🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 17b4070f7739accf08ec200d8fe71a65f407afbca9f3f576f42397519f694d2d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 17


Intelligence 17 IOCs YARA 20 File information Comments

SHA256 hash: 17b4070f7739accf08ec200d8fe71a65f407afbca9f3f576f42397519f694d2d
SHA3-384 hash: 29f4c05de913012d8aab70ba81e0e93954aa89e702688adda11b676ea17d1eee4547c1e3d216c15d18164435af83a9ba
SHA1 hash: 8fe4eb8b899a696fbb88f56094dc25e876da2a66
MD5 hash: 19447dd51d52b27e5918d50d6782655a
humanhash: massachusetts-thirteen-echo-may
File name:17b4070f7739accf08ec200d8fe71a65f407afbca9f3f576f42397519f694d2d
Download: download sample
Signature Formbook
File size:1'251'328 bytes
First seen:2026-09-04 20:36:34 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'239 x AgentTesla, 20'493 x Formbook, 12'372 x SnakeKeylogger)
ssdeep 24576:I9OYpR9q2iB0l+X2jWwwTpIsQ18NSaJKOczu0wrym5:I9OSy08nwwTp0uApOb0wum
TLSH T1AF45CF9C3202FA6FC403A971C975DDF466106CA6D606C22794D73DBBBF3D9A68E041E2
TrID 70.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win64 Executable (generic) (6522/11/2)
4.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter adrian__luca
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
169
Origin country :
HU HU
Vendor Threat Intelligence
Malware configuration found for:
ConfuserEx RoboSki
Details
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-09-04 22:52:34 UTC
Tags:
netreactor

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a process with a hidden window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Blocking the Windows Defender launch
Adding an exclusion to Microsoft Defender
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
crypt entropy obfuscated obfuscated packed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-08-12T11:28:00Z UTC
Last seen:
2026-09-05T21:23:00Z UTC
Hits:
~1000
Verdict:
inconclusive
YARA:
12 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.86 Win 32 Exe x86
Threat name:
Win32.Trojan.Leonem
Status:
Malicious
First seen:
2026-08-13 23:00:00 UTC
File Type:
PE (.Net Exe)
Extracted files:
9
AV detection:
23 of 36 (63.89%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook discovery evasion execution rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Checks computer location settings
Command and Scripting Interpreter: PowerShell
Family: Formbook
Formbook payload
Modifies Windows Defender DisableAntiSpyware settings
Unpacked files
SH256 hash:
17b4070f7739accf08ec200d8fe71a65f407afbca9f3f576f42397519f694d2d
MD5 hash:
19447dd51d52b27e5918d50d6782655a
SHA1 hash:
8fe4eb8b899a696fbb88f56094dc25e876da2a66
SH256 hash:
76e498f6c3056812a6aa5dab98d61ce4f38fb688de62766a3d6b233f68a51f0b
MD5 hash:
68a9e112ca72295fa5caac73cc65232a
SHA1 hash:
36d946402d86bf9e2e06c58dca1afe57258e7b11
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24
Parent samples :
77a8fe21f54a964ccabd5567514aca90f5ab1b4f4c8def0d109d09cf9a969ac8
a33933b7d1b91190ee240484b5892f58159a9c3b70438ce8b41e42cde07ca02b
059ddcc503fe7484565b349b123b4e6b0438896dbeb0124b85f3ac504d8d67a0
10344c6e5ccd5c6d77b8c41c9b3c1b8df224add85659770ada88f6d0f6404334
87843d4d75d858a1802d545a80afbdf986d5aa3a30588c5094864f55d1ca8f53
845f66b5b5484651e5978daa62d0d227d433ad0c203f9711b099234381afa9d4
0e8021b43a43c8927aadebd29f5c04d0c6500d5f91f18f10e169695e7870c82c
70501144a459b9fdbc8b6e549fbc08db479b7d7aab4e02a352b3f11ba1ec686a
6951b6c8eaad2ba11fb84f2c34008f4dda63be5f9a9dab4ae5d6cff50d8266a3
d62e084a3f4770b1ad2bd13eda19d250b91b222ce6be8e6068ad40fbe28af8b0
03f46cf9a2de612f87385012e18af57a87e1d227f1fe2b0e8f6f335073104964
52740db0771ee580b17561fd4b62659d15a1c9195701f62eb105c2e542e6d3e4
23ec48eb6bd59bbfd84c8d05e14862d7bdf736af090de81ddd6dc29b7a0e7ef0
34074ad3ebee3c726922c815a5a1542ce7b2a5ff5a9233084f7a14d369882943
c86bbf6a553b5475bf6d67fa0874e45ce3bb78709e080cf26475c5d9220e6c4d
0c54067da7fef77b2dec7e57954542f3bea95d4e0c76483efd731e2a5754db73
1d41c3329320e5382a800ad08d5dc4559eebeec2eb7b2c204f56729e931e67a2
b59fe70e499dfd4f13fd545ec1892a10dd8a913ebc41190d69ecca2f4135c02f
1eb04dea7065dec90a181264f6538fc74e86a6ade162e8cd02c961c154ba0569
519de0a4ed8131067f6364e3ae9f010d962f897e50fbdc7479f1325947b68525
e3a438c31a0009e3e4a142437198e9a0da3541200efc437e957b73736b91842b
17b4070f7739accf08ec200d8fe71a65f407afbca9f3f576f42397519f694d2d
f989407c3464bf00b3eb103b08d10e2a71a570b423d510161e79acc4c93bc302
4b5ed2db4d4c48782e6926d8569f314f6aa36d8d6ec7100eaf1f561bd7626ff9
94acc5bde1e48ce426bc61ea90a8780cf2be98795aaba7d946d5fe9d43b3203d
853d90310e606ab389cdea5e8a5988737b701d872a5d9b67a051449a9c7266be
f86ac1d4c78f46aabb5e3d57f949fac4745bfecec1bcd639f1993186bc404cd7
315a48c4b71090772b808f0c4dfe0ecfac9b61909cb14986d465f326fb706c73
d31c9c8f715282a240f1f543230c752d5a76448519cb1d81567b127bc6f0fbaa
59dcfac1af40399add50aba8f2a941f1825a9968652aa414ef9728287f190e49
afb258344df84c835ea7449170ab9a4bad9233d7cdd34d7785636f996ccb3a6b
1ccf47d19e5181c626bf6ad2bad6e95051a3281e9234b3202906bbd8aadd79a4
ef4c15ae30a1d6a2d9c90058349b77c4609020d2d6f43b6fd2e9098b379bbdb5
f0638f4f18dcd0104dd3b8a151d2e17503ddfa254a22cbbebd451a3adbc52a0c
f7b25aaca2e51acd2360cd1ef3e5392d225f082b8412417b0a6507363799dbb8
1a3f93b8270ddc448662f04121eec66bdc1dfd7185dfa0c99b9ae7fa79d97b2b
d12b8749661abf45051dfffd0ef7b398ebcb414cfc66a03d2a40a08a3e157066
251ebe9abee9e3f8b668b4db14e4db7328062e2e0725531511843d00823c1d70
31a04a58a27fb44552e863df1aa8e5da68c043ca33f9619ab50a328ce6c83b60
70709ba747aa5f89277fbf2c80fd0c02975c57996cd11d323427e784faf53d68
b61e95706ad5eeb2ce5258f583e306d413a59510c970206434e41c5a8f46f4c9
b9464fc051e0bc72c0cb3d022126f9ed77252955f3a38211b34e4f2975d248a9
6bf7a8afe9831a929fdb074e089ba06ec36df02e5edc7751d0d4380baf689ae5
aab14e3152a99083841205667d41213155d61e64e734bf6ead723f3e702b14a6
SH256 hash:
e7c92c6c0c86b5a2fc15b341bcb964d5293b0f80ca3bf9a963936cefb1095fc2
MD5 hash:
5c9a1563bb3344ce3fc47be68efcb25b
SHA1 hash:
8a6d45ff20e447130e8c2f04c8b64b9f62d97cce
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24
SH256 hash:
d1b48252c49c9739a690f8ebb9767554a8dd19b15a05005e77e8ef4fe971cf9d
MD5 hash:
e5e1c0d0d8f90f380d75aaeedb3bd635
SHA1 hash:
be45f4538ad113685c946e2e0a2c8ef446ffa2b4
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__GlobalFlags
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Active
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:dgaagas
Author:Harshit
Description:Uses certutil.exe to download a file named test.txt
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:TH_Win_ETW_Bypass_2025_CYFARE
Author:CYFARE
Description:Windows ETW Bypass Detection Rule - 2025
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments