General
-
Target
MT103-746394.doc
-
Size
465KB
-
Sample
240624-s8r7vszeqe
-
MD5
fd8649f8d7287ef36bdcec7f9b2f98c9
-
SHA1
3e0d4305545d69aa47e741061adaf2a044d01d0d
-
SHA256
25128aab1edb1b7db3940787f0ae45722ea36b0a3e2423a155ea5618fab2af85
-
SHA512
308a4d5bbb969d34e448591e9caa1d4138ae25a2f8573d3f220de1487cb2ac3ebe08b3736d64e7d11f4cd46dbc867a2e5d5db7ceba89e2b382b74fb363863660
-
SSDEEP
6144:4wAYwAYwAYwAYwAYwAYwAYwAYwAYwAqFm4NvfB/0:T
Static task
static1
Behavioral task
behavioral1
Sample
MT103-746394.rtf
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
MT103-746394.rtf
Resource
win10v2004-20240508-en
Malware Config
Extracted
formbook
4.1
bi09
fayenterprises.online
anekagaminghk.rest
mina-chan.site
theselfcarefaire.com
progym.app
cherishedtimes.space
gkrp9s016x.icu
api288-s-rtp.online
chikankari.shop
annarosellc.com
lcloud.services
aisuitability.com
sks41.com
7779c1.vip
tunasolution.click
nexbetwin.com
huatless.quest
junroptskdyued.shop
yourwellnesseq.com
zcymc.top
alabamacoastalhomesforsale.com
gemline.online
hydroshinepowerwash.com
brandpromocodes.com
soicauxsmb.com
healthcare-trends-31189.bond
qg65.top
lipinpay.com
nfrcadrvcf.com
xn--72cb0bab2pc6b3j3b.com
cb191.pro
solargridsnorthtampabay.com
bodiedbycoyaaa.com
mh-card50.online
759my.xyz
davidlorenc.com
hub2367.com
vmjpdnls.xyz
parentingsupportgroup.xyz
roofing-services-15001.bond
searchhomeshamiltonmill.com
fhermer.com
emailsports.com
t-sit.com
j1xhon.com
67657.ooo
one-business-steering.com
bt365323.com
clientsun.site
bernzahnarzt.com
evriukpostcom.xyz
plasoi.xyz
fxrxvvpc.shop
ixdye610r.xyz
wvpbuildingservices.com
fabergerobotics.com
winday.xyz
myicecreambb.com
plusmc.site
eudlt417i.xyz
rajabet123-akunvip.xyz
lubaksa.shop
baicb.com
zhaotongshi0870.top
umc.autos
Targets
-
-
Target
MT103-746394.doc
-
Size
465KB
-
MD5
fd8649f8d7287ef36bdcec7f9b2f98c9
-
SHA1
3e0d4305545d69aa47e741061adaf2a044d01d0d
-
SHA256
25128aab1edb1b7db3940787f0ae45722ea36b0a3e2423a155ea5618fab2af85
-
SHA512
308a4d5bbb969d34e448591e9caa1d4138ae25a2f8573d3f220de1487cb2ac3ebe08b3736d64e7d11f4cd46dbc867a2e5d5db7ceba89e2b382b74fb363863660
-
SSDEEP
6144:4wAYwAYwAYwAYwAYwAYwAYwAYwAYwAqFm4NvfB/0:T
-
Formbook payload
-
Blocklisted process makes network request
-
Downloads MZ/PE file
-
Executes dropped EXE
-
Loads dropped DLL
-
Suspicious use of SetThreadContext
-