MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cbe345880baebbc56c019721184c56577bccf0b66091b09f90163646f0bc7af7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: cbe345880baebbc56c019721184c56577bccf0b66091b09f90163646f0bc7af7
SHA3-384 hash: e4f313a6cca7ce20a28ba28cbace48b43af01bf675a083466a1c0630b056b4230718147fa4cb0d36a43421d0e5964efe
SHA1 hash: d0d3efa603e31f0b29744cecdab2ea19abf3b953
MD5 hash: 1f85ea51619710b5debdc67cb4c8b54f
humanhash: emma-missouri-dakota-earth
File name:SecuriteInfo.com.Fareit-FTA1F85EA516197.229
Download: download sample
Signature FormBook
File size:86'016 bytes
First seen:2020-05-08 04:41:12 UTC
Last seen:2020-05-08 16:40:48 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 5873275e2a236704a82318bd34d572bb (1 x FormBook)
ssdeep 768:UU2W3ATLM6qyIHw6+k36pq8JbcaVGWKPnrul3NPrtrawNYIPc:V2W32qyo6pPbZV57TZraqM
Threatray 5'092 similar samples on MalwareBazaar
TLSH 56830A52BDB4EC72D2107A75DBAAFA5EC35ABC381D31090724893B1D9F369029D3132E
Reporter SecuriteInfoCom
Tags:FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-08 05:35:24 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
19 of 31 (61.29%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Checks QEMU agent state file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

FormBook

Executable exe cbe345880baebbc56c019721184c56577bccf0b66091b09f90163646f0bc7af7

(this sample)

  
Delivery method
Distributed via web download

Comments