MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b76b8c13335413cab914bf9ffc58d5f0c121fc734c61c2083633125dc2210562. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 14


Intelligence 14 IOCs YARA File information Comments

SHA256 hash: b76b8c13335413cab914bf9ffc58d5f0c121fc734c61c2083633125dc2210562
SHA3-384 hash: 5cf3c7aa0b03371da0f9cbf098c15af0d2cb3e729fd655fa8bf949a4ce47271fbbde59f3662e033b00c73459d60d40ab
SHA1 hash: ec377b64bcb783f94dc90d8229fed8d448cf49c1
MD5 hash: 0fc950d47b8ed0b5bbb31c26c81155a3
humanhash: yellow-aspen-mexico-solar
File name:SecuriteInfo.com.Trojan.PackedNET.1761.18568.815
Download: download sample
Signature Formbook
File size:541'696 bytes
First seen:2023-01-11 14:38:33 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'744 x AgentTesla, 19'608 x Formbook, 12'242 x SnakeKeylogger)
ssdeep 12288:nl2wi5FpsIU8hDRfnILP0JXxcIIy2hd2XEYPC6m+8ubkw:n1i5FfU8hDRuP0PcIXW+bkw
TLSH T10AB4E08F58D1B820EFD41574C342A8CC19772F019AF7E89E9C973D2F69205ED2AA518F
TrID 69.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.0% (.EXE) Win64 Executable (generic) (10523/12/4)
6.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.2% (.EXE) Win32 Executable (generic) (4505/5/1)
1.9% (.EXE) Win16/32 Executable Delphi generic (2072/23)
Reporter SecuriteInfoCom
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
181
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
SecuriteInfo.com.Trojan.PackedNET.1761.18568.815
Verdict:
Suspicious activity
Analysis date:
2023-01-11 14:41:48 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Sending a custom TCP request
Unauthorized injection to a recently created process
Creating a file
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
packed
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
88 / 100
Signature
.NET source code contains potential unpacker
C2 URLs / IPs found in malware configuration
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Yara detected AntiVM3
Yara detected FormBook
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2023-01-11 14:39:10 UTC
File Type:
PE (.Net Exe)
Extracted files:
14
AV detection:
21 of 26 (80.77%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
formbook
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook campaign:g44n rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Formbook
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
e7242ae1cd799ea3200b7705221fdddd8abf588e87215a28057e02135bf547ad
MD5 hash:
6b1c0c833df93681eafdcf57072e8075
SHA1 hash:
5081196e5fd1e90c7564ce07096baf4668bbc3fc
Detections:
XLoader win_formbook_auto win_formbook_g0
SH256 hash:
59bcd4203167ab824809004c0f4030f58acbd7c4f382b6e2d5f0c5695a71e170
MD5 hash:
3820d6b49c5470a173913d3933e38cff
SHA1 hash:
563a66c1ccd79d751de8b717f050300bdbf776db
SH256 hash:
d5718cfc5ded3ac791f539fab3a5559384b2a1694a0dc689f58e98e57bed18aa
MD5 hash:
207f7ee2a146b265261dbb94a29b06a9
SHA1 hash:
c2d0954cd772f6d6e6c020796fe90f3aee4c18bb
SH256 hash:
c8ff0d78fc921526b0addaa85114f31f7a142ff079281538142c95b085828cb5
MD5 hash:
6121b59c68e773beafd68c8191ec0062
SHA1 hash:
ba18e0f0698e308b2e464549ec3a1d90326c61ef
SH256 hash:
231d3ad6e558cd5c0d624f8979181f8aa2a21973828aadcae105523284f9d74a
MD5 hash:
572165371ae288df8eed27e05656ada6
SHA1 hash:
378e6f9511a1b1253eb6a2f1ed081ff801fac90b
SH256 hash:
b37263c6e42f4dfc0b82f296b93b0328e2bb74fa0d27b19ce703b9e557dfe9e9
MD5 hash:
6c95fb55c4b4f32dcdca1e493e2c22d9
SHA1 hash:
0367811fbbd72e60d3abfd6ffc469837c7437c0d
SH256 hash:
b76b8c13335413cab914bf9ffc58d5f0c121fc734c61c2083633125dc2210562
MD5 hash:
0fc950d47b8ed0b5bbb31c26c81155a3
SHA1 hash:
ec377b64bcb783f94dc90d8229fed8d448cf49c1
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments