General

  • Target

    a10740d29e2893feeb045ffc024317447b7bd06ccdb76e33da08ff97f1a9c48e

  • Size

    517KB

  • Sample

    240616-a7pfgawdjk

  • MD5

    22dfcea6b9a1cb6690a49b39be8eb18f

  • SHA1

    7c55b5acc2b63c984b44d56d7ab071da98dd31bc

  • SHA256

    a10740d29e2893feeb045ffc024317447b7bd06ccdb76e33da08ff97f1a9c48e

  • SHA512

    b457da101cf88ea6e847970b20f1ecf6ddd7f9bfe5699010621acebbf9edc97de3a32e338ed9e3e2ce2ca68f9122f31bdbe7eef2f2607cd523fbee013738ac76

  • SSDEEP

    12288:Q7JYXh0JJro3lFqXjumzt2RavD7R5GDYG2ucI:yih0JJrovcIGxGV

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

na10

Decoy

tetheus.com

ventlikeyoumeanit.com

tintbliss.com

rinabet357.com

sapphireboutiqueusa.com

abc8bet6.com

xzcn3i7jb13cqei.buzz

pinktravelsnagpur.com

bt365038.com

rtpbossujang303.shop

osthirmaker.com

thelonelyteacup.com

rlc2019.com

couverture-charpente.com

productivagc.com

defendercarcare.com

abcentixdigital.com

petco.ltd

oypivh.top

micro.guru

Targets

    • Target

      a10740d29e2893feeb045ffc024317447b7bd06ccdb76e33da08ff97f1a9c48e

    • Size

      517KB

    • MD5

      22dfcea6b9a1cb6690a49b39be8eb18f

    • SHA1

      7c55b5acc2b63c984b44d56d7ab071da98dd31bc

    • SHA256

      a10740d29e2893feeb045ffc024317447b7bd06ccdb76e33da08ff97f1a9c48e

    • SHA512

      b457da101cf88ea6e847970b20f1ecf6ddd7f9bfe5699010621acebbf9edc97de3a32e338ed9e3e2ce2ca68f9122f31bdbe7eef2f2607cd523fbee013738ac76

    • SSDEEP

      12288:Q7JYXh0JJro3lFqXjumzt2RavD7R5GDYG2ucI:yih0JJrovcIGxGV

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks