Resubmissions

01-07-2024 19:19

240701-x1p5raydmj 10

General

  • Target

    mQY9ka5sW6hv2Ri.exe

  • Size

    584KB

  • Sample

    240701-x1p5raydmj

  • MD5

    e97620420d37596704d9f4fa70303453

  • SHA1

    533b98b289ba07c446f8350950fdbee2ab39dcf2

  • SHA256

    a5a3067e6a3c4e957152655df5c68ce4db77f8308feff43c53e7535031033be5

  • SHA512

    a5ee774c492216568a9c16768cf83188cc261e1f4888cbe4aff9717bc13bccade2594ffe04bac35367213e8b3288e2671841320d529aa5f5a168e1756c6c7ed3

  • SSDEEP

    12288:wanv6lRPM97SMRgqbFwWAEY/Z1NJQtUa2e0szSoMXGjxbFtACUYsOl7n9W1ei:5IRombqbFwWrYn7Q32e0GSUptACOOBn9

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

dy13

Decoy

manga-house.com

kjsdhklssk51.xyz

b0ba138.xyz

bt365033.com

ccbsinc.net

mrwine.xyz

nrxkrd527o.xyz

hoshi.social

1912ai.com

serco2020.com

byfchfyr.xyz

imuschestvostorgov.online

austinheafey.com

mrdfa.club

883106.photos

profitablefxmarkets.com

taini00.net

brye.top

ginsm.com

sportglid.com

Targets

    • Target

      mQY9ka5sW6hv2Ri.exe

    • Size

      584KB

    • MD5

      e97620420d37596704d9f4fa70303453

    • SHA1

      533b98b289ba07c446f8350950fdbee2ab39dcf2

    • SHA256

      a5a3067e6a3c4e957152655df5c68ce4db77f8308feff43c53e7535031033be5

    • SHA512

      a5ee774c492216568a9c16768cf83188cc261e1f4888cbe4aff9717bc13bccade2594ffe04bac35367213e8b3288e2671841320d529aa5f5a168e1756c6c7ed3

    • SSDEEP

      12288:wanv6lRPM97SMRgqbFwWAEY/Z1NJQtUa2e0szSoMXGjxbFtACUYsOl7n9W1ei:5IRombqbFwWrYn7Q32e0GSUptACOOBn9

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks