General

  • Target

    PAGO BANORTE 6142024pdf.iso

  • Size

    1.1MB

  • Sample

    240621-pz6r4szfpe

  • MD5

    2b06887603a2023194d82575594f1e96

  • SHA1

    e97dce5f32ec4a3f5eab974f10efa28c3f04d292

  • SHA256

    fb92f304400b9274eec3a4e893cfc21b3fbe8036926992e387358e2034c37772

  • SHA512

    185d6f810ca5ca536696ec2a96e56cdb86d766c2eb802577d1123f52ddf4bc3b269b39c96695d32ea08992c5949b078464724fcc75706149314a5f6d9bc4e251

  • SSDEEP

    24576:sAHnh+eWsN3skA4RV1Hom2KXMmHaasO9G2EW/tC5:Lh+ZkldoPK8YaasOg2EW/i

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

es13

Decoy

xn--p5tz1dc38d1tj.com

letszum.co

16475.autos

eat.company

ruletka-no-zero.store

mizj1yg0.shop

sxyaddhlmk.top

wlgj6789.cc

mammamiacookbook.com

sunart.tech

dutajp.co

odty58.app

newparentssupport.com

p2pprofitarbitrage.com

yeqzik.xyz

ncheikta.website

golfwick.com

premiumproducts.co.in

gemeinde-warringholz.com

bancamarch-web-avisos.com

Targets

    • Target

      PAGO BANORTE 6142024pdf.exe

    • Size

      1.1MB

    • MD5

      c9c6594fc73129a42cf3d589c662190c

    • SHA1

      a0686ac0c2e2b742ad3d21277da1bcd513eab8bc

    • SHA256

      807f9abf6e410264a3c0adf50e8e92bdcffeb20fbd52c67450aff6801ab2e0e6

    • SHA512

      d2a022ada910905a74feb9b99b25b929c05cb742e7743f96a2c0bdb1d6364bf1c2701832fe00251d2f08a03be450508ec1fb0192ad6614561c53c2bf20b5209a

    • SSDEEP

      24576:AAHnh+eWsN3skA4RV1Hom2KXMmHaasO9G2EW/tC5:3h+ZkldoPK8YaasOg2EW/i

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • AutoIT Executable

      AutoIT scripts compiled to PE executables.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks