MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 043b45f9d94820186d7324c5f6e0fd7661de15ad29104fd43294e2f3839efa06. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 11
| SHA256 hash: | 043b45f9d94820186d7324c5f6e0fd7661de15ad29104fd43294e2f3839efa06 |
|---|---|
| SHA3-384 hash: | fcffde474609e83a1d14c3f70ae4429a624972da012442f2fd1e12ab3bf8bfe5f79f9211179bee3f8bb5e4939425973c |
| SHA1 hash: | 426ff70d8bc93dfda31e849156e1c1e6c758d371 |
| MD5 hash: | 026028926f83ef1d31d0f170210c14f8 |
| humanhash: | colorado-illinois-orange-green |
| File name: | 026028926f83ef1d31d0f170210c14f8.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 854'528 bytes |
| First seen: | 2021-09-27 08:29:56 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'647 x AgentTesla, 19'449 x Formbook, 12'201 x SnakeKeylogger) |
| ssdeep | 24576:kMIFPQSclITZyApce48FIGxALQF+N6+3:kMIFPdM6koX4soQE |
| Threatray | 9'642 similar samples on MalwareBazaar |
| TLSH | T19105BF19A2AC9B4EC5BF83FAB00350181777ED8B3E0DD6059EC231E81E75BB14A565CB |
| File icon (PE): | |
| dhash icon | 00868ecccce8cc10 (13 x AgentTesla, 9 x Formbook, 2 x NanoCore) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
4c5887639c1dfcc0349690d98e9c8034029a6fa2f2e6bdbba96371bf23ce3301
2ac830fd4c5c4c3522b5cb9983edc13f2580b932875bc9daeb02633b8829fb3b
043b45f9d94820186d7324c5f6e0fd7661de15ad29104fd43294e2f3839efa06
92c90d735148f7fd056e2d53bf44239f3fdab6b029e78d3ed6077d9c7f40aef2
c7ea020c54d4ce9a629d57feb15e38fac8457b14221386111ef022735e375d13
5be742e9644f86ef1d407e5b3e85dff6211561e6dbf9c9fc85b0c5289b899979
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.