf9ce49bd939a62bacd3e4d1af3522d72e660382684b1e4d1bb8e6b7
8fb359ccf3a3b6a0eff8204f9ee27c2dc41b3270721716192a7ef9253453b59b
8f53280f0b7807f08cf03152768d385200db1ad864b256fd9e7decbc846b05a2
70517116e2400906af6125849ac27b66159a45f6f1782178351e82bfe5ba205c
1711d935991cb37bd208dec08aefb47cf049baa4aa465d3188feccd8d330e72d
b1a574a7a0aad03e9f0a8470fd53013c565e67461ff21fc79e1bb6205974adb1
190504e991bb8bb608cf87db9ee7c7549999a17970251490ce85282f85cb49aa
f4eaa74eb268a58cff6f5d37607758bd49cc00af060da799857ae10cfd59efb2
8243f0400ffe13c6d332e0ab70af833ae44e446a5419f411a5c2586c86c51277
2a0a27371b6f4d355c3264fcc668d8a0fe1af7ebb8b19dca3b5cdf20a3282d65
f486a970c3228b346008eb169500d373560ea047084818b77357ba68bfa960af
8f02ecb26530c0a13b7f00020ebca144fc271fe36a5caaba1f4b3270e8e0023c
bd7f924e17174165e42ee077f973be26f07c6653ff33951ff9c53fb7cc833bae
1dea51f5680fedc83402ccb9401ae907c9493ef8625a76fe6f6cd9f475021e6a
a433dfdb99b293b73898ac05be0fbf6baa9d79976655b0c51ba5a5a0066a2632
b1f7d2a6fee6eb162c9e154b565ee6fe95c6e03fa15bef35d8c14663b844087c
da86da7fc086aa8262222feed9f4cd4df4c4538e77d90a7c160b1c794f298b92
ef8ad9042176ddf7dae5199f0135c2efabf224a45ac52f0ebc054b7ee9806c04
efb67364fa543ceddc607094c10c4b71f3baac1f45de5c2c759c489f97a64ec2
47cf473f0a0c146e5ae4a37b987c297be41d82af40d53e4dc750ca9b66fa7ea6
9d1f9f7012962df24baa3c3ac0816333abecf2a433953f68dab7e7673fac59aa
4b4c3585bbf95af33fac18ae92347069e2b732626cc6c7984ebfef92ea0a89b0
31fea186e7379793d1d9b37d2a981ed0fb05d40ee7d62e227eac695106ebbe2f
d23bd1fbaae83547ec6aba06ad8b4eef5119bd4a0f66634a6726b6ccd5dc3c78
dd14afafbf11a0251a0c5c56b3ef8b0be205cd4ed5d70fe77df7fdc90a039a4a
36ea8608df9b009caf566d4309832531c532d9eaf5c28b5b1657acf54c471209
95e4dd6cc5a341f4440a113e0a832175aa2f5baafd9c7483255a18088e1c2764
44ba13a119d19891a586d95310d8a51e9440fe2c1659b397d5795ecab37e3eeb
SH256 hash:
bc39c3ba2ef220300f37e0ccffd84e387eaa28c831859c3588cdfdeec243b0c5
MD5 hash:
e4c53cafec45a303e00d4d7702b02822
SHA1 hash:
bf21964cd02330655a1eb04fb83ece35899977bf
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
5d7b1224c77b4413e49156de8a050fdcfbfc5cc75b3d73c13abd67475ddabd3c
70f27cc87397701a73835625b0ee8caf3ef97b506554f2a7f65c2c08afd264f7
f7e3d289131a067c332064bd6f6cb7d336f0fb0476af14eea1d1b1a7127493a9
c1ecdc617db839e561aa5318e3458ce0f0db30386f8b9cb5586314b2e75a8a7d
54a4891d6753b4acaa07bb6c01aebcb44a0140ffc05ccdc53785a74365969585
2843aae844d0b90a78597dc383828ef6d67ecc6e3d5e689ca4567bc823383b72
994e690703864150e91ac5f4d3cd5264d45e2ecc182424bd5285cbf935cb855d
37c4f4f899e08371042e4b4cc03b87297989ad424c62228a7a50293f2ea7de22
921d900f4ba05b2c93f5ca8076861ea60f698eecc36e4fd6013a415592e3272d
82048072a8cf203444037aa1f037b305437c7a273811a2287f2a5addb2cbcb41
c7a16881f8c69d16a9b0bdcbfdd5c4aada81eba19521d1c03ee7f6005f7d6629
78b15621d0319e8b7a105e1aa9a1927fb434bfce29e2a4f56051f552e393f08a
12c7ec6f047ebf12cb9f142bb71fb0de5a61de79286776440b5814c94d93e2e4
9f70d8532d4c8655671ecb52609c6ba9e8e34dc0b08cbb92ca795b59a9bdc862
ce213fe45b524d85486c2f3956e17a333b2d8ecbf1d73078bf56014cc1c7702c
31462fecb3ea50e9d958b14e99acf10b91ef3207224f82a90c6b15f0f1d1285a
7f610fb90140292d4a5dfcb4bd0e691833307a428714f6381fefaa6c39bc5bed
94279f693b7bb1c21594d96e572ebc15e6aea416816b03d677a3875ebb84a99b
413bf66fb3f4c507d5e04fcd975056619d5874af3b92fa59eb9db52d18e2928b
8243f0400ffe13c6d332e0ab70af833ae44e446a5419f411a5c2586c86c51277
9d4ba0d30577e0398c95e01ff42e2ea2f2f02dcb50ff3202f6077de094e7a439
46c5c413b31c08c49b03d6de4ddb926863d66a7d0b39b7b30cb340d2cb963ad0
cd00f31be2b7bb08d5e499cbe39d3ab9d5aac66ba0a5e5ffc3e97bd9cc598fc1
8ab205dc4d6f7c232cf9e2047a6abf4b2bb6425258cefeaf9b05e922c8229c6a
32b7561a0ed879b965b01f99cf9cd249f533104462bbec8ff65a4607f61d75ec
d302ca49fbe8a59c391e8de2ba44683dbff2e9b97fd136b9dea96f4354defb62
3edd3fe6434d631459584bfef13f646c14866e7d99121a3067d10f1e330b28e6
18f2d604285e3f9987eb47ae56cda190d11ae271a5ac05f0413b2c988ae241e1
5702612caa2cfd626ce28bb1e173d884d5314e0922bca28d979e7bf5158441e2
SH256 hash:
cf825a935b947c55dcf36b72f13d9fe159dbc957571c662c1405f0bcac4d3b63
MD5 hash:
949992271b2b8b584cee62b0e81dc60e
SHA1 hash:
6803126b895d1dd7a43971b1c9fd7558c3be40a1
SH256 hash:
9ddc829df188f81ace8bd2a00e3358e24909f98363c4405eeba8c9237f74db6c
MD5 hash:
eac7ff4dbd439ecc7f977eb4d1773160
SHA1 hash:
2926d00283d397930806b059c6cea19ff84a20aa
Detections:
AgentTesla win_agent_tesla_g2 INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients Agenttesla_type2 INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients INDICATOR_SUSPICIOUS_EXE_SandboxHookingDLL INDICATOR_EXE_Packed_GEN01 INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store
SH256 hash:
8243f0400ffe13c6d332e0ab70af833ae44e446a5419f411a5c2586c86c51277
MD5 hash:
0c72285fcd2eda1574978a9b01f5d58b
SHA1 hash:
a20251798e3b226bf69fc57938ec5672767e72b3
Malware family:
AgentTesla
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AgentTeslaV3
Author:ditekshen
Description:AgentTeslaV3 infostealer payload
Rule name:AgentTeslaV5
Author:ClaudioWayne
Description:AgentTeslaV5 infostealer payload
Rule name:DebuggerCheck__RemoteAPI
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:INDICATOR_EXE_Packed_GEN01
Author:ditekSHen
Description:Detect packed .NET executables. Mostly AgentTeslaV4.
Rule name:INDICATOR_SUSPICIOUS_Binary_References_Browsers
Author:ditekSHen
Description:Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers.
Rule name:INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store
Author:ditekSHen
Description:Detects executables referencing many confidential data stores found in browsers, mail clients, cryptocurreny wallets, etc. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients
Author:ditekSHen
Description:Detects executables referencing many email and collaboration clients. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients
Author:ditekSHen
Description:Detects executables referencing many file transfer clients. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_SandboxHookingDLL
Author:ditekSHen
Description:Detects binaries and memory artifacts referencing sandbox DLLs typically observed in sandbox evasion
Rule name:INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID
Author:ditekSHen
Description:Detects executables referencing Windows vault credential objects. Observed in infostealers
Rule name:malware_Agenttesla_type2
Author:JPCERT/CC Incident Response Group
Description:detect Agenttesla in memory
Reference:internal research
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Windows_Trojan_AgentTesla_ebf431a8
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/attack-chain-leads-to-xworm-and-agenttesla

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments