MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dacb9aad48869f1349e62dd30eb4aca9eaff7355e67c1611616cd23c0b823934. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 12


Intelligence 12 IOCs YARA 13 File information Comments

SHA256 hash: dacb9aad48869f1349e62dd30eb4aca9eaff7355e67c1611616cd23c0b823934
SHA3-384 hash: ee815044788b3359e2a9727ddc27e285174ae005637964e509123fe7d37e071484738ead9e50a140f852e72c9dc632af
SHA1 hash: a0f877913bbcba46bb3cc5b6479fdc2593335281
MD5 hash: 135b23d07b760c07b340e87030d40c7c
humanhash: indigo-video-pennsylvania-island
File name:17131599069a0e2ee3c772313de436652eb63fc16f458874beccd156253cf564a27491c5be430.dat-decoded
Download: download sample
Signature Formbook
File size:268'800 bytes
First seen:2024-04-15 05:45:07 UTC
Last seen:2024-04-15 06:34:50 UTC
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 6144:AyynRpQtS0fhjh2NQf6irwJhIKv8nyCbZBNtjzntbZq7H:NyfCS0feNDkFckxA
TLSH T1324423C5730285A5CC1EE67B519F346991962E1E1BE83387FB8E2D31B42C19BE371287
Reporter abuse_ch
Tags:base64-decoded exe FormBook


Avatar
abuse_ch
Malware dropped as base64 encoded payload

Intelligence


File Origin
# of uploads :
2
# of downloads :
447
Origin country :
DE DE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
dacb9aad48869f1349e62dd30eb4aca9eaff7355e67c1611616cd23c0b823934.exe
Verdict:
Suspicious activity
Analysis date:
2024-04-15 05:49:59 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Launching a process
Moving a file to the Program Files subdirectory
Replacing files
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
overlay packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj
Score:
76 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected FormBook
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.FormBook
Status:
Malicious
First seen:
2024-04-15 05:46:05 UTC
File Type:
PE (Exe)
AV detection:
20 of 24 (83.33%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
formbook
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
d41c9d555bbde1cac10fc0e236e317559c83ada5fc1de6bbda6279d23770cc83
MD5 hash:
c498851924581d77d0e0538ace0146f2
SHA1 hash:
4f3abdd97b3d619c37a227aca4f2163af1dabb64
Detections:
win_formbook_w0 win_formbook_g0
SH256 hash:
9c831c29338d9257f4f45289f0988b1fa1ed1533ad954cda531c9421654688d1
MD5 hash:
0c5fa3877a2dc472f2611a91c590f343
SHA1 hash:
cdc76ea146bb25a05e9f597fcca98d8f9041666e
SH256 hash:
98d77b341fdb027c538b35fee80bac7376b38eadf9325aac34704921ada51115
MD5 hash:
dbfb08d5d5153622d8365aedba776e7c
SHA1 hash:
9843adc460bdafb71062e13bc9fbdacf09eae3e2
SH256 hash:
25c67d0905b14835406608894475c96be38a192a4f847d0a0013d5553f8fa0f9
MD5 hash:
72972bf53541727b59c39291c032f01d
SHA1 hash:
906ba61e9b7a9210983eea5e642ae51d83c7e7b2
SH256 hash:
9b709fe79388d03f816f4477790a5654a66ca536921cba0edd9462e3b2f2e1da
MD5 hash:
91a3705ce74b7f462c7527ca9621538b
SHA1 hash:
35251a4010220334d3af23d1eef2a01bef0d4d6d
SH256 hash:
b3723589104a1898a5111133dedf825a8b26137e8bc3340f74d5d4b651fbe166
MD5 hash:
73ebf91dbe095cb3e0687db8f493f0cd
SHA1 hash:
327b24fdb9e812f9406eadb72c0add984df3a8a5
SH256 hash:
f392e5e8079a78077c57f316d15ebfda74748469e693d5608e7e8773406a3d22
MD5 hash:
4985f19af9cfd5731c7741d8fb957570
SHA1 hash:
0eaefe9e423e07ac3107ebba943281afb37d333b
SH256 hash:
dacb9aad48869f1349e62dd30eb4aca9eaff7355e67c1611616cd23c0b823934
MD5 hash:
135b23d07b760c07b340e87030d40c7c
SHA1 hash:
a0f877913bbcba46bb3cc5b6479fdc2593335281
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__GlobalFlags
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Active
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:maldoc_getEIP_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns

File information


The table below shows additional information about this malware sample such as delivery method and external references.

9a0e2ee3c772313de436652eb63fc16f458874beccd156253cf564a27491c5be

Formbook

Executable exe dacb9aad48869f1349e62dd30eb4aca9eaff7355e67c1611616cd23c0b823934

(this sample)

  
Dropped by
SHA256 9a0e2ee3c772313de436652eb63fc16f458874beccd156253cf564a27491c5be
  
Dropped by
MD5 70a9c5aba5bc8a49d2d582a5ae6d3620
  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments