MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c4e474e869076cbf955d57568015fe56732e0b3af1592f03e023063ac2875030. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c4e474e869076cbf955d57568015fe56732e0b3af1592f03e023063ac2875030
SHA3-384 hash: 1110273c849b4c7a9f36956c10527b9256edd25bfeeaf1c2d2c8388fa7194ac63cf9123c13ff8b475b7f0def1f7b4202
SHA1 hash: 6ec28dd60461267576685276309a301177b9a1f0
MD5 hash: 2b76423b76efa219911047811de9dbb3
humanhash: alabama-white-uranus-ten
File name:fake_svchost_vilech_formbook.exe
Download: download sample
Signature Formbook
File size:889'856 bytes
First seen:2020-04-30 07:32:20 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash cd04accb575d60487a31325798946cf8 (1 x Formbook)
ssdeep 24576:P+3jBSlgFMS7LSiPISH+nja+lPcMv0hTLbhsv6Nr08KH:PAlSl+nFqjRPtvITLbuiCl
Threatray 4'565 similar samples on MalwareBazaar
TLSH D415BF62F5D1D1B1F8D511B9D2FE2FB618395E03932690C7A6D03D84BEB01E2353E26A
Reporter jarumlus
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Unknown
Detection:
malicious
Classification:
spyw.evad.
Score:
100 / 100
Behaviour
Behavior Graph:
n/a
Gathering data
Threat name:
Win32.Trojan.Formbook
Status:
Malicious
First seen:
2019-03-28 17:41:16 UTC
File Type:
PE (Exe)
Extracted files:
11
AV detection:
27 of 31 (87.10%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Formbook

Executable exe c4e474e869076cbf955d57568015fe56732e0b3af1592f03e023063ac2875030

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
KERNEL32.dll::CreateThread
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::GetSystemInfo
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetDiskFreeSpaceW
KERNEL32.dll::GetDiskFreeSpaceA
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileW
KERNEL32.dll::CreateFileMappingA
KERNEL32.dll::CreateFileMappingW
KERNEL32.dll::CreateFileA
KERNEL32.dll::DeleteFileW
KERNEL32.dll::DeleteFileA
WIN_USER_APIPerforms GUI ActionsUSER32.dll::CreateWindowExW

Comments