Derin Statik Analiz — FormBook | Tehdit: high
Dosya Kimliği
| SHA256 | 64bb3ef49a6f0d11aa926b5af1cd93796af2137e529068859fc15f691c034510 |
|---|---|
| MD5 | 2e3dd45aaf15c4bc163554aec1f0f287 |
| SHA1 | 52bbcf346aadd9fb197b07192df37aa59af53452 |
| Dosya Adı | Quotation Request.exe |
| Boyut | 995840 byte |
| Tür | /opt/ksentinel/samples/64bb3ef49a6f0d11_QuotationRequest.exe: PE32 executable (GUI) Intel 80386 Mono |
| Derleme Tarihi | Bilinmiyor |
| Packer | UPX |
C2 Sunucuları
| Adres | Tip | Durum |
|---|---|---|
3.29.19.86 | IP | active |
Tespit Edilen IOC'lar
| Değer | Tip |
|---|---|
3.29.19.86 | IP |
System.IO | Domain |
Yetenekler
- —
Şifreleme: RijndaelManaged
Geliştirici İpuçları
Telegram: @2pON @8A8B8C8D8E8F8G8H8JI @bYQw @D2zky @D5FG
PE Analizi
PE Güvenlik Taraması
file entropy: 6.955553 (normal) fpu anti-disassembly: no imagebase: normal entrypoint: normal DOS stub: normal TLS directory: not found timestamp: normal section co
Import Tablosu (özet)
Imported functions
Library
Name: mscoree.dll
Functions
Function
Hint: 0
Name: _CorExeMain
Aile Tespiti — String Kanıtı
String kanıtı bulunamadı (obfuscated).
FormBook — Malware Profile
FormBook web form verisi ve credential hırsızı. SmartAssembly paketleyici. İspanyolca LATAM elektrik faturası lür.
Malware Type
Infostealer
Programming Language
C
C2 Protocol
HTTP
Target Systems
Windows
Also Known As (AKA)
xLoader
Technical Details
C dili, Windows API hooking (form grabbing), HTTP POST C2, browser form stealer, keylogger, screenshot, clipboard monitor, process injection (process hollowing)
Attribution / Threat Actor
ABD'de gelistirilmis; satis darknet forumlari uzerinden yapilmis. Dunya genelindeki multuple suc gruplarina hizmet veren MaaS platformu.
Capabilities & Behavior
Tarayıcı Kimlik Bilgileri
Çerez Hırsızlığı
Kripto Cüzdan Çalma
Sistem Bilgisi
Ekran Görüntüsü
FTP/SSH İstemci Şifreleri
E-posta İstemcisi Çalma
Veri Sızıntısı
IOC List (5 indicators)
IOC — FormBook
#
52bbcf346aadd9fb197b07192df37aa59af53452
# SHA256
64bb3ef49a6f0d11aa926b5af1cd93796af2137e529068859fc15f691c034510
# MD5
2e3dd45aaf15c4bc163554aec1f0f287
# IP
3.29.19.86
# DOMAIN
System.IO
| Type | Value | Note |
|---|---|---|
| 52bbcf346aadd9fb197b07192df37aa59af53452 | ||
| sha256 | 64bb3ef49a6f0d11aa926b5af1cd93796af2137e529068859fc15f691c034510 | |
| md5 | 2e3dd45aaf15c4bc163554aec1f0f287 | |
| ip | 3.29.19.86 | |
| domain | System.IO |
C2 Servers (5 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| 45.61.136.16 | ip | 80 | HTTP | active | US |
| hxxp://freeupgrades.net/s1xt/ | domain | 80 | HTTP | inactive | US |
| 103.75.160.239 | ip | 443 | HTTPS | inactive | HK |
| 3.29.19.86 | ip | — | TCP | inactive | — |
| form-book.club | domain | 80 | HTTP | sinkholed | — |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.