General

  • Target

    Dograr Intl. Co. Ref PO_DG-251106001-2240613.pdf.ace

  • Size

    367KB

  • Sample

    240614-2vk13azapd

  • MD5

    cd4e76c5aeb2bda75025f100132cac77

  • SHA1

    4413a4fe001a2276d7a8ef5db9a8c56a52c8caa9

  • SHA256

    52dea1b2d1343335780111e30a42ae6477cd2f95dc797a66d99dae14d68687f5

  • SHA512

    648dbb5687423424510e7454cb977074b48291f60d095182df9712d672cd9e9f72df37429eb3559f1587901c3979448c1bdf79979ba568f19cbb1106a9df994d

  • SSDEEP

    6144:UYcaUhGiOzYw9yvvgWWm9KFQ9c+v/iIRimanU/o65Bpn/5t9aE4ajYw5t0z:AAXzYwAvYm9KalRijJ6PZ/5t9LZjYwTE

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

na10

Decoy

tetheus.com

ventlikeyoumeanit.com

tintbliss.com

rinabet357.com

sapphireboutiqueusa.com

abc8bet6.com

xzcn3i7jb13cqei.buzz

pinktravelsnagpur.com

bt365038.com

rtpbossujang303.shop

osthirmaker.com

thelonelyteacup.com

rlc2019.com

couverture-charpente.com

productivagc.com

defendercarcare.com

abcentixdigital.com

petco.ltd

oypivh.top

micro.guru

Targets

    • Target

      Dograr Intl. Co. Ref PO_DG-251106001-2240613.pdf.exe

    • Size

      517KB

    • MD5

      22dfcea6b9a1cb6690a49b39be8eb18f

    • SHA1

      7c55b5acc2b63c984b44d56d7ab071da98dd31bc

    • SHA256

      a10740d29e2893feeb045ffc024317447b7bd06ccdb76e33da08ff97f1a9c48e

    • SHA512

      b457da101cf88ea6e847970b20f1ecf6ddd7f9bfe5699010621acebbf9edc97de3a32e338ed9e3e2ce2ca68f9122f31bdbe7eef2f2607cd523fbee013738ac76

    • SSDEEP

      12288:Q7JYXh0JJro3lFqXjumzt2RavD7R5GDYG2ucI:yih0JJrovcIGxGV

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Deletes itself

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks