MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 99737bd60422defc150edf7e1ec863acd6d2e599e8139aa987b6b4c43ab18cec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 99737bd60422defc150edf7e1ec863acd6d2e599e8139aa987b6b4c43ab18cec
SHA3-384 hash: ef8e38c8d0670b0625bf093666d12149cfb4c3565e375d81d2f5ab75f18d9b0ad1d9bc333fc63667d1a7a112fca00406
SHA1 hash: 09535f0a8d2dbb233a8e6d910e1b7daef98663b2
MD5 hash: 100f2664cfdf13b8fbbb4c5da2640aac
humanhash: fifteen-oklahoma-pizza-oxygen
File name:utasarmsinc.ru_live__emma001.exe
Download: download sample
Signature Formbook
File size:569'344 bytes
First seen:2020-03-18 19:24:01 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 5dd5b48ad7b764ef2f5ab81dac9cf32a (1 x Formbook)
ssdeep 6144:i6Y8x3DnYjI3R3vlkdSdfQMYrZs2ggiuMwl3ycjza5ij:h74I3R/OdSboSwihT0j
Threatray 4'829 similar samples on MalwareBazaar
TLSH E0C4683CE6FD06A8F99D507B36E1C9B251D02C6894321BC67C3E3BE296B761C6CD1A05
Reporter ov3rflow1
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaSetSystemError
MSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef
MSVBVM60.DLL::__vbaErrorOverflow

Comments