MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fae382236e9fdef35faef2dfe2c8f604917de1507900341fe50391abf56d1eb8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 13


Intelligence 13 IOCs YARA 2 File information Comments

SHA256 hash: fae382236e9fdef35faef2dfe2c8f604917de1507900341fe50391abf56d1eb8
SHA3-384 hash: 2decaf4292aa6680f02a9a24ddf45201075945727a1f75f5f153bb5e4bce9eb2df496cc6cfc1a65947260b6abb8791ed
SHA1 hash: 3779247b2e21fa498cd1acce59b55a31879b78d1
MD5 hash: acf677b6db86bd2bae4b72e7496a5fcd
humanhash: indigo-alpha-avocado-twelve
File name:Enclosed (SOA).exe
Download: download sample
Signature Formbook
File size:781'824 bytes
First seen:2023-06-13 07:15:00 UTC
Last seen:2023-06-15 16:16:50 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'657 x AgentTesla, 19'468 x Formbook, 12'206 x SnakeKeylogger)
ssdeep 12288:Is32iNyOe42KMu/N3mWhQmwmJCMpUH3wru+c5+Rm3cwzpKfVFVBvu8upjROXfy1:J1wOV/NOaxru+Aw1VFVBvuzpjP
Threatray 2'443 similar samples on MalwareBazaar
TLSH T175F40149737A5E7BC8762AFD8C166930C3FA4261707AD1D74EC368CE9DC4F942980A87
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10523/12/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4505/5/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Reporter cocaman
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
285
Origin country :
CH CH
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Enclosed (SOA).exe
Verdict:
No threats detected
Analysis date:
2023-06-13 07:17:42 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Launching a process
Creating a file
Unauthorized injection to a system process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
formbook packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
64 / 100
Signature
.NET source code contains potential unpacker
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2023-06-12 19:19:23 UTC
File Type:
PE (.Net Exe)
Extracted files:
10
AV detection:
25 of 37 (67.57%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Unpacked files
SH256 hash:
bcdf6407de5f7a6c9e2a5cd8d5d05acc08739585c4fc626c4e4cc1dec995d462
MD5 hash:
ca7c7722dd3923ddd9cf6d411d0a970a
SHA1 hash:
bed4d764bccfb3be1389eb735bc91c7685757cdc
SH256 hash:
135318882056118c5bbdbb625014fef26fa2a12ea88dc7bfc82cd65b24e3181a
MD5 hash:
52323ecbd0551870f55242737d5a675c
SHA1 hash:
d6bccfa1c32b22454fef601439c8cda914bc8f8a
SH256 hash:
c440617e04a50ced73c8ab992cbe8d8954a3e41f21f046ee9d1f2a41ea9b416d
MD5 hash:
9390df6c9a6111978dee5414bc42eda6
SHA1 hash:
d3cb1c366b9e466afa93eb369838a04d30777795
SH256 hash:
3b2eb4a4b65a4154f851e806687365ae8a33eb6ce9f7d74ca0258ab247605f6b
MD5 hash:
fc6a2d3e9eba21f51fa2d3308a591c15
SHA1 hash:
add909cdf8495e94a87a1bedfd10a5a3e45ab798
SH256 hash:
f8dbc6077f6b01c6eec334061d687ff1b291a2aa5513cf1e0b5bde4a8dbc5588
MD5 hash:
15aab611795bcbf2758052944013be1a
SHA1 hash:
772a1002b111e117cf3b1e9f0cabda4894777399
SH256 hash:
fae382236e9fdef35faef2dfe2c8f604917de1507900341fe50391abf56d1eb8
MD5 hash:
acf677b6db86bd2bae4b72e7496a5fcd
SHA1 hash:
3779247b2e21fa498cd1acce59b55a31879b78d1
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe fae382236e9fdef35faef2dfe2c8f604917de1507900341fe50391abf56d1eb8

(this sample)

Comments