MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9347ae026aab2c86f134615a932ab0244f25cc8c994ce8ed96ca07c698c7e743. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA 8 File information Comments

SHA256 hash: 9347ae026aab2c86f134615a932ab0244f25cc8c994ce8ed96ca07c698c7e743
SHA3-384 hash: f0001418a833fff4915b81f4dbf6003f60d046102c3bc25c55687030d918d72089f24f899911ad7aeba9d04d397366e1
SHA1 hash: 48d54e68530e08678dddd3428b3da527a7ba4fc1
MD5 hash: fb1382c88ab553864413df9410063163
humanhash: beer-stairway-wyoming-iowa
File name:QuoteSummary.img
Download: download sample
Signature FormBook
File size:462'848 bytes
First seen:2023-01-24 14:00:50 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:JYa6vkDt/cnsThphI8z/F6zFaIWZ94pmVC+GHfgz:JY1kDt/hiBa994cHGHI
TLSH T152A4AC03EBB6ED77D6F176FB0414B1151D6D6E910CE27686326CB588FEB3A42D848283
TrID 99.4% (.NULL) null bytes (2048000/1)
0.2% (.ISO) ISO 9660 CD image (5100/59/2)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
0.0% (.ABR) Adobe PhotoShop Brush (1002/3)
Reporter cocaman
Tags:FormBook img QUOTATION


Avatar
cocaman
Malicious email (T1566.001)
From: ""Cindy Jospeh" <sales@autolider.com.tw>" (likely spoofed)
Received: "from autolider.com.tw (unknown [95.168.173.183]) "
Date: "24 Jan 2023 06:00:04 -0800"
Subject: "Quotation Summary "
Attachment: "QuoteSummary.img"

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:QuoteSummary.exe
File size:409'419 bytes
SHA256 hash: 4873abac800f1c2594fdf8802b84ecfbdb7e704c0d46ff5edf66f46ec7a692e7
MD5 hash: f15b261228ef2d9060730543739abd09
MIME type:application/x-dosexec
Signature FormBook
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
context-iso overlay packed shell32.dll
Result
Verdict:
MALICIOUS
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:SUSP_EXE_in_ISO
Author:SECUINFRA Falcon Team
Description:Detects ISO files that contains an Exe file. Does not need to be malicious
Reference:Internal Research
Rule name:Windows_Trojan_Formbook
Author:@malgamy12
Rule name:Windows_Trojan_Formbook_1112e116
Author:Elastic Security
Rule name:win_formbook_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.formbook.
Rule name:win_formbook_g0
Author:Slavo Greminger, SWITCH-CERT

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

img 9347ae026aab2c86f134615a932ab0244f25cc8c994ce8ed96ca07c698c7e743

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments