MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 07ad0c61940072d3f26c6706e550f970c2e3ee59d1b0a519515ebf16e013b11c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 15
| SHA256 hash: | 07ad0c61940072d3f26c6706e550f970c2e3ee59d1b0a519515ebf16e013b11c |
|---|---|
| SHA3-384 hash: | f82610a1a0b2c88766ef78c58032ffbdcadc5e3fdda1e8d6a024b9532f4857296026249068958ba545329c04d02739d0 |
| SHA1 hash: | ea9d1926a1955545174e5bd1596bd7abb37cbb65 |
| MD5 hash: | cb5e7f7ee2f99aab48b154b1db91174c |
| humanhash: | west-seventeen-football-wisconsin |
| File name: | Nova ordem de compra.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 719'360 bytes |
| First seen: | 2023-04-28 05:04:12 UTC |
| Last seen: | 2023-05-13 22:54:11 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'649 x AgentTesla, 19'461 x Formbook, 12'202 x SnakeKeylogger) |
| ssdeep | 12288:LmSvxezpdFjtgAoraUpDKMkLBcmwLumhw/Am595aos3:64xIg9q9KShz |
| Threatray | 2'771 similar samples on MalwareBazaar |
| TLSH | T1AFE4F53C59BDE22BD1B8C6A58FD18427F790A46F3115EEE5ACD643918326E1234C723E |
| TrID | 63.0% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 11.2% (.SCR) Windows screen saver (13097/50/3) 9.0% (.EXE) Win64 Executable (generic) (10523/12/4) 5.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 3.8% (.EXE) Win32 Executable (generic) (4505/5/1) |
| Reporter | |
| Tags: | ESP exe FormBook geo |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
f0eef09d45e8b0edf907f9fa6f9bd84a33327f62359fef4b92508a413d68c1b3
3ff8da989c0463e0eca88964ea38876e1b9e1e3dfe7cbab96297feadff54713b
f0ce6536bd8f80c0ee0ff1a246fd8447514906a38d4d24ec0d373c814180f9fb
319ed15753e7ce1ff182e1bd2e4900de9c76300f30cb645c01b57324de50face
c233b5359370a026201a1648489a3f1f91fd11cadb41e87ce45c60ea3a15f8f1
07ad0c61940072d3f26c6706e550f970c2e3ee59d1b0a519515ebf16e013b11c
c89bf6380445a49127491a4c68b77bc9ff8ba9b8fa016846ed6cc2274b6133d0
4dce4459e53e569a20c892efadb0424a4698bf5f67d16e7b73668dc2e172663e
3b0069e420ccfba9dff2e274d714fe3f62a6b9f3b5630e0fd28a89f579ebadcd
9c0a4fbfc6a9ee19747c3bd56699ad195ef95f65752476a208f7ef7fc2dd27f8
e30d41df0b3384eb57a607989bdfe40191b4e81df96327c1974f6d05a3a3d83f
880b7f96797851986e0dfb579afb707a7529f1adf9cce67efb7534d4003b8aa7
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.