General

  • Target

    e81e4705d4485dbe4bcc7027c73e67ca5c52d46a43eb50c9a55cf178a2ef7b84

  • Size

    469KB

  • Sample

    240706-gezt3axclj

  • MD5

    12f938cace69ee49cb83bb9684beb240

  • SHA1

    0a7b892d0cedb69b7545c20936c4491ab60f56d5

  • SHA256

    e81e4705d4485dbe4bcc7027c73e67ca5c52d46a43eb50c9a55cf178a2ef7b84

  • SHA512

    583a80efe637816da884b6420183842f0df841525278f45f196b974c707fcd424c97fcdc3efb31ed3da4b6534ef8a5838bb2c047469c6769f6d648dfc7f029bc

  • SSDEEP

    12288:mJr5CGEAyqt79DrTFJkAnwuHqiIVKpFvvQlCdDB3oPO:gtORqB9vTFJBt/P/3QQdtV

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

na10

Decoy

tetheus.com

ventlikeyoumeanit.com

tintbliss.com

rinabet357.com

sapphireboutiqueusa.com

abc8bet6.com

xzcn3i7jb13cqei.buzz

pinktravelsnagpur.com

bt365038.com

rtpbossujang303.shop

osthirmaker.com

thelonelyteacup.com

rlc2019.com

couverture-charpente.com

productivagc.com

defendercarcare.com

abcentixdigital.com

petco.ltd

oypivh.top

micro.guru

Targets

    • Target

      15f84dc497c0b5c757f8fcc090e88adbfd25d506c267bd8c76f92824856931c4.exe

    • Size

      637KB

    • MD5

      b7c5b8e817f1520b433d097c68c71441

    • SHA1

      3dee3d2ffe1c32d3dcc6d140dbcfa06a55ada781

    • SHA256

      15f84dc497c0b5c757f8fcc090e88adbfd25d506c267bd8c76f92824856931c4

    • SHA512

      c366c3571db1717a9b0dcc5da6911bb3c2fc2135dffa06cabd62a4555fa25d2e8ce8df686531e917171e41d4211969dea5017146fc74f2a55b33af1529377cb8

    • SSDEEP

      12288:erFz+ZVgeTJ1kZjYqVRavD7R5GhYG2ucIg:0FzyVgSHqVGDGV

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks