MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bcdfc779372272941a86132fe14ef811d9d0faa47e5430175122b0bc2a215dcb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: bcdfc779372272941a86132fe14ef811d9d0faa47e5430175122b0bc2a215dcb
SHA3-384 hash: f19ffa509ded1690c574a610e47bd8dbd33541421b77367f7440e05239bc4fdb637c9a3df977cab79a87d433394235c2
SHA1 hash: fc58a69204dd5bba922f347cb37b325d179e982f
MD5 hash: 267691fd1499d18f835dc12fef17ea1d
humanhash: cup-undress-harry-twelve
File name:bcdfc779372272941a86132fe14ef811d9d0faa47e5430175122b0bc2a215dcb
Download: download sample
Signature FormBook
File size:686'080 bytes
First seen:2020-04-07 19:15:11 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash e89afcbcfdfa93008df71eedbaa248e8 (6 x AgentTesla, 3 x Loki, 2 x FormBook)
ssdeep 12288:P79EsfzsZh1jQntckNWjDRIwu+w46sYRMMEX6WyLvDkkvJIVRwR5:5Dfoh6tcFDRQ+9JM2qJ8k6VKR5
Threatray 4'898 similar samples on MalwareBazaar
TLSH A9E4AE22B2B04C37D3A3267D8C1F57A8A8267E513D6759862FED1C4C5F3D38134AA297
Reporter srcr
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-03-26 18:04:30 UTC
File Type:
PE (Exe)
Extracted files:
48
AV detection:
28 of 31 (90.32%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
WIN32_PROCESS_APICan Create Process and Threadskernel32.dll::CloseHandle
kernel32.dll::CreateThread
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryExA
kernel32.dll::LoadLibraryA
kernel32.dll::GetSystemInfo
kernel32.dll::GetStartupInfoA
kernel32.dll::GetDiskFreeSpaceA
kernel32.dll::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programskernel32.dll::WinExec
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateFileA
kernel32.dll::FindFirstFileA
version.dll::GetFileVersionInfoSizeA
version.dll::GetFileVersionInfoA
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegOpenKeyExA
advapi32.dll::RegQueryValueExA
WIN_USER_APIPerforms GUI Actionsuser32.dll::ActivateKeyboardLayout
user32.dll::CreateMenu
user32.dll::FindWindowA
user32.dll::PeekMessageA
user32.dll::CreateWindowExA

Comments