General

  • Target

    PO._21007438-SCH_30724.exe

  • Size

    637KB

  • Sample

    240704-tvs3ns1ene

  • MD5

    b7c5b8e817f1520b433d097c68c71441

  • SHA1

    3dee3d2ffe1c32d3dcc6d140dbcfa06a55ada781

  • SHA256

    15f84dc497c0b5c757f8fcc090e88adbfd25d506c267bd8c76f92824856931c4

  • SHA512

    c366c3571db1717a9b0dcc5da6911bb3c2fc2135dffa06cabd62a4555fa25d2e8ce8df686531e917171e41d4211969dea5017146fc74f2a55b33af1529377cb8

  • SSDEEP

    12288:erFz+ZVgeTJ1kZjYqVRavD7R5GhYG2ucIg:0FzyVgSHqVGDGV

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

na10

Decoy

tetheus.com

ventlikeyoumeanit.com

tintbliss.com

rinabet357.com

sapphireboutiqueusa.com

abc8bet6.com

xzcn3i7jb13cqei.buzz

pinktravelsnagpur.com

bt365038.com

rtpbossujang303.shop

osthirmaker.com

thelonelyteacup.com

rlc2019.com

couverture-charpente.com

productivagc.com

defendercarcare.com

abcentixdigital.com

petco.ltd

oypivh.top

micro.guru

Targets

    • Target

      PO._21007438-SCH_30724.exe

    • Size

      637KB

    • MD5

      b7c5b8e817f1520b433d097c68c71441

    • SHA1

      3dee3d2ffe1c32d3dcc6d140dbcfa06a55ada781

    • SHA256

      15f84dc497c0b5c757f8fcc090e88adbfd25d506c267bd8c76f92824856931c4

    • SHA512

      c366c3571db1717a9b0dcc5da6911bb3c2fc2135dffa06cabd62a4555fa25d2e8ce8df686531e917171e41d4211969dea5017146fc74f2a55b33af1529377cb8

    • SSDEEP

      12288:erFz+ZVgeTJ1kZjYqVRavD7R5GhYG2ucIg:0FzyVgSHqVGDGV

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks