00000000.00000002.408488225.0000000002B1D000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AntiVM_3 | Yara detected AntiVM_3 | Joe Security | |
0000000D.00000002.632823935.0000000002DD0000.00000040.80000000.00040000.00000000.sdmp | JoeSecurity_FormBook | Yara detected FormBook | Joe Security | |
0000000D.00000002.632823935.0000000002DD0000.00000040.80000000.00040000.00000000.sdmp | Windows_Trojan_Formbook_1112e116 | unknown | unknown | - 0x6621:$a1: 3C 30 50 4F 53 54 74 09 40
- 0x1d7d0:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
- 0xa95f:$a3: 1A D2 80 E2 AF 80 C2 7E EB 2A 80 FA 2F 75 11 8A D0 80 E2 01
- 0x16b87:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
|
0000000D.00000002.632823935.0000000002DD0000.00000040.80000000.00040000.00000000.sdmp | Formbook_1 | autogenerated rule brought to you by yara-signator | Felix Bilstein - yara-signator at cocacoding dot com | - 0x16985:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
- 0x16431:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
- 0x16a87:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
- 0x16bff:$sequence_4: 5D C3 8D 50 7C 80 FA 07
- 0xa52a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
- 0x1567c:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
- 0xb272:$sequence_7: 66 89 0C 02 5B 8B E5 5D
- 0x1c427:$sequence_8: 3C 54 74 04 3C 74 75 F4
- 0x1d53a:$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
|
0000000D.00000002.632823935.0000000002DD0000.00000040.80000000.00040000.00000000.sdmp | Formbook | detect Formbook in memory | JPCERT/CC Incident Response Group | - 0x18e79:$sqlite3step: 68 34 1C 7B E1
- 0x18fac:$sqlite3step: 68 34 1C 7B E1
- 0x18ebb:$sqlite3text: 68 38 2A 90 C5
- 0x19003:$sqlite3text: 68 38 2A 90 C5
- 0x18ed2:$sqlite3blob: 68 53 D8 7F 8C
- 0x19025:$sqlite3blob: 68 53 D8 7F 8C
|
00000000.00000002.407071082.00000000028F3000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_AntiVM_3 | Yara detected AntiVM_3 | Joe Security | |
00000006.00000000.403522788.0000000000401000.00000040.00000400.00020000.00000000.sdmp | JoeSecurity_FormBook | Yara detected FormBook | Joe Security | |
00000006.00000000.403522788.0000000000401000.00000040.00000400.00020000.00000000.sdmp | Windows_Trojan_Formbook_1112e116 | unknown | unknown | - 0x5621:$a1: 3C 30 50 4F 53 54 74 09 40
- 0x1c7d0:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
- 0x995f:$a3: 1A D2 80 E2 AF 80 C2 7E EB 2A 80 FA 2F 75 11 8A D0 80 E2 01
- 0x15b87:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
|
00000006.00000000.403522788.0000000000401000.00000040.00000400.00020000.00000000.sdmp | Formbook_1 | autogenerated rule brought to you by yara-signator | Felix Bilstein - yara-signator at cocacoding dot com | - 0x15985:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
- 0x15431:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
- 0x15a87:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
- 0x15bff:$sequence_4: 5D C3 8D 50 7C 80 FA 07
- 0x952a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
- 0x1467c:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
- 0xa272:$sequence_7: 66 89 0C 02 5B 8B E5 5D
- 0x1b427:$sequence_8: 3C 54 74 04 3C 74 75 F4
- 0x1c53a:$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
|
00000006.00000000.403522788.0000000000401000.00000040.00000400.00020000.00000000.sdmp | Formbook | detect Formbook in memory | JPCERT/CC Incident Response Group | - 0x17e79:$sqlite3step: 68 34 1C 7B E1
- 0x17fac:$sqlite3step: 68 34 1C 7B E1
- 0x17ebb:$sqlite3text: 68 38 2A 90 C5
- 0x18003:$sqlite3text: 68 38 2A 90 C5
- 0x17ed2:$sqlite3blob: 68 53 D8 7F 8C
- 0x18025:$sqlite3blob: 68 53 D8 7F 8C
|
00000000.00000002.409203550.000000000397B000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_FormBook | Yara detected FormBook | Joe Security | |
00000000.00000002.409203550.000000000397B000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Formbook_1112e116 | unknown | unknown | - 0x75b1:$a1: 3C 30 50 4F 53 54 74 09 40
- 0x325d1:$a1: 3C 30 50 4F 53 54 74 09 40
- 0x5c5f1:$a1: 3C 30 50 4F 53 54 74 09 40
- 0x1e760:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
- 0x49780:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
- 0x737a0:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
- 0xb8ef:$a3: 1A D2 80 E2 AF 80 C2 7E EB 2A 80 FA 2F 75 11 8A D0 80 E2 01
- 0x3690f:$a3: 1A D2 80 E2 AF 80 C2 7E EB 2A 80 FA 2F 75 11 8A D0 80 E2 01
- 0x6092f:$a3: 1A D2 80 E2 AF 80 C2 7E EB 2A 80 FA 2F 75 11 8A D0 80 E2 01
- 0x17b17:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
- 0x42b37:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
- 0x6cb57:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
|
00000000.00000002.409203550.000000000397B000.00000004.00000800.00020000.00000000.sdmp | Formbook_1 | autogenerated rule brought to you by yara-signator | Felix Bilstein - yara-signator at cocacoding dot com | - 0x17915:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
- 0x42935:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
- 0x6c955:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
- 0x173c1:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
- 0x423e1:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
- 0x6c401:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
- 0x17a17:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
- 0x42a37:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
- 0x6ca57:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
- 0x17b8f:$sequence_4: 5D C3 8D 50 7C 80 FA 07
- 0x42baf:$sequence_4: 5D C3 8D 50 7C 80 FA 07
- 0x6cbcf:$sequence_4: 5D C3 8D 50 7C 80 FA 07
- 0xb4ba:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
- 0x364da:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
- 0x604fa:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
- 0x1660c:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
- 0x4162c:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
- 0x6b64c:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
- 0xc202:$sequence_7: 66 89 0C 02 5B 8B E5 5D
- 0x37222:$sequence_7: 66 89 0C 02 5B 8B E5 5D
- 0x61242:$sequence_7: 66 89 0C 02 5B 8B E5 5D
|
00000000.00000002.409203550.000000000397B000.00000004.00000800.00020000.00000000.sdmp | Formbook | detect Formbook in memory | JPCERT/CC Incident Response Group | - 0x19e09:$sqlite3step: 68 34 1C 7B E1
- 0x19f3c:$sqlite3step: 68 34 1C 7B E1
- 0x44e29:$sqlite3step: 68 34 1C 7B E1
- 0x44f5c:$sqlite3step: 68 34 1C 7B E1
- 0x6ee49:$sqlite3step: 68 34 1C 7B E1
- 0x6ef7c:$sqlite3step: 68 34 1C 7B E1
- 0x19e4b:$sqlite3text: 68 38 2A 90 C5
- 0x19f93:$sqlite3text: 68 38 2A 90 C5
- 0x44e6b:$sqlite3text: 68 38 2A 90 C5
- 0x44fb3:$sqlite3text: 68 38 2A 90 C5
- 0x6ee8b:$sqlite3text: 68 38 2A 90 C5
- 0x6efd3:$sqlite3text: 68 38 2A 90 C5
- 0x19e62:$sqlite3blob: 68 53 D8 7F 8C
- 0x19fb5:$sqlite3blob: 68 53 D8 7F 8C
- 0x44e82:$sqlite3blob: 68 53 D8 7F 8C
- 0x44fd5:$sqlite3blob: 68 53 D8 7F 8C
- 0x6eea2:$sqlite3blob: 68 53 D8 7F 8C
- 0x6eff5:$sqlite3blob: 68 53 D8 7F 8C
|
00000007.00000000.463881212.000000000D63F000.00000040.00000001.00040000.00000000.sdmp | JoeSecurity_FormBook | Yara detected FormBook | Joe Security | |
00000007.00000000.463881212.000000000D63F000.00000040.00000001.00040000.00000000.sdmp | Windows_Trojan_Formbook_1112e116 | unknown | unknown | - 0xe7d0:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
- 0x7b87:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
|
00000007.00000000.463881212.000000000D63F000.00000040.00000001.00040000.00000000.sdmp | Formbook_1 | autogenerated rule brought to you by yara-signator | Felix Bilstein - yara-signator at cocacoding dot com | - 0x7985:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
- 0x7431:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
- 0x7a87:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
- 0x7bff:$sequence_4: 5D C3 8D 50 7C 80 FA 07
- 0x667c:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
- 0xd427:$sequence_8: 3C 54 74 04 3C 74 75 F4
- 0xe53a:$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
|
00000007.00000000.463881212.000000000D63F000.00000040.00000001.00040000.00000000.sdmp | Formbook | detect Formbook in memory | JPCERT/CC Incident Response Group | - 0x9e79:$sqlite3step: 68 34 1C 7B E1
- 0x9fac:$sqlite3step: 68 34 1C 7B E1
- 0x9ebb:$sqlite3text: 68 38 2A 90 C5
- 0xa003:$sqlite3text: 68 38 2A 90 C5
- 0x9ed2:$sqlite3blob: 68 53 D8 7F 8C
- 0xa025:$sqlite3blob: 68 53 D8 7F 8C
|
00000007.00000000.484050905.000000000D63F000.00000040.00000001.00040000.00000000.sdmp | JoeSecurity_FormBook | Yara detected FormBook | Joe Security | |
00000007.00000000.484050905.000000000D63F000.00000040.00000001.00040000.00000000.sdmp | Windows_Trojan_Formbook_1112e116 | unknown | unknown | - 0xe7d0:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
- 0x7b87:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
|
00000007.00000000.484050905.000000000D63F000.00000040.00000001.00040000.00000000.sdmp | Formbook_1 | autogenerated rule brought to you by yara-signator | Felix Bilstein - yara-signator at cocacoding dot com | - 0x7985:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
- 0x7431:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
- 0x7a87:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
- 0x7bff:$sequence_4: 5D C3 8D 50 7C 80 FA 07
- 0x667c:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
- 0xd427:$sequence_8: 3C 54 74 04 3C 74 75 F4
- 0xe53a:$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
|
00000007.00000000.484050905.000000000D63F000.00000040.00000001.00040000.00000000.sdmp | Formbook | detect Formbook in memory | JPCERT/CC Incident Response Group | - 0x9e79:$sqlite3step: 68 34 1C 7B E1
- 0x9fac:$sqlite3step: 68 34 1C 7B E1
- 0x9ebb:$sqlite3text: 68 38 2A 90 C5
- 0xa003:$sqlite3text: 68 38 2A 90 C5
- 0x9ed2:$sqlite3blob: 68 53 D8 7F 8C
- 0xa025:$sqlite3blob: 68 53 D8 7F 8C
|
0000000D.00000002.631975004.0000000002CD0000.00000040.10000000.00040000.00000000.sdmp | JoeSecurity_FormBook | Yara detected FormBook | Joe Security | |
0000000D.00000002.631975004.0000000002CD0000.00000040.10000000.00040000.00000000.sdmp | Windows_Trojan_Formbook_1112e116 | unknown | unknown | - 0x6621:$a1: 3C 30 50 4F 53 54 74 09 40
- 0x1d7d0:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
- 0xa95f:$a3: 1A D2 80 E2 AF 80 C2 7E EB 2A 80 FA 2F 75 11 8A D0 80 E2 01
- 0x16b87:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
|
0000000D.00000002.631975004.0000000002CD0000.00000040.10000000.00040000.00000000.sdmp | Formbook_1 | autogenerated rule brought to you by yara-signator | Felix Bilstein - yara-signator at cocacoding dot com | - 0x16985:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
- 0x16431:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
- 0x16a87:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
- 0x16bff:$sequence_4: 5D C3 8D 50 7C 80 FA 07
- 0xa52a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
- 0x1567c:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
- 0xb272:$sequence_7: 66 89 0C 02 5B 8B E5 5D
- 0x1c427:$sequence_8: 3C 54 74 04 3C 74 75 F4
- 0x1d53a:$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
|
0000000D.00000002.631975004.0000000002CD0000.00000040.10000000.00040000.00000000.sdmp | Formbook | detect Formbook in memory | JPCERT/CC Incident Response Group | - 0x18e79:$sqlite3step: 68 34 1C 7B E1
- 0x18fac:$sqlite3step: 68 34 1C 7B E1
- 0x18ebb:$sqlite3text: 68 38 2A 90 C5
- 0x19003:$sqlite3text: 68 38 2A 90 C5
- 0x18ed2:$sqlite3blob: 68 53 D8 7F 8C
- 0x19025:$sqlite3blob: 68 53 D8 7F 8C
|
0000000D.00000002.631553136.0000000000B90000.00000004.00000800.00020000.00000000.sdmp | JoeSecurity_FormBook | Yara detected FormBook | Joe Security | |
0000000D.00000002.631553136.0000000000B90000.00000004.00000800.00020000.00000000.sdmp | Windows_Trojan_Formbook_1112e116 | unknown | unknown | - 0x6621:$a1: 3C 30 50 4F 53 54 74 09 40
- 0x1d7d0:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
- 0xa95f:$a3: 1A D2 80 E2 AF 80 C2 7E EB 2A 80 FA 2F 75 11 8A D0 80 E2 01
- 0x16b87:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
|
0000000D.00000002.631553136.0000000000B90000.00000004.00000800.00020000.00000000.sdmp | Formbook_1 | autogenerated rule brought to you by yara-signator | Felix Bilstein - yara-signator at cocacoding dot com | - 0x16985:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
- 0x16431:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
- 0x16a87:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
- 0x16bff:$sequence_4: 5D C3 8D 50 7C 80 FA 07
- 0xa52a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
- 0x1567c:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
- 0xb272:$sequence_7: 66 89 0C 02 5B 8B E5 5D
- 0x1c427:$sequence_8: 3C 54 74 04 3C 74 75 F4
- 0x1d53a:$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
|
0000000D.00000002.631553136.0000000000B90000.00000004.00000800.00020000.00000000.sdmp | Formbook | detect Formbook in memory | JPCERT/CC Incident Response Group | - 0x18e79:$sqlite3step: 68 34 1C 7B E1
- 0x18fac:$sqlite3step: 68 34 1C 7B E1
- 0x18ebb:$sqlite3text: 68 38 2A 90 C5
- 0x19003:$sqlite3text: 68 38 2A 90 C5
- 0x18ed2:$sqlite3blob: 68 53 D8 7F 8C
- 0x19025:$sqlite3blob: 68 53 D8 7F 8C
|
Process Memory Space: vbc.exe PID: 6088 | JoeSecurity_AntiVM_3 | Yara detected AntiVM_3 | Joe Security | |
Process Memory Space: vbc.exe PID: 6088 | Windows_Trojan_Formbook_1112e116 | unknown | unknown | - 0x7f789:$a1: 3C 30 50 4F 53 54 74 09 40
|
Process Memory Space: vbc.exe PID: 5776 | Windows_Trojan_Formbook_1112e116 | unknown | unknown | - 0xcb30e:$a1: 3C 30 50 4F 53 54 74 09 40
|
Process Memory Space: control.exe PID: 1272 | Windows_Trojan_Formbook_1112e116 | unknown | unknown | - 0x4e199:$a1: 3C 30 50 4F 53 54 74 09 40
- 0x1b1f24:$a1: 3C 30 50 4F 53 54 74 09 40
- 0x1b2fdd:$a1: 3C 30 50 4F 53 54 74 09 40
|
Click to see the 29 entries |