General

  • Target

    New Order.exe

  • Size

    815KB

  • Sample

    240617-qn9kassfmd

  • MD5

    8282de81f994c057525b0c1213e2ff43

  • SHA1

    1ee376ff06d56b5d51f349e29bcc173ccfc9a4a1

  • SHA256

    e85c7115b0b9003f5b856a28c7d18262eec92e87c8c639a43ae4233962da5d24

  • SHA512

    60edf7ce44afc42e72aedad3c778af7fc742c38d4119aceef690c3b8ce7d562a1db8820c6a2b57c664c849388f3a281b7566900b71dac98c261227659b665f6f

  • SSDEEP

    12288:h5wSaeorXQpJE1oDOghGMxVFGgxRavD7R5GhYG2ucIcL:hj5EXq9D1hGjeGHGVK

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

na10

Decoy

tetheus.com

ventlikeyoumeanit.com

tintbliss.com

rinabet357.com

sapphireboutiqueusa.com

abc8bet6.com

xzcn3i7jb13cqei.buzz

pinktravelsnagpur.com

bt365038.com

rtpbossujang303.shop

osthirmaker.com

thelonelyteacup.com

rlc2019.com

couverture-charpente.com

productivagc.com

defendercarcare.com

abcentixdigital.com

petco.ltd

oypivh.top

micro.guru

Targets

    • Target

      New Order.exe

    • Size

      815KB

    • MD5

      8282de81f994c057525b0c1213e2ff43

    • SHA1

      1ee376ff06d56b5d51f349e29bcc173ccfc9a4a1

    • SHA256

      e85c7115b0b9003f5b856a28c7d18262eec92e87c8c639a43ae4233962da5d24

    • SHA512

      60edf7ce44afc42e72aedad3c778af7fc742c38d4119aceef690c3b8ce7d562a1db8820c6a2b57c664c849388f3a281b7566900b71dac98c261227659b665f6f

    • SSDEEP

      12288:h5wSaeorXQpJE1oDOghGMxVFGgxRavD7R5GhYG2ucIcL:hj5EXq9D1hGjeGHGVK

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks