Report - bin---0.exe

Formbook PE File PE32
ScreenShot
Created 2021.05.24 18:23 Machine s1_win7_x6401
Filename bin---0.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
9
Behavior Score
3.6
ZERO API file : clean
VT API (file) 44 detected (AIDetect, malware2, malicious, high confidence, Formbook, GenericRXLS, Unsafe, Save, Eldorado, score, Razy, ccmw, Siggen9, A + Troj, ZPACK, R369478, ai score=80, BScope, TrojanPSW, Fareit, dGZlOgKB3kMUFgoSCw, Static AI, Malicious PE, susgen, GenKryptik, AYEB, confidence, 100%)
md5 9191f2c11d448ac2baa34768d210f3a7
sha256 8d27c368e6431f796a96389ac517d654ca3de20a6b9047095a47691532c7cf11
ssdeep 3072:qnB3Iv1lKekDI1xqMoAjrE6j30kSxSObtCxv4kLay2CG5ETpA:qx3DmLoAvRz0kSkObtCxv4kLDG5wpA
imphash
impfuzzy 3::
  Network IP location

Signature (7cnts)

Level Description
danger File has been identified by 44 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Performs some HTTP requests
notice Sends data using the HTTP POST Method
notice The binary likely contains encrypted or compressed data indicative of a packer

Rules (3cnts)

Level Name Description Collection
danger Win_Trojan_Formbook_Zero Used Formbook binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (44cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://www.leonardocarrillo.com/p2io/ Unknown clean
http://www.micheldrake.com/p2io/?8pz8KT3x=d2NgnqRQHDqC8zfUpSeXKrGILlrAeXd0mpzt/HUKTHCMsqjNpHqiPqxZu8ECgv8Wi9ydyjUw&CR=CFQH8Xe US AUTOMATTIC 192.0.78.25 clean
http://www.yunlimall.com/p2io/ US EGIHOSTING 142.111.47.2 clean
http://www.vectoroutlines.com/p2io/?8pz8KT3x=RfOK6jKjejKyxd8Ge5LTyAppaXreGCTFIzs53vHZyU46XfbA28pKG3jMmZvEd1BBCDsLyI+Y&CR=CFQH8Xe US NAMECHEAP-NET 198.54.126.105 clean
http://www.adultpeace.com/p2io/ JP GMO Internet,Inc 163.44.239.73 clean
http://www.liminaltechnology.com/p2io/?8pz8KT3x=PfX6gvL1n2k6iJTsm2w17tv0qq3FBu3hWsZA38xYtqeUN4691F0nKiAgOKyjpkHMBi57ZW6+&CR=CFQH8Xe HU Websupport s.r.o. 185.111.89.170 clean
http://www.adultpeace.com/p2io/?8pz8KT3x=4oufm6g7w9cVhgu+mDBWoA8I6Q2bNaX51teMhl/6i5f1woTl8Y4Ohfe29cQ9y7IaJQfIj0iK&CR=CFQH8Xe JP GMO Internet,Inc 163.44.239.73 clean
http://www.alfenas.info/p2io/ US GOOGLE 34.102.136.180 clean
http://www.untylservice.com/p2io/?8pz8KT3x=L8zxg9SOaofWzoyPv00N4yNSfvs8vmV6MzKbpPLG03vcM8SdHJJ++2zBKn8m8TZ8Pf8jLpz7&CR=CFQH8Xe DE Hostinger International Limited 185.224.137.223 clean
http://www.alfenas.info/p2io/?8pz8KT3x=qSqSgno9cBloRqN5VLtR5zfvl4qKeuO7jrdOV5f2r4ZX0X85kelskx3YtL4YRmLXGzhxb6Nv&CR=CFQH8Xe US GOOGLE 34.102.136.180 clean
http://www.liminaltechnology.com/p2io/ HU Websupport s.r.o. 185.111.89.170 clean
http://www.essentiallyourscandles.com/p2io/?8pz8KT3x=tOwaJov3Qh/So8Abi3+vLu8KpTdHs2Vuljr6rtQHuYg94Ec45hj5yXZ1J0+xHcOVWF/IMli4&CR=CFQH8Xe CA CLOUDFLARENET 23.227.38.74 clean
http://www.untylservice.com/p2io/ DE Hostinger International Limited 185.224.137.223 clean
http://www.vectoroutlines.com/p2io/ US NAMECHEAP-NET 198.54.126.105 clean
http://www.myfavbutik.com/p2io/ US CLOUDFLARENET 104.21.15.16 clean
http://www.yunlimall.com/p2io/?8pz8KT3x=FG8u3oFYMEksByvCNClu9ACxgqrSnZ6gPOMyaYsdv+YEYVVrg2Qkx51ZmTmiwfcSVwhsWZbW&CR=CFQH8Xe US EGIHOSTING 142.111.47.2 clean
http://www.essentiallyourscandles.com/p2io/ CA CLOUDFLARENET 23.227.38.74 clean
http://www.leonardocarrillo.com/p2io/?8pz8KT3x=Z8FkwwkotLBkQtrDqM/eMJCTIQtJD+6S4GTF4HzAZ8KQRsKSHf3+L+a292aesc2eaUyoVCup&CR=CFQH8Xe Unknown clean
http://www.micheldrake.com/p2io/ US AUTOMATTIC 192.0.78.25 clean
http://www.myfavbutik.com/p2io/?8pz8KT3x=dKp6rERBK113SD0GvHZ5ksFEU2G9ncFkpMVxqDe1xbP28bbT8N8SqFHc7ZWN2qvn1fWpyoOF&CR=CFQH8Xe US CLOUDFLARENET 104.21.15.16 clean
www.leonardocarrillo.com Unknown clean
www.essentiallyourscandles.com CA CLOUDFLARENET 23.227.38.74 clean
www.vectoroutlines.com US NAMECHEAP-NET 198.54.126.105 clean
www.pandemisorgugirisi-tr.com Unknown clean
www.adultpeace.com JP GMO Internet,Inc 163.44.239.73 clean
www.liminaltechnology.com HU Websupport s.r.o. 185.111.89.170 clean
www.buylocalclub.info Unknown clean
www.tricqr.com Unknown clean
www.micheldrake.com US AUTOMATTIC 192.0.78.25 clean
www.myfavbutik.com US CLOUDFLARENET 172.67.161.4 clean
www.alfenas.info US GOOGLE 34.102.136.180 clean
www.untylservice.com DE Hostinger International Limited 185.224.137.223 clean
www.zgcbw.net Unknown clean
www.yunlimall.com US EGIHOSTING 142.111.47.2 clean
185.224.137.223 DE Hostinger International Limited 185.224.137.223 clean
163.44.239.73 JP GMO Internet,Inc 163.44.239.73 clean
198.54.126.105 US NAMECHEAP-NET 198.54.126.105 mailcious
209.99.40.222 US CONFLUENCE-NETWORK-INC 209.99.40.222 mailcious
185.111.89.170 HU Websupport s.r.o. 185.111.89.170 clean
34.102.136.180 US GOOGLE 34.102.136.180 mailcious
104.21.15.16 US CLOUDFLARENET 104.21.15.16 clean
192.0.78.24 US AUTOMATTIC 192.0.78.24 mailcious
23.227.38.74 CA CLOUDFLARENET 23.227.38.74 mailcious
142.111.47.2 US EGIHOSTING 142.111.47.2 clean

Suricata ids

PE API

IAT(Import Address Table) is none

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure