MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e30934706120cb94fa1b52ff9d64ae43a3ea73b51efeaf50a936a982a9a7d5e2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e30934706120cb94fa1b52ff9d64ae43a3ea73b51efeaf50a936a982a9a7d5e2
SHA3-384 hash: 5570ec5d90823ca82027b84b4481d9607dc96f8adfa9641ac988da723a2a69946e9abc21115e9c665c79cb6fd8fe95cd
SHA1 hash: e85154d3821a930ccd477126eed611051d2f448a
MD5 hash: 7710ef8595f95e0d152c5fa63a7a8cee
humanhash: pizza-hamper-mockingbird-mississippi
File name:e30934706120cb94fa1b52ff9d64ae43a3ea73b51efeaf50a936a982a9a7d5e2
Download: download sample
Signature Formbook
File size:735'232 bytes
First seen:2020-03-23 16:26:11 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 7a2d2aa167b54ff07419da1382503b99 (1 x Formbook)
ssdeep 12288:dK7de+RxGRCWZfuOJjHESZ7aYPl+9QEQmMpCCvMeT2qT96RvXYq:dsg+Khn9BNv5EKZUSf6Rv
Threatray 4'856 similar samples on MalwareBazaar
TLSH 75F4BF67F1E04C33D2361A7CBD1BAB65A939FD112E2469422BF85C8C9F396813C660D7
Reporter Marco_Ramilli
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Formbook

Executable exe e30934706120cb94fa1b52ff9d64ae43a3ea73b51efeaf50a936a982a9a7d5e2

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and Threadskernel32.dll::CloseHandle
kernel32.dll::CreateThread
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryExA
kernel32.dll::LoadLibraryA
kernel32.dll::GetSystemInfo
kernel32.dll::GetStartupInfoA
kernel32.dll::GetDiskFreeSpaceA
kernel32.dll::GetCommandLineA
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateFileA
kernel32.dll::GetFileAttributesA
kernel32.dll::FindFirstFileA
kernel32.dll::GetTempPathA
version.dll::GetFileVersionInfoSizeA
version.dll::GetFileVersionInfoA
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegOpenKeyExA
advapi32.dll::RegQueryValueExA
WIN_USER_APIPerforms GUI Actionsuser32.dll::ActivateKeyboardLayout
user32.dll::CreateMenu
user32.dll::EmptyClipboard
user32.dll::FindWindowA
user32.dll::OpenClipboard
user32.dll::PeekMessageA

Comments