MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d2fc030aa693bc5eb67fa48f9be53295af2c95b9b39365332f779225f89f7317. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: d2fc030aa693bc5eb67fa48f9be53295af2c95b9b39365332f779225f89f7317
SHA3-384 hash: f83eb0b5295b1f1b7dab251fb57f9794f0c3f8d51775a2d6ac167f31c212fed459b8d5ec3f31a22819d7f95e68fbd73a
SHA1 hash: e254a66d376c9e098fa31142e2bd226dcadca270
MD5 hash: 2be06ede47eb5febfeb54b57ff59dcbf
humanhash: virginia-eight-tango-vermont
File name:2be06ede47eb5febfeb54b57ff59dcbf.exe
Download: download sample
Signature Formbook
File size:1'098'944 bytes
First seen:2021-01-12 07:10:43 UTC
Last seen:2021-01-12 08:54:44 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 34688f6e75b1bb27a358488e10a9abac (3 x RemcosRAT, 2 x Loki, 1 x Phobos)
ssdeep 12288:nNZGyaAmYrFHmXVCu/BnA3ddRw+yRnSYeCRqlZVpiiiiiOvpeT:nN0DiZ0knO+qnS5CclZ7iiiiiMG
Threatray 11 similar samples on MalwareBazaar
TLSH 4B35A2A82478649FF3B24336DC06F134E956DF662046A12A3497E7FB64323C4D51EB2E
Reporter abuse_ch
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
142
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
2be06ede47eb5febfeb54b57ff59dcbf.exe
Verdict:
No threats detected
Analysis date:
2021-01-12 07:43:51 UTC
Tags:
installer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
52 / 100
Signature
Contains functionality to detect sleep reduction / modifications
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Spyware.AveMaria
Status:
Malicious
First seen:
2021-01-12 07:11:08 UTC
AV detection:
16 of 46 (34.78%)
Threat level:
  2/5
Result
Malware family:
modiloader
Score:
  10/10
Tags:
family:modiloader
Unpacked files
SH256 hash:
d2fc030aa693bc5eb67fa48f9be53295af2c95b9b39365332f779225f89f7317
MD5 hash:
2be06ede47eb5febfeb54b57ff59dcbf
SHA1 hash:
e254a66d376c9e098fa31142e2bd226dcadca270
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Formbook

Executable exe d2fc030aa693bc5eb67fa48f9be53295af2c95b9b39365332f779225f89f7317

(this sample)

  
Delivery method
Distributed via web download

Comments