MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 89801979a78a0f635526ad4b9a31a63cbc9600fc6f49d26cc3b2a76039f4a940. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 89801979a78a0f635526ad4b9a31a63cbc9600fc6f49d26cc3b2a76039f4a940
SHA3-384 hash: 1726adf842f4d01d513947422d97ee4852a6494a620a9e9f078122668e39f8bf3b27c3683ab4605aeff7d2c7c2c49286
SHA1 hash: 8f2c06aeaf6a8b917423a28fd68384a423f65642
MD5 hash: fdbec925fa1746cf0d9590fea5f6ca50
humanhash: cola-one-foxtrot-montana
File name:08dd6b1d409e6af1e3804e1d7a673b6e
Download: download sample
Signature Formbook
File size:335'360 bytes
First seen:2020-11-17 12:18:11 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 3c71e8f02dc3eee71c99d7c46768840f (4 x AgentTesla, 3 x Formbook)
ssdeep 6144:98ed+0orVKaS0jgo2pkoAcX3UsqxcZholz/v4CjBCgr6DZWOYgoMA45xUmJXOzVS:ied+tVh+XEsRMD4CQZpYfMnFB+VS
Threatray 2'942 similar samples on MalwareBazaar
TLSH C164E03478D3C472D863003544A4DA719A3EFD327EA5E89BF35437A89E702D2C629DA7
Reporter seifreed
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Unauthorized injection to a recently created process
Launching a process
Launching cmd.exe command interpreter
DNS request
Sending an HTTP GET request
Unauthorized injection to a system process
Threat name:
Win32.Spyware.Stelega
Status:
Malicious
First seen:
2020-11-17 12:23:51 UTC
AV detection:
26 of 29 (89.66%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
89801979a78a0f635526ad4b9a31a63cbc9600fc6f49d26cc3b2a76039f4a940
MD5 hash:
fdbec925fa1746cf0d9590fea5f6ca50
SHA1 hash:
8f2c06aeaf6a8b917423a28fd68384a423f65642
SH256 hash:
810e49cfa84ab5921f3ac51aa5f0bba28dea8c300b209bbd226116333fbb3e8a
MD5 hash:
e3c2de6d08fcdd86b7f9ab0bdeeae64e
SHA1 hash:
763241fc9d5c586889bb038ac85e5ef8cbd29211
Detections:
win_formbook_g0 win_formbook_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments