General

  • Target

    PAZxQIjeuyCNRXg.exe

  • Size

    603KB

  • Sample

    240708-g2lkyswenp

  • MD5

    10a8103659aad83e4d7e38aa31c612a4

  • SHA1

    3ae41c624f25f782208b06fedfd6600835bc6a43

  • SHA256

    3108dc358ffd2e4dbc93fdd1aa4e71b605bceb8ceb14cd31df9b4c796811b77b

  • SHA512

    572cab9c6c0f7c59d2a5cd2534e1ad7bcc80f6566eb090900335c90921dec857a6ec69ce49871672c73463b556f2db170832973e6885685f6133898420f891f3

  • SSDEEP

    12288:a4Dzsi6OfS7Idp4X1TqTEA5dFr0g3NLr6TMXouP9d2jJ:a4DDLS7/X1TqTp/x3BmHu+J

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

dy13

Decoy

manga-house.com

kjsdhklssk51.xyz

b0ba138.xyz

bt365033.com

ccbsinc.net

mrwine.xyz

nrxkrd527o.xyz

hoshi.social

1912ai.com

serco2020.com

byfchfyr.xyz

imuschestvostorgov.online

austinheafey.com

mrdfa.club

883106.photos

profitablefxmarkets.com

taini00.net

brye.top

ginsm.com

sportglid.com

Targets

    • Target

      PAZxQIjeuyCNRXg.exe

    • Size

      603KB

    • MD5

      10a8103659aad83e4d7e38aa31c612a4

    • SHA1

      3ae41c624f25f782208b06fedfd6600835bc6a43

    • SHA256

      3108dc358ffd2e4dbc93fdd1aa4e71b605bceb8ceb14cd31df9b4c796811b77b

    • SHA512

      572cab9c6c0f7c59d2a5cd2534e1ad7bcc80f6566eb090900335c90921dec857a6ec69ce49871672c73463b556f2db170832973e6885685f6133898420f891f3

    • SSDEEP

      12288:a4Dzsi6OfS7Idp4X1TqTEA5dFr0g3NLr6TMXouP9d2jJ:a4DDLS7/X1TqTp/x3BmHu+J

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Deletes itself

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks