Report - d.hta

Formbook RAT
ScreenShot
Created 2023.05.25 10:59 Machine s1_win7_x6402
Filename d.hta
Type HTML document, ASCII text, with very long lines, with CRLF line terminators
AI Score Not founds Behavior Score
0.6
ZERO API file : clean
VT API (file)
md5 c808f7c2c8b88c92abf095f10afae803
sha256 95f678dbd0429decb07045c2d32a646e5d56dbf267a47c042de936be879b31d5
ssdeep 1536:IS928Eb9LPZCXztJ0TcMo+GQehfk/BsCJ5MY5/Dd5qbinFvQM3ZGPQ:IuqdCXRyxjBL5Mk/BsWFvQMEPQ
imphash
impfuzzy
  Network IP location

Signature (2cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
info One or more processes crashed

Rules (2cnts)

Level Name Description Collection
danger Win_Trojan_Formbook_Zero Used Formbook binaries (upload)
info Win_Backdoor_AsyncRAT_Zero Win Backdoor AsyncRAT binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure