MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 10333cfe3b8de037f163d4e80af8e1f18cd5ca7af555dbc9c1da5409925a079d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 16
| SHA256 hash: | 10333cfe3b8de037f163d4e80af8e1f18cd5ca7af555dbc9c1da5409925a079d |
|---|---|
| SHA3-384 hash: | 3f57198e2df541e87d8da7e67b51ebbe0b21fcc64026fa693c65ff63b80fa8c69d33032862c52010d2d41fb495e6586f |
| SHA1 hash: | 572b625b6f48b64ec15e038500c1d196f387e808 |
| MD5 hash: | ad6a7fe9c9d21c0f6d68b3d44f966150 |
| humanhash: | magnesium-four-hawaii-berlin |
| File name: | QUOTATION_2543_REQUEST_FORM.com |
| Download: | download sample |
| Signature | Formbook |
| File size: | 885'760 bytes |
| First seen: | 2026-10-06 04:28:27 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/vnd.microsoft.portable-executable |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'249 x AgentTesla, 20'535 x Formbook, 12'383 x SnakeKeylogger) |
| ssdeep | 12288:9Aoa3fikONrtry2VNX/tK4hSq8/W1fz795m8yDllVqlbc7n4P0:6HvifFy2Vp84GW1vS/VqJK |
| TLSH | T1BE158B04215BCA23C25526B0C9B2D2F90374DE54D932C36B5AEA7DBB7F35FF1A5402A2 |
| TrID | 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.6% (.EXE) Win64 Executable (generic) (6522/11/2) 4.5% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
CHVendor Threat Intelligence
Details
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
ac927aaf104545b1fa57b638a9ae8a7e1401b72095936bc8b36788fd2aa1c306
69a482c5823cd333423121c9eb9235d445467018d48a964b634ed4cf3754c37b
0761a56193a5ce6cc03b4fa36c77b80dcc43dd638c5232f32cae5eb2f5727ced
0926f6f79fcac8bc7e1e1e7027743a37662a1db79464fd24dc12c6c199ddee21
50de568b3bd5bdc9855aa047713706d77238e8e7c0bb3aae94123fb8456b2cb4
f103df0af6684dd4e14e698172bc510552053197b2aa2daa075679682ddaaf6d
10333cfe3b8de037f163d4e80af8e1f18cd5ca7af555dbc9c1da5409925a079d
9c374c3801bdcfa56b3c6c264ecb9e54acae6536b5ca77b9927abf76592457a4
fa1d013f5d8f4833ca5e80b1987ce0908625fab234048fe16e293d5ccbb963fa
17161ca9b95f7b2550a69cc0f2fce78ae93ae27869f6652fd54cbc2bbec68b38
2450fabd7c6ac77f8c79b9171f4a9f85faf200c46cf3390930847f677347abe6
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | HUNT_NET_Loader_ImagePixel_To_AssemblyLoad |
|---|---|
| Author: | Anish Bogati |
| Description: | Hunting: .NET loader that reads pixel data from an embedded image, loads it as a .NET assembly, and runs it via reflection or late binding. Catches bitmap-steganography loaders. |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | WIN_Malware_Derialock_ForgeAuto_3127f957_Extrait |
|---|---|
| Author: | Marjoriefort |
| Description: | Detects Derialock (pe, etat extrait) |
| Rule name: | WIN_Sample_Unique_69354b41 |
|---|---|
| Author: | Marjoriefort |
| Description: | Specimen unique (soumission Bazaar) - strings distinctifs propres au sample |
| Reference: | 69354b41e10daf03d3f3af881b32d5c0fec56b1cfe96629fd4c5263413a42854.exe |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.