MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 16bd868c6c2200864825de71892e8802f0f7f243f476dcd38e9d713bb0a5ee44. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 16
| SHA256 hash: | 16bd868c6c2200864825de71892e8802f0f7f243f476dcd38e9d713bb0a5ee44 |
|---|---|
| SHA3-384 hash: | cbf629a76b6302af03ccb7086ee21fc6e21000a1cdb104cedf5ec2f9d3aecd1bc1884640bd45f08912c81d3463d10234 |
| SHA1 hash: | 75c34ce60cdaf23110ea7a3c0fce158073408eb0 |
| MD5 hash: | e6195fd5e34ef77e3cb1bbd4595b671d |
| humanhash: | jersey-violet-eight-undress |
| File name: | 16bd868c6c2200864825de71892e8802f0f7f243f476dcd38e9d713bb0a5ee44 |
| Download: | download sample |
| Signature | Formbook |
| File size: | 858'112 bytes |
| First seen: | 2023-07-05 13:12:23 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 24576:rMgcKHlWxMiQW/O4ue7Tt0LCMSpwjpaCqufNFAhV6ji:VnlYMiQWmS7TQwwjpn/V2hui |
| Threatray | 3'341 similar samples on MalwareBazaar |
| TLSH | T11605F11862FADB1AE4BE7FFC0880917143F1525A7516E78A4ED374DA5E70F018F019AB |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4505/5/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| File icon (PE): | |
| dhash icon | e08c0f2322073bc0 (10 x AgentTesla, 6 x Formbook, 3 x SnakeKeylogger) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
HUVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
b81b5d7a927299cc54748988d70523c615e82e21482652510a1a95db89b3521d
9c3d5704da83029f78ee8cf532c746cd04834f5375a698f21c50040ade6c5a09
89dc8c98551c4f2b309fd2807b8bf1d24e1c2abd953930f95b5aa1987e0966f2
4baabf9e31ff1f2fec8fa4f3165d5456836c307591bf8840ec5a8074759fe742
2c4d743879afbbe0b4baa18e99e515a8b0586caf23308026e233c2031e69237c
16bd868c6c2200864825de71892e8802f0f7f243f476dcd38e9d713bb0a5ee44
581a4f34ba7db66e569d2d9135f8e73e089ed3bc4654c2e5099baf6854166021
324dcadf47a0c3085f54a7cfc51b512562ff907c953862e792356334b8fa74d8
b81b5d7a927299cc54748988d70523c615e82e21482652510a1a95db89b3521d
9c3d5704da83029f78ee8cf532c746cd04834f5375a698f21c50040ade6c5a09
89dc8c98551c4f2b309fd2807b8bf1d24e1c2abd953930f95b5aa1987e0966f2
4baabf9e31ff1f2fec8fa4f3165d5456836c307591bf8840ec5a8074759fe742
2c4d743879afbbe0b4baa18e99e515a8b0586caf23308026e233c2031e69237c
16bd868c6c2200864825de71892e8802f0f7f243f476dcd38e9d713bb0a5ee44
581a4f34ba7db66e569d2d9135f8e73e089ed3bc4654c2e5099baf6854166021
324dcadf47a0c3085f54a7cfc51b512562ff907c953862e792356334b8fa74d8
b81b5d7a927299cc54748988d70523c615e82e21482652510a1a95db89b3521d
9c3d5704da83029f78ee8cf532c746cd04834f5375a698f21c50040ade6c5a09
89dc8c98551c4f2b309fd2807b8bf1d24e1c2abd953930f95b5aa1987e0966f2
4baabf9e31ff1f2fec8fa4f3165d5456836c307591bf8840ec5a8074759fe742
2c4d743879afbbe0b4baa18e99e515a8b0586caf23308026e233c2031e69237c
16bd868c6c2200864825de71892e8802f0f7f243f476dcd38e9d713bb0a5ee44
581a4f34ba7db66e569d2d9135f8e73e089ed3bc4654c2e5099baf6854166021
324dcadf47a0c3085f54a7cfc51b512562ff907c953862e792356334b8fa74d8
b81b5d7a927299cc54748988d70523c615e82e21482652510a1a95db89b3521d
9c3d5704da83029f78ee8cf532c746cd04834f5375a698f21c50040ade6c5a09
89dc8c98551c4f2b309fd2807b8bf1d24e1c2abd953930f95b5aa1987e0966f2
4baabf9e31ff1f2fec8fa4f3165d5456836c307591bf8840ec5a8074759fe742
2c4d743879afbbe0b4baa18e99e515a8b0586caf23308026e233c2031e69237c
16bd868c6c2200864825de71892e8802f0f7f243f476dcd38e9d713bb0a5ee44
581a4f34ba7db66e569d2d9135f8e73e089ed3bc4654c2e5099baf6854166021
324dcadf47a0c3085f54a7cfc51b512562ff907c953862e792356334b8fa74d8
b81b5d7a927299cc54748988d70523c615e82e21482652510a1a95db89b3521d
9c3d5704da83029f78ee8cf532c746cd04834f5375a698f21c50040ade6c5a09
89dc8c98551c4f2b309fd2807b8bf1d24e1c2abd953930f95b5aa1987e0966f2
4baabf9e31ff1f2fec8fa4f3165d5456836c307591bf8840ec5a8074759fe742
2c4d743879afbbe0b4baa18e99e515a8b0586caf23308026e233c2031e69237c
16bd868c6c2200864825de71892e8802f0f7f243f476dcd38e9d713bb0a5ee44
581a4f34ba7db66e569d2d9135f8e73e089ed3bc4654c2e5099baf6854166021
324dcadf47a0c3085f54a7cfc51b512562ff907c953862e792356334b8fa74d8
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.