General

  • Target

    PROFORMA INVOICE - MV CNC BANGKOK - ST24PJ-287.exe

  • Size

    1.0MB

  • Sample

    240701-p2zrkswcnp

  • MD5

    f44bc4e0027f0f44d75fed04b8416be2

  • SHA1

    70fffcae8382f82570ec5b8e0389e7378c5db522

  • SHA256

    c019951411af4b89614d39e15b69e1798f267c54aebfe7e61852e4626bf00cbe

  • SHA512

    506d386d7fbd7506930017ba869573bb1e21762c002fb686740ef9cfd906459886fba519486600582f5ab903a958ddfeed81d5df92af6a16c2cc6951e34e9458

  • SSDEEP

    12288:5D9Q6t+p9J/s61NobMm1k4Wcqx9cpwtNHdlIoXcPANAe5WdNH6gsmxhgR6ZdEyGk:yoYck4JqncElfcINPewgsw26ZdxAx87

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

ps94

Decoy

gokorgiboard.com

17tk558f.com

xbtdlz.com

agence-dyf.com

azovtour.com

refreshoutdoors.shop

muyidajs.com

bull007s.autos

huskyacres.net

nryijx628b.xyz

romansotam.com

norlac.xyz

dorsetbusinessforum.com

prpasti.shop

amycostellospeech.com

dpaijvpiajvpin.top

rinabet371.com

corporatebushcraft.com

0755xx.com

wxsjlwkj2019.com

Targets

    • Target

      PROFORMA INVOICE - MV CNC BANGKOK - ST24PJ-287.exe

    • Size

      1.0MB

    • MD5

      f44bc4e0027f0f44d75fed04b8416be2

    • SHA1

      70fffcae8382f82570ec5b8e0389e7378c5db522

    • SHA256

      c019951411af4b89614d39e15b69e1798f267c54aebfe7e61852e4626bf00cbe

    • SHA512

      506d386d7fbd7506930017ba869573bb1e21762c002fb686740ef9cfd906459886fba519486600582f5ab903a958ddfeed81d5df92af6a16c2cc6951e34e9458

    • SSDEEP

      12288:5D9Q6t+p9J/s61NobMm1k4Wcqx9cpwtNHdlIoXcPANAe5WdNH6gsmxhgR6ZdEyGk:yoYck4JqncElfcINPewgsw26ZdxAx87

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Command and Scripting Interpreter: PowerShell

      Run Powershell to modify Windows Defender settings to add exclusions for file extensions, paths, and processes.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

1
T1059

PowerShell

1
T1059.001

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks