Derin Statik Analiz — FormBook | Tehdit: high

Dosya Kimligi

SHA256ab7a9209e242ed3c0a29e678edfd76bed53d00664ec27c4d3ef4ab4aef8a8248
MD5c512ff0eb09c96041e38e344ce382995
SHA1ad06e6c6bb21a8f91160bf7c9cd1c25155a5e97b
Boyut723380 byte
Tur/opt/ksentinel/samples/64bb3ef49a6f0d11aa926b5af1cd93796af2137e529068859fc15f691
DerlemeBilinmiyor
PackerUPX
C2 Adresi: Sifrelenmis/obfuskeli config (statik analizle cozulemedi)

Yetenekler

  • Tespit edilemedi (obfuskeli)

Gelistirici Ipuclari

PDB Yolu: bash: -c: line 1: syntax error near unexpected token `|' bash: -c: line 1: `grep -oiE '[A-Za-z]:\\Users\\[^\\]{2,30}\\[^

Telegram: @109M @EpLb @fo4w @JcZ7 @mIn_C

PE Analizi

Binwalk / Packer

DECIMAL       HEXADECIMAL     DESCRIPTION
--------------------------------------------------------------------------------
0             0x0             Zip archive data, encrypted compressed size: 72

Aile Tespiti

String kaniti bulunamadi (sifrelenmis/obfuskeli).

FormBook — Malware Profile

FormBook web form verisi ve credential hırsızı. SmartAssembly paketleyici. İspanyolca LATAM elektrik faturası lür.

Malware Type
Infostealer
Programming Language
C
C2 Protocol
HTTP
Target Systems
Windows
Also Known As (AKA)
xLoader

Technical Details

C dili, Windows API hooking (form grabbing), HTTP POST C2, browser form stealer, keylogger, screenshot, clipboard monitor, process injection (process hollowing)

Attribution / Threat Actor

ABD'de gelistirilmis; satis darknet forumlari uzerinden yapilmis. Dunya genelindeki multuple suc gruplarina hizmet veren MaaS platformu.

Capabilities & Behavior

Tarayıcı Kimlik Bilgileri
Çerez Hırsızlığı
Kripto Cüzdan Çalma
Sistem Bilgisi
Ekran Görüntüsü
FTP/SSH İstemci Şifreleri
E-posta İstemcisi Çalma
Veri Sızıntısı

IOC List (5 indicators)

IOC — FormBook
# ad06e6c6bb21a8f91160bf7c9cd1c25155a5e97b # SHA256 ab7a9209e242ed3c0a29e678edfd76bed53d00664ec27c4d3ef4ab4aef8a8248 # MD5 c512ff0eb09c96041e38e344ce382995 # FILEPATH bash: -c: line 1: syntax error near unexpected token `|' # FILEPATH bash: -c: line 1: `grep -oiE '[A-Za-z]:\\[^\s\"'\'<>|*?]{5,150}' /tmp/all.txt | grep -viE '(msbuild|nuget|packages|Microsoft\.NET)' | sort -u | head -10'
TypeValueNote
ad06e6c6bb21a8f91160bf7c9cd1c25155a5e97b
sha256 ab7a9209e242ed3c0a29e678edfd76bed53d00664ec27c4d3ef4ab4aef8a8248
md5 c512ff0eb09c96041e38e344ce382995
filepath bash: -c: line 1: syntax error near unexpected token `|'
filepath bash: -c: line 1: `grep -oiE '[A-Za-z]:\\[^\s\"'\'<>|*?]{5,150}' /tmp/all.txt | grep -viE '(msbuild|nuget|packages|Microsoft\.NET)' | sort -u | head -10'

C2 Servers (5 recorded servers for this family)

Address Type Port Protocol Status Country
45.61.136.16 ip 80 HTTP active US
hxxp://freeupgrades.net/s1xt/ domain 80 HTTP inactive US
103.75.160.239 ip 443 HTTPS inactive HK
3.29.19.86 ip &mdash; TCP inactive &mdash;
form-book.club domain 80 HTTP sinkholed &mdash;

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
formbookstatik-analizhighc2iocpe