MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 933635e63b946b9090a7e4ba95a0dc48382cbdf4c5079c2b1809a8b107337391. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 933635e63b946b9090a7e4ba95a0dc48382cbdf4c5079c2b1809a8b107337391
SHA3-384 hash: f41ab366a3c647622c73e06346d28b98c3999edc79f6dba6679f071ffdd9ffcc94805a0a73c5841a3b1210dc66c63f16
SHA1 hash: e3303d8109318dd89ee7ce9b9db7568eaf799b8a
MD5 hash: ec96e7f23610c56ffe4a47efe7cbf9f3
humanhash: carpet-six-cola-thirteen
File name:PO FOR COVID-19 PRODUCTS.exe
Download: download sample
Signature FormBook
File size:65'536 bytes
First seen:2020-03-30 09:46:31 UTC
Last seen:2020-03-30 12:13:05 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash b7e5c562b1cb1a4da49470d040f657b8 (1 x FormBook)
ssdeep 384:YlwcripX2rNGn/OWhIAzHKP4CqNE5MSyeVvf9GwPzsrek4mkEKcF7o1ywdnv3zdV:FcrzrIn/OWhIu5/IHswPzsrj4mUq0F
TLSH FE53E651B3745265F26D17B26CA58B548E21BC302845CA3AFF783F6E1836683B9B0737
Reporter abuse_ch
Tags:COVID-19 exe FormBook GuLoader


Avatar
abuse_ch
COVID-19 themed malspam distributing GuLoader->FormBook:

HELO: mata.com
Sending IP: 173.82.151.178
From: Candice Medpace Medical Device B.V. <edyth@carrollndixon.us>
Subject: Purchase Order (PO For-COVID-19 Products)
Attachment: PO FOR COVID-19 PRODUCTS.arj (contains "PO FOR COVID-19 PRODUCTS.exe")

GuLoader payload URL (FormBook):
https://drive.google.com/uc?export=download&id=1UY-m7ByYJgaXFwe_acHJZrBf3_z99-DK

Intelligence


File Origin
# of uploads :
2
# of downloads :
98
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-03-31 00:45:48 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
24 of 31 (77.42%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
guloader
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::EVENT_SINK_AddRef

Comments