General

  • Target

    1eca8e2ba8d4939400ef3b6f315a68f2.bin

  • Size

    547KB

  • Sample

    240708-csrndsxgrj

  • MD5

    179b165f426033abb1b555ebc01e3217

  • SHA1

    efe74061acf0c9312ee321fae1d077c8229c89d8

  • SHA256

    89a9334d4157903300c1864c9c1cbdd85c4a559d8afa9feb5c13ca3744bf8d42

  • SHA512

    ae6f433b73b6e2541eb3498c825fbadce3208608039f6f535aec3a912d980074a79f6090401810de4678009a9436909a6fa43d3a9a63f3e6dc3b79d02f8957ed

  • SSDEEP

    12288:Z/r5lJaj4dANRrCF8eNsf6O6KhPO+Jq2kGAhMLVGslSQ:ZsjEAHCIfz5R1q2k3MPn

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

na10

Decoy

tetheus.com

ventlikeyoumeanit.com

tintbliss.com

rinabet357.com

sapphireboutiqueusa.com

abc8bet6.com

xzcn3i7jb13cqei.buzz

pinktravelsnagpur.com

bt365038.com

rtpbossujang303.shop

osthirmaker.com

thelonelyteacup.com

rlc2019.com

couverture-charpente.com

productivagc.com

defendercarcare.com

abcentixdigital.com

petco.ltd

oypivh.top

micro.guru

Targets

    • Target

      2a899ee00e6f2b09c002a3dc271e3ec7d15a7c98b8a3d9500f96dfd7fe941f4a.exe

    • Size

      714KB

    • MD5

      1eca8e2ba8d4939400ef3b6f315a68f2

    • SHA1

      6729aea498f4d5d67bd78776a309cd3c7c06e3cb

    • SHA256

      2a899ee00e6f2b09c002a3dc271e3ec7d15a7c98b8a3d9500f96dfd7fe941f4a

    • SHA512

      c826420eeaa3cb9726de4a20ff92b8d66b13b9edfd625e1955d9f5d44c86ba2987686789e99dc42c4f8ec734090259e9c7c4582fba05e7d8b02f6bd899718159

    • SSDEEP

      12288:mY5Qvy6uSajv6QAcFahFRavD7R5GMYG2ucItiyE:t5QvTuSar6QgjGqGV

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks