MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b12ef83752daeb6755b31cce4d8367246b380fc4d8d5bfd5e42e36f34df5c8d6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b12ef83752daeb6755b31cce4d8367246b380fc4d8d5bfd5e42e36f34df5c8d6
SHA3-384 hash: b6ae52a0335372ce166ffec633e5d57f31413e69bdc6ce2243d3b831c1bb2d58be130b534860afa1bde5b57d6fd3f170
SHA1 hash: 774c13649f5ee6901baefc17d66539f99e9c0767
MD5 hash: 56e777a6b2cdfa641c8e6c193ca6061c
humanhash: glucose-river-zulu-oven
File name:89NTb(3).exe
Download: download sample
Signature FormBook
File size:1'062'400 bytes
First seen:2020-04-28 11:42:22 UTC
Last seen:2020-04-28 12:57:29 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 0318ec2c3e20540fe0ccf697fa352b5b (4 x FormBook, 2 x Loki, 2 x AgentTesla)
ssdeep 12288:EDYvWV4fQB0cHSs3fvMHLZT/LqMg9Oer/lC8+lEvKlJfF05Ibmu9EgeIKxAtWFQ4:q400o9vY1qMWRblCbXnAqafhx
Threatray 4'777 similar samples on MalwareBazaar
TLSH E735AE22B3C048B7D5760A385E17B2B058377D776A28A8457FE43E091F3868579393AF
Reporter oppimaniac
Tags:FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
97
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-28 12:35:25 UTC
File Type:
PE (Exe)
Extracted files:
47
AV detection:
27 of 31 (87.10%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

FormBook

Executable exe b12ef83752daeb6755b31cce4d8367246b380fc4d8d5bfd5e42e36f34df5c8d6

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
SHELL_APIManipulates System Shellshell32.dll::ShellExecuteExA
shell32.dll::ShellExecuteA
shell32.dll::SHGetFileInfoA
WIN32_PROCESS_APICan Create Process and Threadskernel32.dll::CloseHandle
kernel32.dll::CreateThread
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryExA
kernel32.dll::LoadLibraryA
kernel32.dll::GetSystemInfo
kernel32.dll::GetStartupInfoA
kernel32.dll::GetDiskFreeSpaceA
kernel32.dll::GetCommandLineA
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateFileA
kernel32.dll::FindFirstFileA
version.dll::GetFileVersionInfoSizeA
version.dll::GetFileVersionInfoA
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegOpenKeyExA
advapi32.dll::RegQueryValueExA
WIN_USER_APIPerforms GUI Actionsuser32.dll::ActivateKeyboardLayout
user32.dll::CreateMenu
user32.dll::FindWindowA
user32.dll::PeekMessageA
user32.dll::CreateWindowExA

Comments