SUSPICIOUS — 3ddce244c308f1ce27307b16467f29bd7f3e2333c535cb4a0c5d93a0b7296230.bin
SUSPICIOUS — 3ddce244c308f1ce27307b16467f29bd7f3e2333c535cb4a0c5d93a0b7296230.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (57/100), attributed to the Formbook family. 4 of 55 detection engines flagged it.
Identification
- SHA-256:
3ddce244c308f1ce27307b16467f29bd7f3e2333c535cb4a0c5d93a0b7296230 - SHA-1:
2d2dc3e2beb02d79d39c17c3388b51566f29edf2 - MD5:
f01afca27ee2c5d8779eed816bf8c91d - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
6144:MYd77T/BjuU/aTca6vBOCi2udXrdw7vdZury71AebVUDX:577TNZ/tBOr2ErdwZ57yebV0 - TLSH:
T11245239837057FA2D63F445C08825E1C9495317ECABA66CE988BB6CC2F5C547F4E4823 - Submitted as: 3ddce244c308f1ce27307b16467f29bd7f3e2333c535cb4a0c5d93a0b7296230.bin
- File type: pe · Size: 283648 bytes
- Verdict: suspicious (57/100) · Family: Formbook
Source: MalShare · first seen 2026-08-18T06:20:49.529Z · SHA-256 verified
Detections (4 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- Microsoft Defender: Trojan:Win32/FormBook.AFB!MTB
- Emsisoft (Emergency Kit): Trojan.Formbook.1358
- Kaspersky (KVRT): Trojan-Spy.Win32.Noon.bsqz
Why this verdict
The suspicious score of 57/100 is the fusion of 3 weighted signals:
- Contacted 25 external host(s) at runtime (23 HTTP) - network signal, weight 0.40, confidence 0.80
- Extracted Formbook config (0 C2) - engine signal, weight 0.45, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
93 behavior events · 0 ATT&CK techniques · 4 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- msedge.api.cdp.microsoft.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- 1f3e09080a0552204a89bc1ebb32fb58b798b0ee595a9c854ef757836f8dfc0e -
1f3e09080a0552204a89bc1ebb32fb58b798b0ee595a9c854ef757836f8dfc0e - 31e9705ddb62e7a7c6711c6fed7b3bb9ebab3bef5aaab799b1bd9e16cadcd529 -
31e9705ddb62e7a7c6711c6fed7b3bb9ebab3bef5aaab799b1bd9e16cadcd529 - 826b55af34ee0254ac017dc01decaaf619ca1e9c2cab4bf7e1e7c0cc667ed66d -
826b55af34ee0254ac017dc01decaaf619ca1e9c2cab4bf7e1e7c0cc667ed66d - b70577cc423bd1e8a4c8ef0552342fc9ad9ba3f94904d3bb032960479ab50d27 -
b70577cc423bd1e8a4c8ef0552342fc9ad9ba3f94904d3bb032960479ab50d27
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787650840&P2=404&P3=2&P4=BGgKKCY%2fs9Ui%2b4oPyQPzk1mVOAnELJ4RVDAXmjggLTnBM5u6phzGYrjE4cuivFUzMWfv3qDfpgvoVf67VKj4Fg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/45cd9142-6feb-4946-89e7-63e58fada30a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/45cd9142-6feb-4946-89e7-63e58fada30a?P1=1787650879&P2=404&P3=2&P4=kSaht53Eng4fJM22lviB5pICNdJdB835%2bauYE%2fP3qIdNOGo1uuh9SmQP1BDJPq7zIKXulPlBnuC7aMOTD%2fTm6A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 4.150.223.106
- 57.155.101.212
- 20.247.184.142
- 4.230.171.124
- 52.123.252.231
- 74.179.71.159
- 74.178.240.61
- 135.233.95.135
- 4.150.223.103
- 74.179.77.204
- 203.26.79.13
- 20.76.201.171
- 52.123.128.14
- 4.150.223.105
- 135.234.160.244
- 162.159.142.9
- 52.148.114.188
- 4.150.223.109
- 13.89.179.15
- 72.153.5.132
- 52.110.12.48
- 52.110.12.31
- 92.223.78.30
- 52.110.12.45
- 52.110.12.19
More Formbook samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report