General

  • Target

    4acc0dbaeb63dfaa4815deac04d75aeb8e9741c6fa66a5b55b460a4b3cf2b9b1.r01

  • Size

    555KB

  • Sample

    240620-bl2dksvenk

  • MD5

    2de4c2febf4246142e5d2bc4bc73cb03

  • SHA1

    5ca9ee49fad005dc646aa970bf27839a0765212c

  • SHA256

    4acc0dbaeb63dfaa4815deac04d75aeb8e9741c6fa66a5b55b460a4b3cf2b9b1

  • SHA512

    79b61c9f765e51ecbc2c15bf50da81864de8399ff5ac90ff02ec1c366a86cae59d013065b19a794736d76abe32dea41029741cebfe0e1b38c6dc8d3c7e837c80

  • SSDEEP

    12288:PCwtvHSCgC2kPil26/0eh+6R7496XccchADt54KJ0TEx:PngCql268e3R74UXcc34KJ0TEx

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

dy13

Decoy

manga-house.com

kjsdhklssk51.xyz

b0ba138.xyz

bt365033.com

ccbsinc.net

mrwine.xyz

nrxkrd527o.xyz

hoshi.social

1912ai.com

serco2020.com

byfchfyr.xyz

imuschestvostorgov.online

austinheafey.com

mrdfa.club

883106.photos

profitablefxmarkets.com

taini00.net

brye.top

ginsm.com

sportglid.com

Targets

    • Target

      IZPnmcCu5EZWa98.exe

    • Size

      594KB

    • MD5

      a5a66a419e31b8a69cf1bd612ec6ffde

    • SHA1

      a8e3a66fff21e337ada34998a717aaad0d323fc0

    • SHA256

      e004e6798d1e44ac7f24a273eeb129c8dfe9e4522baeda0e6756ec5319b90af1

    • SHA512

      9b797f22e6e1a030255adf506514ae3567fafc7853b5aa116a44bed0e63a62589cfe500cc84b98a62f10132fa14d2137da5c1622320433df71344bdad24faf93

    • SSDEEP

      12288:+FIsPALdYGwUQkNVgnkLclbIDCTBr4TXzwgOAju:YIKtGEkNynD5IOTexTj

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Deletes itself

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks