MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ad048fa92eef59c07432e25c1afa2af4853be0a301e3ea64910352373fdea51c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 14


Intelligence 14 IOCs YARA 17 File information Comments

SHA256 hash: ad048fa92eef59c07432e25c1afa2af4853be0a301e3ea64910352373fdea51c
SHA3-384 hash: c2f5d6bc06160076d998469d09fe7673d8fe8e560abe01be61754fefb1a8e755df95c3b61edd23cba04438b30bdd3d04
SHA1 hash: 9418667787860af0ca3f8f448fe5e6ccfebacf47
MD5 hash: e8abc31ea3817ce904ecb9296d792ed7
humanhash: sweet-single-monkey-pip
File name:purchase order 8MCE15.scr
Download: download sample
Signature Formbook
File size:704'512 bytes
First seen:2024-03-21 17:13:37 UTC
Last seen:2024-03-21 18:41:56 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'647 x AgentTesla, 19'451 x Formbook, 12'201 x SnakeKeylogger)
ssdeep 12288:UT7n4mCX6nP7DdMzN5sG8adZEuZyn8wKj9YhZ2LVZLwl7Zum9mO/jcot7wSzc197:KzegPHdMJ5szaYuZy8wGKhO/Y/mO/48c
Threatray 80 similar samples on MalwareBazaar
TLSH T1BBE42236B3389257CFB10AF610B85A2513B6BA1F2926D6CD1DD6309D86F2B404E60F97
TrID 61.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
11.1% (.SCR) Windows screen saver (13097/50/3)
8.9% (.EXE) Win64 Executable (generic) (10523/12/4)
5.5% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
3.8% (.EXE) Win32 Executable (generic) (4504/4/1)
File icon (PE):PE icon
dhash icon 12b092d0c4d4e871 (3 x AgentTesla, 1 x AsyncRAT, 1 x Formbook)
Reporter abuse_ch
Tags:exe FormBook scr

Intelligence


File Origin
# of uploads :
2
# of downloads :
332
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
formbook
ID:
1
File name:
ad048fa92eef59c07432e25c1afa2af4853be0a301e3ea64910352373fdea51c.exe
Verdict:
Malicious activity
Analysis date:
2024-03-21 17:55:56 UTC
Tags:
formbook xloader stealer spyware

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Launching a process
Creating a file
Adding an exclusion to Microsoft Defender
Enabling autorun by creating a file
Unauthorized injection to a system process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade packed
Malware family:
MSIL Injector
Verdict:
Malicious
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Antivirus detection for URL or domain
Found direct / indirect Syscall (likely to bypass EDR)
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Queues an APC in another process (thread injection)
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Scheduled temp file as task from temp location
Snort IDS alert for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Yara detected AntiVM3
Yara detected FormBook
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1413431 Sample: purchase order 8MCE15.scr.exe Startdate: 21/03/2024 Architecture: WINDOWS Score: 100 65 www.vertilehub.xyz 2->65 67 xiaoyue.zhuangkou.com 2->67 69 18 other IPs or domains 2->69 75 Snort IDS alert for network traffic 2->75 77 Malicious sample detected (through community Yara rule) 2->77 79 Antivirus detection for URL or domain 2->79 83 10 other signatures 2->83 10 purchase order 8MCE15.scr.exe 7 2->10         started        14 mUfVkltcoOUI.exe 5 2->14         started        signatures3 81 Performs DNS queries to domains with low reputation 65->81 process4 file5 55 C:\Users\user\AppData\...\mUfVkltcoOUI.exe, PE32 10->55 dropped 57 C:\Users\user\AppData\Local\...\tmpC4AB.tmp, XML 10->57 dropped 89 Writes to foreign memory regions 10->89 91 Allocates memory in foreign processes 10->91 93 Adds a directory exclusion to Windows Defender 10->93 16 RegSvcs.exe 10->16         started        19 powershell.exe 23 10->19         started        21 powershell.exe 23 10->21         started        23 schtasks.exe 1 10->23         started        95 Multi AV Scanner detection for dropped file 14->95 97 Machine Learning detection for dropped file 14->97 99 Injects a PE file into a foreign processes 14->99 25 RegSvcs.exe 14->25         started        27 schtasks.exe 14->27         started        signatures6 process7 signatures8 71 Maps a DLL or memory area into another process 16->71 29 PljtUwTxWiA.exe 16->29 injected 31 WmiPrvSE.exe 19->31         started        33 conhost.exe 19->33         started        35 conhost.exe 21->35         started        37 conhost.exe 23->37         started        39 PljtUwTxWiA.exe 25->39 injected 42 conhost.exe 27->42         started        process9 signatures10 44 newdev.exe 13 29->44         started        85 Maps a DLL or memory area into another process 39->85 87 Found direct / indirect Syscall (likely to bypass EDR) 39->87 47 newdev.exe 39->47         started        process11 signatures12 101 Tries to steal Mail credentials (via file / registry access) 44->101 103 Tries to harvest and steal browser information (history, passwords, etc) 44->103 105 Writes to foreign memory regions 44->105 107 3 other signatures 44->107 49 PljtUwTxWiA.exe 44->49 injected 53 firefox.exe 44->53         started        process13 dnsIp14 59 xiaoyue.zhuangkou.com 47.76.88.64, 49715, 49716, 49717 VODAFONE-TRANSIT-ASVodafoneNZLtdNZ United States 49->59 61 www.vertilehub.xyz 203.161.49.220, 49739, 49740, 49741 VNPT-AS-VNVNPTCorpVN Malaysia 49->61 63 8 other IPs or domains 49->63 73 Found direct / indirect Syscall (likely to bypass EDR) 49->73 signatures15
Threat name:
ByteCode-MSIL.Trojan.Swotter
Status:
Malicious
First seen:
2024-03-20 18:47:04 UTC
File Type:
PE (.Net Exe)
Extracted files:
13
AV detection:
22 of 38 (57.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Creates scheduled task(s)
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of UnmapMainImage
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Checks computer location settings
Unpacked files
SH256 hash:
31d015abc0e2e30d7f9aad7f4c8ef1ae2781ffdee591f9edfe33b063a001fa65
MD5 hash:
c9a871d07d5fef5be8e96a68d7c16e82
SHA1 hash:
7d1b9ce6f6c341fecca002b2cfbce749bff2830f
SH256 hash:
f35ee8182ca1f1077c639e55ef9f95c6516dff1470a30e360d9c395110840538
MD5 hash:
93bda17d5beae552754d7aaf86c6bccf
SHA1 hash:
a578ee58abae1cb7df0d5cb8e9b0c07b1b43e55d
SH256 hash:
b938c6c76eb747faadcfa16561752480cdbf822c60ccd62771d6296e758da694
MD5 hash:
e805cc9a37ade0180d1140525ecedaa5
SHA1 hash:
f5382e8569ed075fc4633efea2a473d9ab4c2f33
SH256 hash:
975d5c095a6bd20d20d1553f0ad36795517087712bdc2a18fb8516665539242e
MD5 hash:
53106229a87e970b8befe76d9118f647
SHA1 hash:
f4965d92934d4acff7ad5f4f9521a1b8fb584798
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
37899fda8cbf74882ae5d68bcd1de525005edfb8b5b87edd42fd86c458bb998f
71ae98c7e6f3e776c17594e8007ecf47ea0209f0ca1142515e4958c02267bed9
5f834237db6598266c1127b74062bd1d92150daf483ccdb0b37f1d306494a5a4
296d5ba75c695171bc26ce33a02e4b16818bddcfdb7688011d741fb78d3dab18
fca4e12e29cf37dcc23a48f671c5dd7f8f4d473bba7754091ca1287d2b124205
d334afd3da3c629abf0772c5be572d1d7b252b9a1ad2fae0e1809d04635f3e4b
bd9a2450499f87561deff9f7862b4ca34b5afb27089b8ae90578f7ed28054808
0a2d5142d03f0dd333f371e089c5f0d5fe8c3169e4ee78d7ca23b1472b2f7b48
27aca3b944c0bbd1b6d020de7a9ef916ba170e017ba63304adfef012822cf20f
7beb85da1bc8b1c935309f219347d8534a77ba114ca4217bd60f98b4ad05836e
a775277953ea0daab3cbec4aa2b37c5e0052172c05f7d4d0e8c39894c58fabe0
771c49d7430b930313e8af81f4b89fefd3d6b6450fceab630b125a6a6d4cf11c
8d5930353d2239c66b566cb6725058657d642d766549d493f0118aa495c95106
aa33486e9090a3807a894ba0c8c918668821875e0df7a15574ea412489673e3d
f6eea72845ed2286d5faf76e537b1e94081c2fea7be4772c5f63a04e6a847795
cb348e8dbd6c518a9ad671a9fb235cea3eeba8b7036fc5498f6b118d4bc3060b
90f4e7731fc41021b7ce9f9d15704c9849cf3215161585721a370745f7392e71
d85a4e28a6003aaf9cf0a6c0bf3f5bee31eb82f39930f8ecec7657dd24093c49
00d1bd4fb6f0afc0345136a810f410fb2c1740fd8adf0793e3cf6597f9bc7447
53cbb972306a7569a1762feaa5df42ad66de898691b4cabcf1c2c35526361d8e
fb73c562937a21c54247a51c05d0e616148301cfdd24b1619f0e13191a3ab687
fc9a9c10b989fb790466a432945be2a122151bd634013222bfd87469a9f4d584
a898ed790cde47b79f0c27f18406d6e290178bea8c35788d5ac22622cfadf2b6
ad048fa92eef59c07432e25c1afa2af4853be0a301e3ea64910352373fdea51c
5762147a28aaed979353975b6f7e2d31d71fb827af0dafb991b442c30e161caa
1c98180948dc869d00e1fe42476559fae2d76e95ce809c47736aca2ed6c20970
4af0ad255ce753c34b265d5714681b436ef635cbfc8dab10349ea913547be805
b21d51bd3eae9c07144b4d2527d732227a775c18e42812eea7a6f3a84c4d3a2d
86cc6304f5610bd7836b6706c2fe5d5c1fd88ad5de23927e41a1848dddf744e1
35283152bb31940827ea64cdef4baf0f332f38b348d83dd3c34364b97f6d3d87
9dfd52d9008fad9915a2ce18b0f9e9a2dc6c513f7396d049a82faf97410950c1
2c86d6d8fe9b19bd2f24d6e424c90b9a4bee255cb10e8319427d689d32dbfc60
d24bd0ebc242b94f043fe80e7f6a48d20566689f31c55aa1ec910a2877ae9e28
b6d91bc05bcc51b0a9e9f6e605493168b1a78ccd6f234030d05461e12544cffb
dce7d8b9beeb107ab7520818cbba375962e1c6e8ace6020d1a344446498260ac
a5810d5e9262b17b5506cbfc546421debd1ddbb593ae8440c2b39793044200df
a25bdcab7a38affd0798e5d674341724726c866e7cd7348b3d75bdb47ccca230
8094dba1e87d004dcade1f0c8c15b78af99e3568d7912fa7b85cafd1e88bc83b
e1ce37159aa3f3e141d622216cc4994b7fa4014e8b094b56f34916bcd838b872
c7a16881f8c69d16a9b0bdcbfdd5c4aada81eba19521d1c03ee7f6005f7d6629
adeebc489ed24b4e3e8ca7d0db2a4fe9bfce24c7c7675d67d57712afce862a72
454e87da084f762d25dcb7858795f6bb6cd549cc0f1435177121b0eb66c17743
SH256 hash:
7cfce9d4374f24d233171eaff3aa995d700542bf0a9fd54f183745647f450c4a
MD5 hash:
aacd3a7a18721a1a5e2aac83bfedc3c9
SHA1 hash:
2743a9077e031d648c206c00bc0fa38f9e0dab38
SH256 hash:
ad048fa92eef59c07432e25c1afa2af4853be0a301e3ea64910352373fdea51c
MD5 hash:
e8abc31ea3817ce904ecb9296d792ed7
SHA1 hash:
9418667787860af0ca3f8f448fe5e6ccfebacf47
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__GlobalFlags
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Active
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:maldoc_getEIP_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments