General

  • Target

    e004e6798d1e44ac7f24a273eeb129c8dfe9e4522baeda0e6756ec5319b90af1.exe

  • Size

    594KB

  • Sample

    240620-b8ne8ssbld

  • MD5

    a5a66a419e31b8a69cf1bd612ec6ffde

  • SHA1

    a8e3a66fff21e337ada34998a717aaad0d323fc0

  • SHA256

    e004e6798d1e44ac7f24a273eeb129c8dfe9e4522baeda0e6756ec5319b90af1

  • SHA512

    9b797f22e6e1a030255adf506514ae3567fafc7853b5aa116a44bed0e63a62589cfe500cc84b98a62f10132fa14d2137da5c1622320433df71344bdad24faf93

  • SSDEEP

    12288:+FIsPALdYGwUQkNVgnkLclbIDCTBr4TXzwgOAju:YIKtGEkNynD5IOTexTj

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

dy13

Decoy

manga-house.com

kjsdhklssk51.xyz

b0ba138.xyz

bt365033.com

ccbsinc.net

mrwine.xyz

nrxkrd527o.xyz

hoshi.social

1912ai.com

serco2020.com

byfchfyr.xyz

imuschestvostorgov.online

austinheafey.com

mrdfa.club

883106.photos

profitablefxmarkets.com

taini00.net

brye.top

ginsm.com

sportglid.com

Targets

    • Target

      e004e6798d1e44ac7f24a273eeb129c8dfe9e4522baeda0e6756ec5319b90af1.exe

    • Size

      594KB

    • MD5

      a5a66a419e31b8a69cf1bd612ec6ffde

    • SHA1

      a8e3a66fff21e337ada34998a717aaad0d323fc0

    • SHA256

      e004e6798d1e44ac7f24a273eeb129c8dfe9e4522baeda0e6756ec5319b90af1

    • SHA512

      9b797f22e6e1a030255adf506514ae3567fafc7853b5aa116a44bed0e63a62589cfe500cc84b98a62f10132fa14d2137da5c1622320433df71344bdad24faf93

    • SSDEEP

      12288:+FIsPALdYGwUQkNVgnkLclbIDCTBr4TXzwgOAju:YIKtGEkNynD5IOTexTj

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Detects executables packed with SmartAssembly

    • Formbook payload

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks