MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d3d0554ba519ad9eeba98fa7d81bd2761b8f0e5a86695d2ba45d08373456796f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: d3d0554ba519ad9eeba98fa7d81bd2761b8f0e5a86695d2ba45d08373456796f
SHA3-384 hash: 3c38de019a2f08d8a7a910f1a98290ea14df1ffd9a2306b94a7aa89b57c000e5333cef8bbd28c36173ece7f87ed44dad
SHA1 hash: 9728f52cda7af3b87bf9576bda1ef2cd68f03fe8
MD5 hash: 6ca1980b644f3e53e4dd14ce5f34c5d8
humanhash: montana-august-happy-potato
File name:MY00884Q00129.zip
Download: download sample
Signature Formbook
File size:6'789 bytes
First seen:2022-07-20 07:12:21 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 192:v4l5AJnigp6A+2vaEYfrnMpdg0DnxbYVZEccI5WbfMqat:v4l5AEAB0NUxsbE2obfMV
TLSH T13BE18E68DCA7A8636F47D2BEA8911B3D67E8B94A89016F8F7714C60790DF320215B721
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter cocaman
Tags:FormBook zip


Avatar
cocaman
Malicious email (T1566.001)
From: "Standard Chartered Bank <ari.ric@puzzest.com>" (likely spoofed)
Received: "from aymotall.puzzest.com (aymotall.puzzest.com [185.246.220.76]) "
Date: "19 Jul 2022 23:12:07 -0700"
Subject: "SUBJECT:Advice from Standard Chartered Bank"
Attachment: "MY00884Q00129.zip"

Intelligence


File Origin
# of uploads :
1
# of downloads :
155
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Spyware.Noon
Status:
Malicious
First seen:
2022-07-20 05:29:33 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
7 of 41 (17.07%)
Threat level:
  2/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook campaign:fs44 rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Checks computer location settings
Formbook payload
Formbook
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip d3d0554ba519ad9eeba98fa7d81bd2761b8f0e5a86695d2ba45d08373456796f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments