MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3a3645cf2d804bebd0d8049b70c95ae545ff06ca2acc9f85721a1d1f3c9b5b8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 17


Intelligence 17 IOCs YARA 10 File information Comments

SHA256 hash: b3a3645cf2d804bebd0d8049b70c95ae545ff06ca2acc9f85721a1d1f3c9b5b8
SHA3-384 hash: 102c90092ee88de1c36d464355aeb608c0ad8cb7104f68202b0e56e98066819bc75c6d0d727122a344ae773669d0d106
SHA1 hash: 4dc3f3eb48422b296b77da0dd2a3b9fdba307844
MD5 hash: 6ed11fa261ad9e5d1f750c8e7adf875b
humanhash: red-wolfram-oscar-delaware
File name:92506745-NTL228900.exe
Download: download sample
Signature Formbook
File size:1'321'032 bytes
First seen:2022-09-19 11:57:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash fcf1390e9ce472c7270447fc5c61a0c1 (863 x DCRat, 118 x NanoCore, 94 x njrat)
ssdeep 24576:iAOcZXp0IIJ9+hwxD1FQSeIWcxzOkdLUkjPV99npuezy71oporahI:oVjxD1FQSzW4ZUkj9fZe6G1
TLSH T1B8551243F6D254B2D4731D304732AB35ADBD7D201E249A6EA7D41EAAEF351806620FB3
TrID 91.0% (.EXE) WinRAR Self Extracting archive (4.x-5.x) (265042/9/39)
3.6% (.EXE) Win64 Executable (generic) (10523/12/4)
1.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
1.5% (.EXE) Win32 Executable (generic) (4505/5/1)
0.6% (.EXE) OS/2 Executable (generic) (2029/13)
File icon (PE):PE icon
dhash icon 80a4a6a6a6a68081 (11 x Formbook)
Reporter lowmal3
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
261
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
formbook
ID:
1
File name:
92506745-NTL228900.exe
Verdict:
Malicious activity
Analysis date:
2022-09-19 11:59:26 UTC
Tags:
formbook trojan stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file
Enabling the 'hidden' option for recently created files
Creating a process from a recently created file
Adding an access-denied ACE
Launching a process
Launching the default Windows debugger (dwwin.exe)
Launching cmd.exe command interpreter
Sending a custom TCP request
Setting browser functions hooks
Unauthorized injection to a system process
Unauthorized injection to a browser process
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
MalwareBazaar
MeasuringTime
EvasionQueryPerformanceCounter
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
greyware overlay packed setupapi.dll shdocvw.dll shell32.dll
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Drops PE files with a suspicious file extension
Injects a PE file into a foreign processes
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Modifies the prolog of user mode functions (user mode inline hooks)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Performs DNS queries to domains with low reputation
Queues an APC in another process (thread injection)
Sample uses process hollowing technique
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Tries to detect virtualization through RDTSC time measurements
Writes to foreign memory regions
Yara detected AntiVM autoit script
Yara detected FormBook
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 705461 Sample: 92506745-NTL228900.exe Startdate: 19/09/2022 Architecture: WINDOWS Score: 100 44 Snort IDS alert for network traffic 2->44 46 Multi AV Scanner detection for domain / URL 2->46 48 Malicious sample detected (through community Yara rule) 2->48 50 5 other signatures 2->50 11 92506745-NTL228900.exe 36 2->11         started        process3 file4 36 C:\Users\user\8_46\agdhpwuhgq.pif, PE32 11->36 dropped 70 Drops PE files with a suspicious file extension 11->70 15 agdhpwuhgq.pif 2 11->15         started        signatures5 process6 signatures7 72 Multi AV Scanner detection for dropped file 15->72 74 Writes to foreign memory regions 15->74 76 Allocates memory in foreign processes 15->76 78 2 other signatures 15->78 18 RegSvcs.exe 15->18         started        21 RegSvcs.exe 15->21         started        process8 signatures9 52 Modifies the context of a thread in another process (thread injection) 18->52 54 Maps a DLL or memory area into another process 18->54 56 Sample uses process hollowing technique 18->56 58 2 other signatures 18->58 23 explorer.exe 18->23 injected process10 dnsIp11 38 www.tunecaring.com 172.67.188.11, 49743, 80 CLOUDFLARENETUS United States 23->38 40 www.wearestallions.com 23->40 42 5 other IPs or domains 23->42 60 System process connects to network (likely due to code injection or exploit) 23->60 62 Performs DNS queries to domains with low reputation 23->62 27 cmmon32.exe 23->27         started        30 rundll32.exe 23->30         started        signatures12 process13 signatures14 64 Modifies the context of a thread in another process (thread injection) 27->64 66 Maps a DLL or memory area into another process 27->66 68 Tries to detect virtualization through RDTSC time measurements 27->68 32 cmd.exe 1 27->32         started        process15 process16 34 conhost.exe 32->34         started       
Threat name:
Win32.Trojan.Leonem
Status:
Malicious
First seen:
2022-09-19 11:58:27 UTC
File Type:
PE (Exe)
Extracted files:
384
AV detection:
22 of 26 (84.62%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
formbook
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook campaign:mh76 rat spyware stealer trojan
Behaviour
Enumerates system info in registry
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Checks computer location settings
Loads dropped DLL
Executes dropped EXE
Formbook payload
Formbook
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
7a51903ae0e79eed1bfa29e36ea357d2ee255dec218016e91c5e287b55ae58e4
MD5 hash:
dd063f1b073b45bc3a4fe25c5a859eeb
SHA1 hash:
b2ea62711693c89ac6376c2075f951de302a779e
Detections:
FormBook win_formbook_auto win_formbook_g0
Parent samples :
76381a94a940a4d2b7f4ecf9ab6e507eb1ab9dfb1deb27ef852b632ed069865e
b185a143f0152879be32508681282a6bf45d12f0d4d9525ac95f026990d82c87
24ef19db63cfcc0cebad5f54758de38284812b707ed53e9f404be03780451d39
d675408e7dcc87922c9d654a5c4f387f70d4a06ad99bad187753d90ee6381a87
1c6a3fdbe07eca91bb067a9ba1c90bd87df0d94a0f8c9d870c792baa4a040c45
1d040cec4469439a6c402ec04abf157a02b202fe4ddafe280d96b937b7eadce4
75563869f37196a473d163e40a4f393ba74b4c5feac4e178c83f670da5dd2762
25c9de9dfbbf115f5809dbbf9e246bebfa8b1925e99f070fa6233ad62ee22b9e
165f7a262d388cf63fc7f360cd1e2f1b7a6370586c8cbfce04e458800aca1d7a
bdb2cd093592b1e41acbf2e35565f0639628b86da36b1e6d49dcf1f81b751832
c767db1d9bb5f369f3a2d395412c98f71de29cf829800a2494a2c0dec8e4a57f
78c8c0aa6b6c7368ce2e9a6edb76db71162d7335c6da4f8489b276cd742f768b
a328bc2d66baa94dc748b1a450a0ede9601ff9ccec5ff2cfd043e669383ba295
43aaf13fbc49a0763cc55dfdf174892b76cc0b74a8698886d9376a4954e00818
a1eb3ccf50d23e3e49d659d55ca85c70d02e9c22a16b6e9f5270793a8487aa27
2d1a6fc2908bac0f7870588ab6f35467ea691f17ba2cb130b62fae506d630046
84b0888a5a6938795c26a681435c52a25c16fe2d1e6230112df171024c8767df
419127a78f8b1a361cab37011662b2ce411af7f4ad59d0f35ce5ca98eca1b92a
22f45817bd8b33de74fe1cc7db5569bd6af759b8fa1bd632ec37d4c7c822cfe1
ec77a02fcb9c5b393ed013b267010cf06e75550e8d977cb054d8e3fe681d8e6b
20abbef0a386be20828344f159293e55cfcf89942c3b26c21acc7b052fbe896d
6de2ff8d01687f6c88e2bc2c19407be670e1ece621227503eacac934739e67c7
82edebd73b6b366121ccf9b066f1a4d140aed527ce9058866fddfa1b7f884466
3702b6cfa76e492d56bd9da5f99f7ff805e32c16b3840ee66bb13a812f5d3155
8f8813e3ed0cdb3ac92de8e6003bc83c0ec859fc717748cab6a45f56a98a9201
b3a3645cf2d804bebd0d8049b70c95ae545ff06ca2acc9f85721a1d1f3c9b5b8
aa9c86a823e654e20b42edc829a890f08b0ffffaaa4054ca0033e0b4fae5765b
87fdf41f3af47dc20348fe21148546a943111c455ffb9a8cd73b1beb77513ce4
3f4e8eda03283329f391e111c756f7b6ece4a9bc0d41672af8c1f09baf2b1cec
b4be0d5867f091bff8f48d03dfdde04ff2e4189170c4168745568a1b20ed1c9a
b1f692dd52aae8317db7cfd262a4bcc053cf721fc7a00bf66f4acc7cb5cc6cbc
67e6fd61e128d5649045a4fc55fc6c287722b5c92e65eef35ce0838d6210d901
SH256 hash:
0e6fffae6503f86463e0a38bc2ae0296a7df993579aa049079679ca25ddda724
MD5 hash:
9d882a4685e233baaf9b24caa78ffca4
SHA1 hash:
3179f4d36aa0cf67ba1a81b3c35c223061414ca7
SH256 hash:
b3a3645cf2d804bebd0d8049b70c95ae545ff06ca2acc9f85721a1d1f3c9b5b8
MD5 hash:
6ed11fa261ad9e5d1f750c8e7adf875b
SHA1 hash:
4dc3f3eb48422b296b77da0dd2a3b9fdba307844
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:malware_Formbook_strings
Author:JPCERT/CC Incident Response Group
Description:detect Formbook in memory
Reference:internal research
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:pdb_YARAify
Author:@wowabiy314
Description:PDB
Rule name:RansomwareTest4
Author:Daoyuan Wu
Description:Test Ransomware YARA rules
Rule name:RansomwareTest5
Author:Daoyuan Wu
Description:Test Ransomware YARA rules
Rule name:Record_Breaker_Similarities
Author:DigitalPanda
Rule name:sfx_pdb
Author:@razvialex
Description:Detect interesting files containing sfx with pdb paths.
Rule name:sfx_pdb_winrar_restrict
Author:@razvialex
Description:Detect interesting files containing sfx with pdb paths.
Rule name:win_formbook_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.formbook.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe b3a3645cf2d804bebd0d8049b70c95ae545ff06ca2acc9f85721a1d1f3c9b5b8

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments