MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a1a538fe935e970518aa2e5c454afa8e6b5cfb0f6defc5659b3b9e9998e7fdd9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: a1a538fe935e970518aa2e5c454afa8e6b5cfb0f6defc5659b3b9e9998e7fdd9
SHA3-384 hash: 4efaa1fd1608e3d84a22aa0bea7ce0480521c0572ffdd387adddd11be69bb00e86c246a30006eb7835a0a50145dc3d2d
SHA1 hash: 9a1fc8d79e40f14944af565182cc7ad8e514ab30
MD5 hash: 58c061cf43de53456cfe636c6643f4e6
humanhash: nitrogen-robin-triple-yankee
File name:SecuriteInfo.com.UDS.Trojan.Win32.Formbook.gen.12577.28976
Download: download sample
File size:71'680 bytes
First seen:2022-04-13 12:44:32 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 85c67b53d7f7073bce98826cd141c0d3
ssdeep 768:/rXofa78om6P8yMW/b/EG8a7K3u/yB0loFi3nzNKtc8WjWsWjcdlUeoUBpVMgu:jS6P8HIbqawAysnwc8DsWjcdlUEgg
Threatray 313 similar samples on MalwareBazaar
TLSH T174636C03B6E188B1E0B3063218F4CA51067FBE226E758D9B7394268E5D751D09F36B6B
Reporter SecuriteInfoCom
Tags:exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
335
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
SecuriteInfo.com.UDS.Trojan.Win32.Formbook.gen.12577.28976
Verdict:
Suspicious activity
Analysis date:
2022-04-13 12:45:44 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
MeasuringTime
CheckCmdLine
EvasionQueryPerformanceCounter
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm formbook greyware
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 608664 Sample: SecuriteInfo.com.UDS.Trojan... Startdate: 13/04/2022 Architecture: WINDOWS Score: 48 12 Multi AV Scanner detection for submitted file 2->12 6 SecuriteInfo.com.UDS.Trojan.Win32.Formbook.gen.12577.exe 1 2->6         started        process3 process4 8 WerFault.exe 23 9 6->8         started        10 conhost.exe 6->10         started       
Threat name:
Win32.Trojan.FormBook
Status:
Malicious
First seen:
2022-04-13 09:58:03 UTC
File Type:
PE (Exe)
Extracted files:
1
AV detection:
17 of 26 (65.38%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
a1a538fe935e970518aa2e5c454afa8e6b5cfb0f6defc5659b3b9e9998e7fdd9
MD5 hash:
58c061cf43de53456cfe636c6643f4e6
SHA1 hash:
9a1fc8d79e40f14944af565182cc7ad8e514ab30
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments