MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b90d30fabfd911bdf2b7d785dee57ffd346019b889601d1411df2872d7d020d5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 15


Intelligence 15 IOCs YARA 4 File information Comments

SHA256 hash: b90d30fabfd911bdf2b7d785dee57ffd346019b889601d1411df2872d7d020d5
SHA3-384 hash: 96fd580b9df9cd3a241a68fa65c4be0f7e357d1dd2b64568378a08b6c677a260e7ad2fa010eb57d547c9019b936fce4c
SHA1 hash: 31021eee20bc7be003b29968cdfde3b2a2aec56c
MD5 hash: b6ace82ca0cb9b68828eb46e51739e90
humanhash: purple-pennsylvania-beryllium-iowa
File name:DUE INVOICES.bat.exe
Download: download sample
Signature Formbook
File size:594'432 bytes
First seen:2024-10-16 13:17:21 UTC
Last seen:2024-10-16 14:50:03 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'647 x AgentTesla, 19'451 x Formbook, 12'201 x SnakeKeylogger)
ssdeep 12288:Co9QlwdedsgcQukU7VzTBlUh96ny0UNxYyhzvvkxr/UgVJVicty+Vo3X:ComaTgvukU7hdZkbphzXkxDt/VicU+
TLSH T1D4C402F5539AED2AD4E403751172E7BB8A698F5CF062D302DEEBDCE7B90539028485C8
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10522/11/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter James_inthe_box
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
422
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
DUE INVOICES.bat.exe
Verdict:
Suspicious activity
Analysis date:
2024-10-16 13:20:06 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
Powershell Phishing
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
masquerade packed
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
AI detected suspicious sample
Antivirus / Scanner detection for submitted sample
C2 URLs / IPs found in malware configuration
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Loading BitLocker PowerShell Module
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Queues an APC in another process (thread injection)
Sample uses process hollowing technique
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Switches to a custom stack to bypass stack traces
Tries to detect virtualization through RDTSC time measurements
Tries to resolve many domain names, but no domain seems valid
Yara detected AntiVM3
Yara detected FormBook
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1535079 Sample: DUE INVOICES.bat.exe Startdate: 16/10/2024 Architecture: WINDOWS Score: 100 35 www.npostl.xyz 2->35 37 www.usinessaviationconsulting.net 2->37 39 10 other IPs or domains 2->39 41 Found malware configuration 2->41 43 Malicious sample detected (through community Yara rule) 2->43 45 Antivirus / Scanner detection for submitted sample 2->45 49 13 other signatures 2->49 11 DUE INVOICES.bat.exe 4 2->11         started        signatures3 47 Performs DNS queries to domains with low reputation 35->47 process4 file5 33 C:\Users\user\...\DUE INVOICES.bat.exe.log, ASCII 11->33 dropped 59 Adds a directory exclusion to Windows Defender 11->59 61 Injects a PE file into a foreign processes 11->61 15 DUE INVOICES.bat.exe 11->15         started        18 powershell.exe 23 11->18         started        20 DUE INVOICES.bat.exe 11->20         started        signatures6 process7 signatures8 63 Modifies the context of a thread in another process (thread injection) 15->63 65 Maps a DLL or memory area into another process 15->65 67 Sample uses process hollowing technique 15->67 71 2 other signatures 15->71 22 explorer.exe 94 1 15->22 injected 69 Loading BitLocker PowerShell Module 18->69 24 conhost.exe 18->24         started        process9 process10 26 colorcpl.exe 22->26         started        signatures11 51 Modifies the context of a thread in another process (thread injection) 26->51 53 Maps a DLL or memory area into another process 26->53 55 Tries to detect virtualization through RDTSC time measurements 26->55 57 Switches to a custom stack to bypass stack traces 26->57 29 cmd.exe 1 26->29         started        process12 process13 31 conhost.exe 29->31         started       
Threat name:
Win32.Backdoor.FormBook
Status:
Malicious
First seen:
2024-10-16 10:09:41 UTC
File Type:
PE (.Net Exe)
Extracted files:
5
AV detection:
12 of 38 (31.58%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
formbook unknown_loader_037
Similar samples:
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook campaign:cu29 discovery execution rat spyware stealer trojan
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of UnmapMainImage
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Checks computer location settings
Deletes itself
Command and Scripting Interpreter: PowerShell
Formbook payload
Formbook
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
9c64915d0a649bb2641dc89b7c1573bd9d49b8acf602769fe87b88e4268fcc36
MD5 hash:
2461709698d52f14ceda2c3086579224
SHA1 hash:
16f282e37f25dd43a699052d9bd23bf33bd55a43
Detections:
FormBook win_formbook_g0 win_formbook_auto win_formbook_w0 Formbook Windows_Trojan_Formbook
Parent samples :
a327355ae6e99929d1303a762ea8a936d8e4884f45d683de08dba6882c1c016d
596681238e749d9109fd00bbc95f364f4cfc5977cf1d2253bd8ee268d6dbbf2f
f30297ce3c8bc97f49286ee0c14b241d6653a2e992de11213aa25a296ab485cd
a2780a43ac1e90a6945c78cbcbd929863ab89c72ff1f86380f48303d051bc7d4
e1902171c2bba8b0280e747ec2457209c1b32bf899d85f241c2993fdcba1ac31
cf8230d20fbd1b9b21058813669fcd7fa9575a5a0f9c38269213b4e712d918d3
a5c97f8e1ff612fbfcc18f1a1852db11099e58bb241f5b825c74715c60dd0fef
0309aa8889daca83b4cf97ab99bc9921bb549c9187736a69c76185dfe68cd325
ea0d7f34cfddec8c57ddf23bfc5eab2c1692f1b3f5e8fdd6f4f7f8596e478d9d
fe32cd498b7f031639961bfb962d1289896a3667f38f06f801b2c5d97d0b5906
b90d30fabfd911bdf2b7d785dee57ffd346019b889601d1411df2872d7d020d5
1c2b963220cf175f77391b7fa2e2f27dc835144750b9c3c0c4c6ddb2e1cccc45
2847c9264726b6c4abbcede6bfc40c2386e93e81a8cd968c19e5493e08851f1a
10b85fb4905227bc1e37c8ebfcb317b188f9d93a761aa887977dae17c71de81f
320aa8c92e7c70266b35c8a5fc38ed069d68e6e1403b3ce56bab93fbd349d890
8352beed8fb5f5823a3ea3829d7e845a3fd3c53535dfb4a13fa0d11e01231912
ec6c0b68ad723bfd12ffe050b290318de9f50ceaac13a9f9483d42a6301ac657
ff410475bb80926bc3933e68f5e84a7185292bb2b78294abe528cb647c78f637
069a4c2c42050c9037f6a11f9083b312c8bc3159fbe2b73f1e84760da762e6a8
00140ab45e4fcbba5f1b52f3058a8ac015771eb60348617843ac7ca841b8bae9
0248b7bdbf6c49ffceddae89725a94da2c3076ebbf6253fafd2c817b57dc5891
bfb4b96460ce25a3a585f3780f8ab6c0db4d31dccfe614491876332c028d4328
c82b82cf444e4a02ffe7091ef5ea7bea733c2127c38366c88775cade7d234681
a6d2a47171f9630a8db62eb4001e196dfbad94cf40638e108cc649883d1bc069
SH256 hash:
c9f1b44b46f038cdc41159ee23837d60f0b78f21a1bc37373c4c8fdaebe551f9
MD5 hash:
3211533f8f6cfba4f3d06e63602e2999
SHA1 hash:
4cf3f6d1d4fe3941291bf689748f760d222e41a8
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24 INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
6a3139af3bd7a833719a3e1c95d92f86e924fbfd34389de1ef5c0202d1716a7c
7a9e36961ab5b2ab759ec2196d40618b1f43c5a04c40c01b31cfb4ea1adfc347
8f24522b05cd4032eff11b1f392146101cdc4ad4f65803c99cff824e4c425098
fc117f10fec938fc5983ad960142b3dafdc946dee592d13a37c6f21aee2618fc
5ae445a991d56393e514f68e235bf8e92b116fedc8cc6d17ae358b34f6873d09
347b852f5907744c87cb80e5564d3116724a895ed856265899ae011738868295
165005cb8423f38beba5461a10f3cf5fb69304013b5033463265c5457e48b76d
a8281f10a65d2066e0bb4d9089efbc567dedec223e6b77303223da17af9021dd
b90d30fabfd911bdf2b7d785dee57ffd346019b889601d1411df2872d7d020d5
e414dcedd89db359ee7d9efa34acd3524b578e627aa18fc627a0d2aee62569ee
1c2b963220cf175f77391b7fa2e2f27dc835144750b9c3c0c4c6ddb2e1cccc45
ebab7ddccea1d6b5a5d4e69bf2dccd2684fc00f5955ca5e6bc5bc51833247232
2e60e1e443fe9ccbc167bd093cbea48ed49743648f5c8df81c9d7356ac499194
d4bf3a107af69bbbc1ace1972e497847e2464ab843a32ca2074726f4d338cc82
2847c9264726b6c4abbcede6bfc40c2386e93e81a8cd968c19e5493e08851f1a
a60dc20a425f59e23a134fc5dc142605ef8663fb7a19829c9604c5b0a57e2f58
c4ec5232b93fdd3a9b66041c8c76944c56c024741c9210681884e3020436c72b
8a48ce8db35cc289949562cae156fce70a8e7f913b35515bce4cdc2741152b8b
e3c2797795813326d842d0d7973b5fbc8f0c797e920c96dc13c17d9705996e6d
b4be7f2484d838df9503c7864f809acbaead8a110cf42a4e6481a01b5f4f9485
773e56d43a64f8dc2f504591a154b045827841c9c352fcb0eb5e00ffb7d2494d
72cbefae43d92c6d12f7ca663d4fd6671b9496bfb2ec6f301cdd7baf6557a667
6191abc34c202d0c07426a07e18de87c7966bc66a5a986fccae897bb029431c7
8163272129040576b8ed3755405d3d54bafd4adb11815d16cf111414837b3341
acf357c833101ffeeaea46fc8db924fd2238fa60c93d0c16b9908d8b8daf605e
d288aeaba9ce6c45ea67888979e4810b2148c01c15c8312c95514112da7602b8
a4e306de360dd28b8d54760139d3b4b9fe5448d6c906ea3ff3bc54b3ab97ea27
0d12cb94f5a68cf9f6c968cfc79f79a7f33e5c4a8457c485e253b7a63c5c6651
7ca24db961bea0f4324c0e13110ab17aabc2da38f67311d2de046a263771858f
d41fe3fc605a799e6f95c52cc16d35a2f1bc03fd166187a1c6fd830f287e3518
f78935b754216fa45dccda11a77055e1ddfbf03caa112ad86ba7e48a16c385d9
10b85fb4905227bc1e37c8ebfcb317b188f9d93a761aa887977dae17c71de81f
0b3423499f53462afd426652f26d5a2cb90347cb3265bb35d7041727912670d2
4265f1052e30da8a8c0df275b96179f0ffdb01affc76d38169414575a8c0bd2c
3bbeda749854caa304bb1e8b968971a7e84359f98105c9ef80d18033adcc2f09
320aa8c92e7c70266b35c8a5fc38ed069d68e6e1403b3ce56bab93fbd349d890
0c76624f247bc645309c46976f8f9a9b76d4c566df2fdd0c82058e98d07c80ca
887df6e244e8d356d468e6fd9a5712f918918b72fe18892f7a80b900dc89ea76
31684d56968063e799ddb7f470216b3b2114531e3a500439d5db90ac337800f0
99da41b6e12ed59550b34c28d2a84eae0a31c5395bd589230a368891d9053159
9a758275144859206b6f3149212ba72c51ead3549da162723bd7d28116fa522e
30788def3a21b46e13085a4144b9d9ecc316d68da8a2492cd7bfda1e9afd316b
9085dc203b9498343a992249942f8b6408180baa2bba58fb799c81a0d1855686
f5192d0f7603e198e0b3098e9204ab40d11958a9bc27d8477db41cd5350b6242
15f617e02521dc3ca65cdc5442d2e5d079a4bbf70d64b465b903d28fcda44103
60c02fe06b1245384055747b14c0c5af879c0973ff23c7701a45fd92372bf631
89f618ae5abb8b3dfd00db8271c120503dff7ae17af576f4169ba4036f4562d7
4b0172ec49e672667d9b9ce4ff5ea0365ce29118728adeda23e5c21e7e170ba6
1d4ec9427f7548ec009c707abcea1938109b5202fcb59712645ead4eca956a72
7a6d0f4a00f827cf525de3d0028ffc70e2114315bcddd1298a719ddf74eb98d6
54fb069a625c765bcad6274dee9288ca9b3ce6cdcbeacae37a1248edfc5bd89a
SH256 hash:
52c542eccbcff90e81838e6c2980eb7be4258471a2ab776be25d770073599311
MD5 hash:
d18c315e0b163ce14231f62472d09822
SHA1 hash:
1c7ba0eebe12aa706c092fc424d56a3065141b79
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24 SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
b90d30fabfd911bdf2b7d785dee57ffd346019b889601d1411df2872d7d020d5
MD5 hash:
b6ace82ca0cb9b68828eb46e51739e90
SHA1 hash:
31021eee20bc7be003b29968cdfde3b2a2aec56c
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe b90d30fabfd911bdf2b7d785dee57ffd346019b889601d1411df2872d7d020d5

(this sample)

  
Delivery method
Distributed via e-mail attachment

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments