MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 18bbddad825e2acd5d88e6b381680a4af565fca673142982f2a5376af238cd66. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 18
| SHA256 hash: | 18bbddad825e2acd5d88e6b381680a4af565fca673142982f2a5376af238cd66 |
|---|---|
| SHA3-384 hash: | 1e1a82b1cccd0e0d13b0ca592e0d551040b8a112bb8544d65a92f7e9a2e74f12a71dd8ba96a27b1f64072588bbd07f17 |
| SHA1 hash: | ec0e5cb20d383d8d6fadd015c321515b43f994a4 |
| MD5 hash: | e664e8839c15a5eff16c98786a99f10a |
| humanhash: | uranus-cold-apart-johnny |
| File name: | Tekopa-20230316pdf.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 271'253 bytes |
| First seen: | 2023-03-16 10:16:28 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 61259b55b8912888e90f516ca08dc514 (1'059 x Formbook, 741 x AgentTesla, 427 x GuLoader) |
| ssdeep | 6144:vYa6inBprMenatcJKCKrUO4Uh9xpQePKwLh3Dy5pi:vYkBBMfgOb9xp1ZDy5pi |
| Threatray | 2'463 similar samples on MalwareBazaar |
| TLSH | T1DF4412A4E6E1C1EBD5B74973493AA53207FBFC162039936B13B02E4FBC11A61E50E352 |
| TrID | 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 15.9% (.EXE) Win64 Executable (generic) (10523/12/4) 9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 7.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 6.8% (.EXE) Win32 Executable (generic) (4505/5/1) |
| File icon (PE): | |
| dhash icon | b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
DEVendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
e0917d732b7c34e4ff60f30a9115ad84dbf3eb15be3301db9bb7297f1ac8581c
91e3c02cea291854baf00afaa7da60840030fe2b29b1f27ecf4230b648c076d3
9fcf42a3b170c6bcdd328c0c7d33bfa5c867a68c2a32c7a5bf8bbed7c029dbd0
a1f1dfe6d2c7d5010bd2d3eef64f83695307f83e12f05aa89762113fd13a9456
dc8ac0ea14e9f418a35bd58f5f495282c9eb6a0e5331c197daf21f69f6d29222
b56c865c1aff92c4024b9f6172d349bf2355025a1d8baa74f8d33e930e86c2cf
18bbddad825e2acd5d88e6b381680a4af565fca673142982f2a5376af238cd66
60d85cc9cdf5ea1c43d698843974eb8ed2a5acb05443ab1a0d24e237438a5b7b
0a39d2df6fe76fbf2e89e43f5f0ed05a48670fdcdd40a8651b4d74c6983286f7
c976b524f9b32a66f198e4a462d62929a482c16ae458e6639da9b8e15306c5b0
06bae25e92bc3fac52c2c12ef0540fc44a3d254a7214fa5875b721c04a62b787
d1d12bba5e07ac4c4a896d6a15dd2e5cef59d70dfb0d2aeb61d51b0de5838213
b57fd7fbcf61b5c21dc101fe95bcd0d7a0a9ade3cdc75597b7352c3d70e00ba9
db29afaa6283ad55b4fc9abb4def3c06a8e445fc110b112408aabb3937432822
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | cobalt_strike_tmp01925d3f |
|---|---|
| Author: | The DFIR Report |
| Description: | files - file ~tmp01925d3f.exe |
| Reference: | https://thedfirreport.com |
| Rule name: | meth_get_eip |
|---|---|
| Author: | Willi Ballenthin |
| Rule name: | meth_stackstrings |
|---|---|
| Author: | Willi Ballenthin |
| Rule name: | shellcode |
|---|---|
| Author: | nex |
| Description: | Matched shellcode byte patterns |
| Rule name: | Windows_Trojan_Formbook |
|---|---|
| Author: | @malgamy12 |
| Rule name: | Windows_Trojan_Formbook_1112e116 |
|---|---|
| Author: | Elastic Security |
| Rule name: | win_formbook_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.formbook. |
| Rule name: | win_formbook_w0 |
|---|---|
| Author: | @malgamy12 |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.