MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a28592058ed33d1a46f187fb5fcccbd89b9167ed84c85755aaa8d2d3ceca9003. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 13


Intelligence 13 IOCs YARA 2 File information Comments

SHA256 hash: a28592058ed33d1a46f187fb5fcccbd89b9167ed84c85755aaa8d2d3ceca9003
SHA3-384 hash: 22a7ff91c515668cdc5a5b8f3eb97e545ccb1caf63f6878da9a9cc7b3c6e2f5750e3ecd14d3222d4451a6fbca72a9585
SHA1 hash: 60d79c1d6e0923c6db2f6cb9f6f436afc5f18d22
MD5 hash: 74f77dba797a511805648d993e1f507e
humanhash: skylark-football-solar-mountain
File name:Arrival notice.exe
Download: download sample
Signature Formbook
File size:738'304 bytes
First seen:2022-06-22 12:22:42 UTC
Last seen:2022-06-22 13:53:41 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'664 x AgentTesla, 19'478 x Formbook, 12'208 x SnakeKeylogger)
ssdeep 12288:IgClpfPMU2iNPf+B85Fram7sayDWnOyFcYeLwW3+t9hQ2ZwZzZIcZP8K:mfl1B+B85FG6sacWnlOLd8FwI2P8
TLSH T129F4C074264C2DA3DA7AE4BC8061424042F1995F7563F9AE3DF228DD26C1FC86371DBA
TrID 72.5% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.4% (.EXE) Win64 Executable (generic) (10523/12/4)
6.5% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.4% (.EXE) Win32 Executable (generic) (4505/5/1)
2.0% (.EXE) OS/2 Executable (generic) (2029/13)
Reporter GovCERT_CH
Tags:exe FormBook xloader

Intelligence


File Origin
# of uploads :
2
# of downloads :
237
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Unauthorized injection to a recently created process
Creating a file
Сreating synchronization primitives
Launching a process
Launching cmd.exe command interpreter
Searching for synchronization primitives
Unauthorized injection to a system process
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Initial sample is a PE file and has a suspicious name
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Sample uses process hollowing technique
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Yara detected AntiVM3
Yara detected FormBook
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2022-06-22 10:47:47 UTC
File Type:
PE (.Net Exe)
Extracted files:
22
AV detection:
23 of 26 (88.46%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
formbook
Result
Malware family:
xloader
Score:
  10/10
Tags:
family:formbook family:xloader campaign:nmd2 loader persistence rat spyware stealer suricata trojan
Behaviour
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Drops file in Program Files directory
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Deletes itself
Xloader Payload
Formbook
Xloader
suricata: ET MALWARE FormBook CnC Checkin (GET)
Unpacked files
SH256 hash:
8f8d821f9b816b475e1c9f34db67d3a4e7c5e6d0a4dfc462ef67248ad0a5afea
MD5 hash:
af41a321878299875b7d3763ebe91b20
SHA1 hash:
34697adff8512e91fdcaf9f22abdf424fbc5f4b9
Detections:
win_formbook_g0 win_formbook_auto
Parent samples :
9f604ab9c007da7543c828be85e5508af9541fb039bb9e90283f84b0d6aebdc4
717ab44671da707ee8ad9e5c6e4ade18d6f47841e65a6bd0cebd56c8c1533fcf
0b8058097313b63fec637d226daa0af6abb9f68bb1d0ccb9edb39876453617be
8586e05ff7d2269e9495e76725cc561d433cb771d6af6581ae5fdcf7b8b571d9
085917245898b3d25910807103748a579b389697e79bdceb82b043f66b86a130
f361a889ba650230da217b06b0c41ced6d025c461f29e854583548461dc84668
a28592058ed33d1a46f187fb5fcccbd89b9167ed84c85755aaa8d2d3ceca9003
313566736f3e85c4303541ddf83b100fd80fefe20702cc7c3e10789942127a9e
1722230b243c441e5498ccd145a7a4f8fa00b97d2a22cb20007efb227cce45a9
6f6be5365b28b8c8bd13b442ea0c7f18bbd6cc92d1a6cea7cece4702bcc8cac9
32b04a3fc9feb6bd1b63e6ec096f2cfa0a78f07f86cb08c64f4a24ec5325c0b1
04326067e70a15d7b5139282361d1cd355b2a6c057ca7ac0e901f0a88b139aa7
970e64f4f7b5a8dd1e1f5df8470f372d27585cff9f75a0d3a596427d261bf809
262d23daa434a3eaf7afceeb9b9340f20c040eac7acb6732749c49f433e2e17f
4f4e5e5550b40c160b4dfa9f399b558d2d96ffdf49cc0c81a86a6b3942f1fd94
901b8ec8346c9ec07fb34f17b2eb18f45d6197b0cbb1d7bad6b1cf23ff0cbab1
4863509ff407e4a6389305b5555bc804aa5df9b67290feeb1e36bf68f40696e1
535fb5862370192d9fa74321ef99aa8fe36aaf56689f48411fc7c14b9c984533
f085387dd3ad9b5e949cdb80752a76f1fab4fe66c7eee38a353d0f80b80df7b7
3064b62e720763ef00cfa548424cf74aef8034f8ddc420084519b27b4e1f271e
a5c83c27bf821b97478d7a7cf53e3de83e15fb3a87ff7bdb793afc6ee8d0f64d
7833781bd55b3c69a30841ca9d10a7d8d0bc15b9fbf5cc4d81eee5e2f9591000
1b382c7ca0e34e9e294ea85dfdb722ccfe0b828ecbf5c665a605af31d7277e6f
3fa0d321b17bc7af7e98f723135bf7c3151107f4572f1a41c68f933c488c77b3
SH256 hash:
fb1f66495ddd485aaec40b19c92cbca102535e35c0fa6641ff02d66caa3abc16
MD5 hash:
21b2d08ce9c92f9ff5b49bb002c69a99
SHA1 hash:
648906ad37a6f05ae862e3f79b82a7b977afe585
SH256 hash:
79823e47436e129def4fba8ee225347a05b7bb27477fb1cc8be6dc9e9ce75696
MD5 hash:
39f524c1ab0eb76dfd79b2852e5e8c39
SHA1 hash:
428018e1701006744e34480b0029982a76d8a57d
SH256 hash:
a28592058ed33d1a46f187fb5fcccbd89b9167ed84c85755aaa8d2d3ceca9003
MD5 hash:
74f77dba797a511805648d993e1f507e
SHA1 hash:
60d79c1d6e0923c6db2f6cb9f6f436afc5f18d22
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe a28592058ed33d1a46f187fb5fcccbd89b9167ed84c85755aaa8d2d3ceca9003

(this sample)

  
Dropped by
xloader
  
Delivery method
Distributed via e-mail attachment

Comments