🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d1c2cc0ca653df8ddb46c1337a5972eaceb81ea924e8ebdb7af0699a7ab909fd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: d1c2cc0ca653df8ddb46c1337a5972eaceb81ea924e8ebdb7af0699a7ab909fd
SHA3-384 hash: 2fcb0882b9a1f41d37ddb338361262274ecc9ca6e79350a20dc978ed3684c0ef2fb6d151dd2341ef659abf927a3c8978
SHA1 hash: 98fdacf3212d4116bb9b7141cd7008414b082078
MD5 hash: 578684aff04e625a2d6801a2fbedc005
humanhash: lactose-steak-eleven-foxtrot
File name:19Jun22 ARR Safari.pdf
Download: download sample
Signature Formbook
File size:248'976 bytes
First seen:2022-06-19 07:22:45 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 6144:zcJ5l9vase0VfiJHlmwEJusJun+2iBOIm:zcPl9JcM1JusJun+3B0
TLSH T10B3402DDB23C5989D015C4B46FAD6F031A57EAF4FA6042BF2409C5272C188DCEE78A76
Reporter stu_b0t
Tags:CVE-2017-11882 CVE-2018-0802 FormBook pdf VelvetSweatshop

Intelligence


File Origin
# of uploads :
1
# of downloads :
672
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
CVE-2018-0802 embedequation exploit javascript packed shellcode VelvetSweatshop
Label:
Malicious
Suspicious Score:
5.4/10
Score Malicious:
54%
Score Benign:
46%
Result
Threat name:
Unknown
Detection:
malicious
Classification:
expl
Score:
52 / 100
Signature
Document exploit detected (process start blacklist hit)
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 648304 Sample: 19Jun22 ARR Safari.pdf Startdate: 19/06/2022 Architecture: WINDOWS Score: 52 17 Multi AV Scanner detection for submitted file 2->17 19 Document exploit detected (process start blacklist hit) 2->19 6 AcroRd32.exe 24 43 2->6         started        8 HxOutlook.exe 47 27 2->8         started        process3 process4 10 RdrCEF.exe 67 6->10         started        13 EXCEL.EXE 22 33 6->13         started        dnsIp5 15 192.168.2.1 unknown unknown 10->15
Threat name:
Document-OLE.Exploit.CVE-2017-11882
Status:
Malicious
First seen:
2022-06-18 22:53:15 UTC
File Type:
Document
Extracted files:
45
AV detection:
14 of 26 (53.85%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:exploit_any_poppopret
Author:Jeff White [karttoon@gmail.com] @noottrak
Description:Identify POP -> POP -> RET opcodes for quick ROP Gadget creation in target binaries.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

pdf d1c2cc0ca653df8ddb46c1337a5972eaceb81ea924e8ebdb7af0699a7ab909fd

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments