General

  • Target

    590b5eb75c4572a426d2b6a58951eeb9.bin

  • Size

    398KB

  • Sample

    240612-b4lqvayaln

  • MD5

    e26ddec36dd8794da72fca819ce2b8d7

  • SHA1

    57d7614df2504ef10a6bb093cabd5b4e9328f452

  • SHA256

    59dc5970164b760deb5d4ca96a52c373130d77085b06565e44db08f5171546dd

  • SHA512

    1131c2116b399dbf7215b6a26ef6e6c056d4ea7666a0261343111fe7d97d1ac3508f202230adfd89d5b2c9ccf0440f251c0d372ae4647220b99af2071bb43ac6

  • SSDEEP

    12288:mT8WTd0KlEUfFQu+54PTOnbd6nWIp7WlACjcfzlpe:mT8eXOnonwlzjaRY

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

ij84

Decoy

resetter.xyz

simonbelanger.me

kwip.xyz

7dbb9.baby

notion-everyday.com

saftiwall.com

pulse-gaming.com

fafafa1.shop

ihaveahole.com

sxtzzj.com

996688x.xyz

komalili.monster

haberdashere.store

nurselifegng.com

kidtryz.com

ghvx.xyz

1minvideopro.com

hidef.group

stylishbeststyler.space

spx21.com

Targets

    • Target

      fe55ce9692454e2449322576708c5ca42f335d9fb73f9daa605599e9e2ab4dd4.exe

    • Size

      670KB

    • MD5

      590b5eb75c4572a426d2b6a58951eeb9

    • SHA1

      d5a3cadb0b9ce83d9c86c044ce5c34f565c2e4e2

    • SHA256

      fe55ce9692454e2449322576708c5ca42f335d9fb73f9daa605599e9e2ab4dd4

    • SHA512

      bf3dfae9677795afa40f1b7d65144e25aeb15ad020f4d50b8ea9c578ebcf790215b3afe9a52711fc9ca716b21386f4edae966962464cb7c216c2245eb2902f7e

    • SSDEEP

      12288:FrSINW2pFKuYFPLJB/LpW8QxNPza/BrM+tK+CVINoX9yKBg7vj:FrSWbKRoiC9yKe/

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Drops startup file

    • Executes dropped EXE

    • Loads dropped DLL

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

2
T1012

System Information Discovery

3
T1082

Remote System Discovery

1
T1018

Tasks