MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 dc7ebbb50daeb8d518dc37a89775ffd1062b0b40014afa69ff2195370fb2f30d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 16
| SHA256 hash: | dc7ebbb50daeb8d518dc37a89775ffd1062b0b40014afa69ff2195370fb2f30d |
|---|---|
| SHA3-384 hash: | 5f2dacf4078d575437716046e878509809579ce096e9951b7c3e7a423d4e2a78ab6ab62d834150f157fbe680c67c26cc |
| SHA1 hash: | 5eea79136a8a337ab43a88d21e55f92b2db74718 |
| MD5 hash: | a796e201c6de52790bf473c385efb84d |
| humanhash: | illinois-nebraska-sad-enemy |
| File name: | SecuriteInfo.com.Win32.CrypterX-gen.2899.32710 |
| Download: | download sample |
| Signature | Formbook |
| File size: | 606'720 bytes |
| First seen: | 2024-09-09 09:22:24 UTC |
| Last seen: | 2024-09-09 10:18:57 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'648 x AgentTesla, 19'452 x Formbook, 12'201 x SnakeKeylogger) |
| ssdeep | 12288:S1xTx3j5DTx7EXuE331INsSB9HsP5A0cClmkDt1pDttlp9i72l:qHFkuK32ftW5A0cEm0ZFkE |
| TLSH | T1CAD4126952A8D902D5A443740972E3BA1738BE5EE621D30A4FCEBCF3741BB907D24793 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
# of uploads :
2
# of downloads :
486
Origin country :
FRVendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
SecuriteInfo.com.Win32.CrypterX-gen.2899.32710
Verdict:
No threats detected
Analysis date:
2024-09-09 09:24:26 UTC
Tags:
n/a
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
Generic Static Swotter
Result
Verdict:
Malware
Maliciousness:
Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Tags:
packed
Verdict:
Malicious
Labled as:
Malware
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
Formbook
Verdict:
Malicious
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Found malware configuration
Injects a PE file into a foreign processes
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Tries to detect virtualization through RDTSC time measurements
Yara detected AntiVM3
Yara detected FormBook
Behaviour
Behavior Graph:
Score:
100%
Verdict:
Malware
File Type:
PE
Threat name:
Win32.Backdoor.FormBook
Status:
Malicious
First seen:
2024-09-09 09:06:07 UTC
File Type:
PE (.Net Exe)
Extracted files:
5
AV detection:
24 of 38 (63.16%)
Threat level:
5/5
Detection(s):
Suspicious file
Verdict:
malicious
Label(s):
formbook
Result
Malware family:
formbook
Score:
10/10
Tags:
family:formbook campaign:b31a discovery rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Formbook payload
Formbook
Verdict:
Malicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
c83c0a367712867b960ce8d742a57cfe6231d65cfe5eb14cdcced497d77fcd65
MD5 hash:
3abd239253118b6d0a823b9efd1ca97c
SHA1 hash:
1da5c763b07be907a24dc57d3d22e278ca9be6ad
Detections:
FormBook
win_formbook_g0
win_formbook_auto
win_formbook_w0
Formbook
Parent samples :
df40a36c01c2a67d0343913950f8c79d0937dcb2e29d7fa4d12dba92128efc02
66ee67315e480d95d46e6d84096a64fcb99038b565e74afba831487f9d75461f
8af00e7a5aa93e2c083481d3b4e5b94f7d1844aab13f13fde1b27a986f38f662
7dbfe3e815092dfd471861a962bbb464ec76438144f4cb5dd031b02eda2f8ea9
435424456ff6964a551a626db39ad606b58644f6ae9189e1e590aec8d645c397
05f3157ada1ddc0583e51a8602f352a8f9a4e139b6a624ee80a0e1acb7372920
dc7ebbb50daeb8d518dc37a89775ffd1062b0b40014afa69ff2195370fb2f30d
af4f28ed9e5d8205220c60f42668e6576233f54885c63fcaf43c2315328f45f1
26b9c2220fa1bef6a477b8303062792420b9fbf3eb4d21da840b11bf93c5d9dc
42e319dba75dc914d5645a6fc1025984c6e64a34303cb7c5e9b936aade524efe
e23bf1a652dd78590f79e4a350dd7869c9c5477ef9d1dcae78504ac4fa46cada
e915f0f594c0cc1c43241cbe47784d5a203dc521c341eb8aa95c6e6d10ff65b3
3d7f6d2750179e8e650d7a689b3271955aadc23e58c2fd6d43077a313ff8707b
59ab557c3e419cd201601311a28669d9eaff788ff92f6cbe6733382d5883f80b
a9ca3955156a843f095203a36d37f40d305926be366fbc1238e73e8590284655
aaad2261843429b4a8574c5c3fd1a80e2462fab4abdd1581eb4dacca34084882
874c6faee7e17445012c0f573c29dde997a71cc86e15fc3152a22365cf83bdf1
66ee67315e480d95d46e6d84096a64fcb99038b565e74afba831487f9d75461f
8af00e7a5aa93e2c083481d3b4e5b94f7d1844aab13f13fde1b27a986f38f662
7dbfe3e815092dfd471861a962bbb464ec76438144f4cb5dd031b02eda2f8ea9
435424456ff6964a551a626db39ad606b58644f6ae9189e1e590aec8d645c397
05f3157ada1ddc0583e51a8602f352a8f9a4e139b6a624ee80a0e1acb7372920
dc7ebbb50daeb8d518dc37a89775ffd1062b0b40014afa69ff2195370fb2f30d
af4f28ed9e5d8205220c60f42668e6576233f54885c63fcaf43c2315328f45f1
26b9c2220fa1bef6a477b8303062792420b9fbf3eb4d21da840b11bf93c5d9dc
42e319dba75dc914d5645a6fc1025984c6e64a34303cb7c5e9b936aade524efe
e23bf1a652dd78590f79e4a350dd7869c9c5477ef9d1dcae78504ac4fa46cada
e915f0f594c0cc1c43241cbe47784d5a203dc521c341eb8aa95c6e6d10ff65b3
3d7f6d2750179e8e650d7a689b3271955aadc23e58c2fd6d43077a313ff8707b
59ab557c3e419cd201601311a28669d9eaff788ff92f6cbe6733382d5883f80b
a9ca3955156a843f095203a36d37f40d305926be366fbc1238e73e8590284655
aaad2261843429b4a8574c5c3fd1a80e2462fab4abdd1581eb4dacca34084882
874c6faee7e17445012c0f573c29dde997a71cc86e15fc3152a22365cf83bdf1
SH256 hash:
2847fbe10e2792c04315b776caa7d37dd7e316e980d5aceb47ed11750a204f65
MD5 hash:
374221dac26baa376fefcdc96d7335b5
SHA1 hash:
b7ad48b494ca7a52277346a56639f2dfbea1eceb
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24
SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
c59a72e874640d2d2c5669edc14fdeb82a72cbacde61679907d2926b8ed79d08
MD5 hash:
b37fc99b846edbde0d0f36bee1760849
SHA1 hash:
0016396b048dcbda5b87742c32678f706db6362c
SH256 hash:
dc7ebbb50daeb8d518dc37a89775ffd1062b0b40014afa69ff2195370fb2f30d
MD5 hash:
a796e201c6de52790bf473c385efb84d
SHA1 hash:
5eea79136a8a337ab43a88d21e55f92b2db74718
Malware family:
FormBook
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Formbook
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
No further information available
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.