General

  • Target

    Payment.exe

  • Size

    714KB

  • Sample

    240706-akgr4ssdrd

  • MD5

    1eca8e2ba8d4939400ef3b6f315a68f2

  • SHA1

    6729aea498f4d5d67bd78776a309cd3c7c06e3cb

  • SHA256

    2a899ee00e6f2b09c002a3dc271e3ec7d15a7c98b8a3d9500f96dfd7fe941f4a

  • SHA512

    c826420eeaa3cb9726de4a20ff92b8d66b13b9edfd625e1955d9f5d44c86ba2987686789e99dc42c4f8ec734090259e9c7c4582fba05e7d8b02f6bd899718159

  • SSDEEP

    12288:mY5Qvy6uSajv6QAcFahFRavD7R5GMYG2ucItiyE:t5QvTuSar6QgjGqGV

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

na10

Decoy

tetheus.com

ventlikeyoumeanit.com

tintbliss.com

rinabet357.com

sapphireboutiqueusa.com

abc8bet6.com

xzcn3i7jb13cqei.buzz

pinktravelsnagpur.com

bt365038.com

rtpbossujang303.shop

osthirmaker.com

thelonelyteacup.com

rlc2019.com

couverture-charpente.com

productivagc.com

defendercarcare.com

abcentixdigital.com

petco.ltd

oypivh.top

micro.guru

Targets

    • Target

      Payment.exe

    • Size

      714KB

    • MD5

      1eca8e2ba8d4939400ef3b6f315a68f2

    • SHA1

      6729aea498f4d5d67bd78776a309cd3c7c06e3cb

    • SHA256

      2a899ee00e6f2b09c002a3dc271e3ec7d15a7c98b8a3d9500f96dfd7fe941f4a

    • SHA512

      c826420eeaa3cb9726de4a20ff92b8d66b13b9edfd625e1955d9f5d44c86ba2987686789e99dc42c4f8ec734090259e9c7c4582fba05e7d8b02f6bd899718159

    • SSDEEP

      12288:mY5Qvy6uSajv6QAcFahFRavD7R5GMYG2ucItiyE:t5QvTuSar6QgjGqGV

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks