General

  • Target

    e97620420d37596704d9f4fa70303453.bin

  • Size

    546KB

  • Sample

    240703-d5h3fszcjp

  • MD5

    77496d0b603649e6ecaf38ac15d0567b

  • SHA1

    c5062fe7d01dd1a5273aec8f472ddba650868df2

  • SHA256

    89ec5c0d8c32482281b1493fe7075d790cc2fc62ff3e2c7f81fbe27c4913e2de

  • SHA512

    1b0d41c8817fe9c5a9fa7ff7b62f5c3cc61400c804fe6db7662d5099819c050b2cc5f70e9549f57c1b9fb934ce5900ba901a8145d4386d5eab4ef6190f916c83

  • SSDEEP

    12288:bJApYXrp0Jm7uQJDVvLTbeamYP2WIv50f7x6/acdpN1ZC:lAdIJ3G9WIKfl6C6zC

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

dy13

Decoy

manga-house.com

kjsdhklssk51.xyz

b0ba138.xyz

bt365033.com

ccbsinc.net

mrwine.xyz

nrxkrd527o.xyz

hoshi.social

1912ai.com

serco2020.com

byfchfyr.xyz

imuschestvostorgov.online

austinheafey.com

mrdfa.club

883106.photos

profitablefxmarkets.com

taini00.net

brye.top

ginsm.com

sportglid.com

Targets

    • Target

      a5a3067e6a3c4e957152655df5c68ce4db77f8308feff43c53e7535031033be5.exe

    • Size

      584KB

    • MD5

      e97620420d37596704d9f4fa70303453

    • SHA1

      533b98b289ba07c446f8350950fdbee2ab39dcf2

    • SHA256

      a5a3067e6a3c4e957152655df5c68ce4db77f8308feff43c53e7535031033be5

    • SHA512

      a5ee774c492216568a9c16768cf83188cc261e1f4888cbe4aff9717bc13bccade2594ffe04bac35367213e8b3288e2671841320d529aa5f5a168e1756c6c7ed3

    • SSDEEP

      12288:wanv6lRPM97SMRgqbFwWAEY/Z1NJQtUa2e0szSoMXGjxbFtACUYsOl7n9W1ei:5IRombqbFwWrYn7Q32e0GSUptACOOBn9

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks