MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 88edce54585b6fd0c886090c53e8f8db451fe67eb1bbafbeac17fcbd694392e8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 19


Intelligence 19 IOCs YARA 17 File information Comments

SHA256 hash: 88edce54585b6fd0c886090c53e8f8db451fe67eb1bbafbeac17fcbd694392e8
SHA3-384 hash: 5e961d68aac06ff758c91f94d67b3902680d2a6b64ff62ea1683665503feb953171048dabe81a8f598254e1bd35b6eef
SHA1 hash: cd1b610b631c64fd3ed07979989cf374a2000175
MD5 hash: 70b20ecb0d4c9fb5705d40595d949fa2
humanhash: fifteen-stairway-tango-oxygen
File name:LkB5jzyXXsO56fk.exe
Download: download sample
Signature Formbook
File size:646'664 bytes
First seen:2025-05-05 08:23:26 UTC
Last seen:2025-05-05 13:10:46 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'462 x Formbook, 12'204 x SnakeKeylogger)
ssdeep 12288:Dd9tCo36PSmDjiOmlY8kE9u+Jz5xGnEdIxoxOPOSVokR:mSmD/KY6uqF4EdIKOPOi/
Threatray 2'552 similar samples on MalwareBazaar
TLSH T1F4D412594E4AD903CDD20BB50261F7366B70AE8DE820D7038FEDBCEBB8A2B54165C355
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10522/11/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon 70e8e09e9ad8d0e1 (9 x Formbook, 3 x RemcosRAT, 3 x SnakeKeylogger)
Reporter cocaman
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
436
Origin country :
CH CH
Vendor Threat Intelligence
Malware family:
formbook
ID:
1
File name:
LkB5jzyXXsO56fk.exe
Verdict:
Malicious activity
Analysis date:
2025-05-05 08:29:53 UTC
Tags:
formbook stealer xloader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
96.5%
Tags:
virus micro msil
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Launching a process
Creating a file
Launching cmd.exe command interpreter
Setting browser functions hooks
Forced shutdown of a system process
Adding an exclusion to Microsoft Defender
Enabling autorun by creating a file
Unauthorized injection to a system process
Unauthorized injection to a browser process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
expired-cert invalid-signature obfuscated packed packed packer_detected signed
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Found malware configuration
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Queues an APC in another process (thread injection)
Sample uses process hollowing technique
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Scheduled temp file as task from temp location
Switches to a custom stack to bypass stack traces
Tries to detect virtualization through RDTSC time measurements
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Yara detected AntiVM3
Yara detected FormBook
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1681168 Sample: LkB5jzyXXsO56fk.exe Startdate: 05/05/2025 Architecture: WINDOWS Score: 100 67 www.873013.xyz 2->67 69 www.xectgroup.net 2->69 71 10 other IPs or domains 2->71 83 Found malware configuration 2->83 85 Malicious sample detected (through community Yara rule) 2->85 87 Antivirus detection for URL or domain 2->87 91 8 other signatures 2->91 11 LkB5jzyXXsO56fk.exe 7 2->11         started        15 VqSbXDysSIpe.exe 5 2->15         started        17 svchost.exe 2->17         started        signatures3 89 Performs DNS queries to domains with low reputation 67->89 process4 dnsIp5 57 C:\Users\user\AppData\...\VqSbXDysSIpe.exe, PE32 11->57 dropped 59 C:\Users\...\VqSbXDysSIpe.exe:Zone.Identifier, ASCII 11->59 dropped 61 C:\Users\user\AppData\Local\...\tmp8D49.tmp, XML 11->61 dropped 63 C:\Users\user\...\LkB5jzyXXsO56fk.exe.log, ASCII 11->63 dropped 103 Uses schtasks.exe or at.exe to add and modify task schedules 11->103 105 Writes to foreign memory regions 11->105 107 Allocates memory in foreign processes 11->107 109 Adds a directory exclusion to Windows Defender 11->109 20 vbc.exe 11->20         started        23 powershell.exe 23 11->23         started        25 powershell.exe 23 11->25         started        33 2 other processes 11->33 111 Multi AV Scanner detection for dropped file 15->111 113 Injects a PE file into a foreign processes 15->113 27 vbc.exe 15->27         started        29 schtasks.exe 15->29         started        31 vbc.exe 15->31         started        65 127.0.0.1 unknown unknown 17->65 file6 signatures7 process8 signatures9 93 Modifies the context of a thread in another process (thread injection) 20->93 95 Maps a DLL or memory area into another process 20->95 97 Sample uses process hollowing technique 20->97 101 3 other signatures 20->101 35 explorer.exe 87 1 20->35 injected 99 Loading BitLocker PowerShell Module 23->99 38 conhost.exe 23->38         started        40 WmiPrvSE.exe 23->40         started        42 conhost.exe 25->42         started        44 conhost.exe 29->44         started        46 conhost.exe 33->46         started        process10 dnsIp11 73 204.79.197.203, 443 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 35->73 48 msiexec.exe 35->48         started        51 control.exe 35->51         started        process12 signatures13 75 Modifies the context of a thread in another process (thread injection) 48->75 77 Maps a DLL or memory area into another process 48->77 79 Switches to a custom stack to bypass stack traces 48->79 53 cmd.exe 48->53         started        81 Tries to detect virtualization through RDTSC time measurements 51->81 process14 process15 55 conhost.exe 53->55         started       
Threat name:
Win32.Spyware.AsyncRAT
Status:
Malicious
First seen:
2025-05-05 03:22:09 UTC
File Type:
PE (.Net Exe)
Extracted files:
7
AV detection:
26 of 38 (68.42%)
Threat level:
  2/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook campaign:hi13 discovery execution rat spyware stealer trojan
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of UnmapMainImage
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Checks computer location settings
Uses the VBS compiler for execution
Command and Scripting Interpreter: PowerShell
Formbook payload
Formbook
Formbook family
Unpacked files
SH256 hash:
88edce54585b6fd0c886090c53e8f8db451fe67eb1bbafbeac17fcbd694392e8
MD5 hash:
70b20ecb0d4c9fb5705d40595d949fa2
SHA1 hash:
cd1b610b631c64fd3ed07979989cf374a2000175
SH256 hash:
b242ad7fad9723e769340e8d6de52706a504dc76d5ad905d4be8a78c5797e7af
MD5 hash:
2aa140d7e89a34db2261ea546d554348
SHA1 hash:
7bca5d640578d47445ee6933fbeaac6cda78eb10
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
0013e6d899c343df37d42e9aea6a40a035021195b544f6c442ff98094501b5a0
865d757dbd675369b749dd68b1da5f785900d98d39386376e3464422248fa561
024537bcb5cb2e33a164a13fa87e13dfc129efe2dd656084f3954f4ba5a821e1
fe425f034245df80aa7de7f613c39ecc9801077ccb38d23f153ba9076c1e6f35
134c8c01c688d2f6a23765c6f917633d2c9f440e6c37753874ddd938862b1ff0
efa9015c2a50a3b7184d201badbe5037764e8dbf61d4267f1479f2150f219d02
b3b3d2e1dfc77efa21b337da267d93da1e3900625c6670e3629d20340e9f0dd8
f3b03dd677c48f38d3e407c423b77ff7b8e5a51cf096cb4673f6f0f016bd6b3c
e3cb3001029182361258d524410fc51f780eca6363a2fd292856bab3326678d1
31e9d19c8f6d7662f150210f4864740af71b58a9f71350ba27167f403d2bac6a
2f94407595db6811148d80660ae322c360c7c5935adaafde9996b6cb610f26e7
7499f69524a85e3fef6b56b14254f87ba6733de5c21f2b0fac5832aeb095e77e
88edce54585b6fd0c886090c53e8f8db451fe67eb1bbafbeac17fcbd694392e8
d4a33be36cd0905651ce69586542ae9bb5763feddc9d1af98e90ff86a6914c0e
d1c11f1e8bbb7eea6fec0d0cd0657ea9145206b91e7220374b771b7ca4b79010
83cdcf1f7b8b580c62b4bc74e0ec2eb1fb18e2229335179d4f333c6b5f52f4ae
fd0049f3bb1393c8192f8053301b8472a18f1bbedb4011655d756fbf3a0b3aa5
0578eeb29bd6418a75a34d5809cc64bcf903cab949060ad38cb2224d23bec10c
b3752b8138360ee7ab6f3583c942f1d2ee806f7ede9123ada34abbf27a055633
e9dcf2288b4adbbfe01de0f952df0f050ef533fa151e77b786ceee577f51a079
247e21229eb4b45928cb2aaeb92a709c3c1e2ce241d99a189775fed95a781e07
9262bb8d45b86ce3583351d99db66eeb3481102a260477360d93185677da2863
138279e950c38c7a2d3c554bbb5b91ea55e7d0c87241c455650d9cc7262cbf6d
80178f684d8914808b1717c7b39b77bbfe616859cee6e117be0f25a99c02fc76
64f00b4e38add0516c0e601276579334518245702815d8fbb4b7c83a77866058
f6b63b291d9596ec5ab7aa65997850c9ac23feb8e5e67a1bf09dfc84221d10bd
4d7aa33e9b949ab328335825604b5e45050c5a5d947a275c650553e0e9f26132
68f21baa9f00e498b8b31630e46addb81a4b4ef3f86d097708b6d6540fdcc8ac
5f63d86d5175fe1b15194dedb48e5eadb0ae1f4656b3ca86a2055df558bdcafc
071c7e6ccfdfb3e88afad91f2e52148213aeb6c36d11155b940f6eaf57642cf0
fa07c7fc145471495727561a074add9874a3572f46dc6c340c3ed1d8646c032f
01b4740a5c1779f464a381836e4b5e95e8e360b46cd95d492cbee029ef06f029
6a39c812d087f3b770de7c05669007bb83d9fb0fc9563d17ee726c96d872af59
8fac642a58b28ce2d0d152bb0dfefc539f85dcbadc6fcd3de2bd9b060b4625c7
9e3ce6488f70a8cddb11c36dc9dc9cdd9cfffabd699d56237843377df8afa5c0
2d51ee60b5d5dc2bdd5de9319b9d174862af7bb205addfbe895bd59df9ac4a64
fd1f814527b20c677b1d8b366be6b75c08219b5c315f0d0d9f8535a13aba2c47
078cd1b6995a95e2057591899a7050da5799ad226afefd75fd442060efd1b027
083f0da491a84fd49f5abfc07b65d65931c1be5675a6a878495bc80880d98865
be0de5c578271405defd5391355546b521881957b891d7423f1d0a7d04cc6bb3
d4020dbe1d51f7f27e253deeb65f1fed6b788091f5adad460f035256ae198a81
b7c25110371e04e935dffad7ec2364cef2725b474f2d62064a369d0e1d3247ce
de1c33694def3b635687a1be3fd3ea586273ef148a664b566b02b187ef2688db
4b6a5d12756b9e746f8bb79d52298927a1116f659e89b8727d0f3f188e1638d9
96abdb9ad0db8612acab489da720957eb633e12c74e6de77d3e81dab6b7b63b5
83720bec38d91097735649d6c29d406f7c1d7521f67e69cafce0437743cf3ebb
ba9856286b079931468e0a80830ae8855efdf38462f467dc7bc91f8a0ccd39e5
736f86e7a431a4307a6ca7ff1650d32a8cb8d68426f6336f87b2041978541d6e
e22479542da314d41da623dd86740e38da3563ea109c0f258e1f6c8993fd468f
73d47bc6706b395ab8a96c53d23af3eaf4faf4c8b92f595b0714c8040096bd5b
b9b8fb27a1f249497e04a36a2c0add5059138a953982e91fa26b293e7c15ef41
f86c8270277c5a7e0213bd9b864d39602f4e46364323b18ea931eba3573ac2aa
b7c7a3bd36dc7993df91c0a108529dd073751f8dc823672f47e5ba128be0f4db
SH256 hash:
0cffb54de93727810029549b41b54e97187f4479133e17a92008cbfb102903c7
MD5 hash:
69f37959c69f2be1dccaa10dcc452c45
SHA1 hash:
9d2959f971fb45fcffdaa96f86d67a2d7a85151e
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24 SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
f7b2a1307788383e625f5e97e8b6493d83d3d5dc92e6668b4021089c31f95b60
MD5 hash:
01dee027b928c11106c8eedee12872e5
SHA1 hash:
9688743d5cb6c7d6bf8bc89b32c8336f3f12293d
Detections:
win_formbook_w0 win_formbook_g0 win_formbook_auto FormBook Windows_Trojan_Formbook Formbook
Parent samples :
c90b2d72296b49c72b221773c6fcc65648e0f0aa7ffc62611681c9cd07e6bf32
59c68aa4d3b5e77347aa69a31f2592220359ff8f45c18bf9ef5ad047e072534d
d22f35b2e413df2285d73d888f9ec91025121fff5fe29c98982e9952c2f3b730
5cc4e78268ea872c52ba12d08a527a7da6a0abd65d7b1aaabc2d56ae4edbdef6
3489a2eab1c57d0eee2ce6e5773e1f4f53ee6e5d8963e0099efc7e190d0c2f1c
6036a28c74493ce0e6d87a468959a047011d2e6cf63807d9a3d154b8642d7e65
6d0a73c255453a2539a63dbeae565abae36b527cd6154691b3c066f3815860ed
9948ae75550edf04cbad0aa67a427908d5f5dd86bae12998ff9e4debfc28a645
896dacfb811fcde80b97bb497aa5abc2dc3bcdedae8c0791512b208aea6b65bf
4ef55b210c4174c2efecbe5ca507305f44226fb26340ff93e36fb65c72b3e181
15b1dd61220782f0fd48d6ca10e0a556e036f2ce0450e443ee33a57fb6dd4ba9
b4f779c06421b878976598d11fe86b9cf3b92a04d93c9ce11b57772876ccc2ba
d6ff37cf17f73dc09e1bb459d7ebec5bfe3ca0acac5924ebeb15c01e1d5985eb
bc407aec3c1515d5cf405c36da5d2336361e57dc07afba016a5a6379b56892fa
2caded000f82486caade3eeb6c47d446037abdcb39a2ba127b58c9fc67d15f33
035cf98a4ed96281ec028ec33c8a15c578e3157f9a1f8e90e95ddbc6204ada29
b75676a458b2251a7e86d7aa12dd1d26f55d49d60af2c4fc534274a8fc170501
0013e6d899c343df37d42e9aea6a40a035021195b544f6c442ff98094501b5a0
024537bcb5cb2e33a164a13fa87e13dfc129efe2dd656084f3954f4ba5a821e1
80c1a0b48688c83d7c1532da5d5871618838eea438a4262a0c36ff21d5914c2f
88edce54585b6fd0c886090c53e8f8db451fe67eb1bbafbeac17fcbd694392e8
83cdcf1f7b8b580c62b4bc74e0ec2eb1fb18e2229335179d4f333c6b5f52f4ae
0578eeb29bd6418a75a34d5809cc64bcf903cab949060ad38cb2224d23bec10c
68f21baa9f00e498b8b31630e46addb81a4b4ef3f86d097708b6d6540fdcc8ac
5f63d86d5175fe1b15194dedb48e5eadb0ae1f4656b3ca86a2055df558bdcafc
078cd1b6995a95e2057591899a7050da5799ad226afefd75fd442060efd1b027
83720bec38d91097735649d6c29d406f7c1d7521f67e69cafce0437743cf3ebb
396d863b28cfe0297b99865faa37c6a7079547e0c275bbed4c4c0ce7451af4d3
285bd22ba49a3de603e9fff856a0bd3111e43629ad29e24bb41178afd93ece23
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__GlobalFlags
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Active
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438
Author:ditekSHen
Description:Detects executables signed with stolen, revoked or invalid certificates
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_imphash
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe 88edce54585b6fd0c886090c53e8f8db451fe67eb1bbafbeac17fcbd694392e8

(this sample)

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments