Resubmissions

20-06-2024 08:53

240620-ktnxwstajj 10

12-06-2024 02:32

240612-c1j9aaygnn 10

Analysis

  • max time kernel
    90s
  • max time network
    94s
  • platform
    windows11-21h2_x64
  • resource
    win11-20240508-en
  • resource tags

    arch:x64arch:x86image:win11-20240508-enlocale:en-usos:windows11-21h2-x64system
  • submitted
    20-06-2024 08:53

General

  • Target

    f1f3c884481aea76a89cfc659e509789e243226118ee103c76dafd76d73aa839.exe

  • Size

    656KB

  • MD5

    58683f82a5c6a4b53e5eea6e3d2df375

  • SHA1

    5781f6d4918dfb0260444dcbaf040dee3ffc0319

  • SHA256

    f1f3c884481aea76a89cfc659e509789e243226118ee103c76dafd76d73aa839

  • SHA512

    df9e89ad721ccfbb730bf82aa67d07697358910dbb401457f66e344b0c74c59ca36c12bfb6e829243fcb92a7f28c23a6aa13b24a05ccea2be55769cfaf795611

  • SSDEEP

    12288:/aCR5leZlNkbMvoHsUjsKZN5eJL/LaG2GcZO6EoLNSB2dC:i+erGMwMf8neJL/+GK3d

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

38gc

Decoy

fgoz3kry51.asia

vanishingacthairremoval.com

onlinelearningsandbox.com

feluca-egypt.com

goforsourcing.com

hairmadeperfect.com

brockspaydayearners.com

vintagetoj.com

tjandthecampers.com

emkanelajiehes.com

bestundersinkwaterfilter.com

proatta777.com

satuslot.beauty

nicolesbodybutter.com

montecarlogallery.com

homeautomation.one

cx-n1.ink

spennys.casa

gaozgn.cfd

hakajimai.online

Signatures

  • Formbook

    Formbook is a data stealing malware which is capable of stealing data.

  • Formbook payload 1 IoCs
  • Suspicious use of SetThreadContext 1 IoCs
  • Suspicious behavior: EnumeratesProcesses 2 IoCs
  • Suspicious use of WriteProcessMemory 6 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\f1f3c884481aea76a89cfc659e509789e243226118ee103c76dafd76d73aa839.exe
    "C:\Users\Admin\AppData\Local\Temp\f1f3c884481aea76a89cfc659e509789e243226118ee103c76dafd76d73aa839.exe"
    1⤵
    • Suspicious use of SetThreadContext
    • Suspicious use of WriteProcessMemory
    PID:2664
    • C:\Users\Admin\AppData\Local\Temp\f1f3c884481aea76a89cfc659e509789e243226118ee103c76dafd76d73aa839.exe
      "C:\Users\Admin\AppData\Local\Temp\f1f3c884481aea76a89cfc659e509789e243226118ee103c76dafd76d73aa839.exe"
      2⤵
      • Suspicious behavior: EnumeratesProcesses
      PID:732

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • memory/732-10-0x0000000000400000-0x000000000042F000-memory.dmp
    Filesize

    188KB

  • memory/732-13-0x0000000001870000-0x0000000001BC6000-memory.dmp
    Filesize

    3.3MB

  • memory/2664-6-0x0000000005CE0000-0x0000000005D02000-memory.dmp
    Filesize

    136KB

  • memory/2664-3-0x0000000005800000-0x0000000005892000-memory.dmp
    Filesize

    584KB

  • memory/2664-5-0x0000000074350000-0x0000000074B01000-memory.dmp
    Filesize

    7.7MB

  • memory/2664-4-0x0000000005990000-0x000000000599A000-memory.dmp
    Filesize

    40KB

  • memory/2664-0-0x000000007435E000-0x000000007435F000-memory.dmp
    Filesize

    4KB

  • memory/2664-7-0x0000000003080000-0x0000000003090000-memory.dmp
    Filesize

    64KB

  • memory/2664-8-0x0000000009990000-0x0000000009A06000-memory.dmp
    Filesize

    472KB

  • memory/2664-9-0x000000000CAA0000-0x000000000CB3C000-memory.dmp
    Filesize

    624KB

  • memory/2664-2-0x0000000005D10000-0x00000000062B6000-memory.dmp
    Filesize

    5.6MB

  • memory/2664-12-0x0000000074350000-0x0000000074B01000-memory.dmp
    Filesize

    7.7MB

  • memory/2664-1-0x0000000000CB0000-0x0000000000D58000-memory.dmp
    Filesize

    672KB