MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 1aac9a73533b5745a863e565e556ecc624619b3cecb917c9e8aee7b141976bb2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 14
| SHA256 hash: | 1aac9a73533b5745a863e565e556ecc624619b3cecb917c9e8aee7b141976bb2 |
|---|---|
| SHA3-384 hash: | 057f92df8a21becebabcc5ae0f5a911080b92badec5a1ae9ffb6cc0c8a48f6e45f3c6f6eec770720828e960b2e49baa4 |
| SHA1 hash: | 09d28ed373405e7ef3c62547bd5e4754ee497e01 |
| MD5 hash: | 902c93a42ab9f3f1fbe967eeb1c33831 |
| humanhash: | charlie-spring-jersey-carbon |
| File name: | PURCHASE ORDER.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 480'768 bytes |
| First seen: | 2021-11-20 11:17:05 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 12288:28ENXh660FkSmAP4flYnvo9YGZGmwobrccm6vBYk:jENkzECnw9YKGm |
| Threatray | 11'589 similar samples on MalwareBazaar |
| TLSH | T1D2A4DF8C3260B2EFC89BCD769DA45C60AA607877470BD343A09716DDAA4DAD7CF045E3 |
| Reporter | |
| Tags: | exe FormBook xloader |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
db0506781bb3416e90891191920292f5db74af4a2c388f92a0ed74d407b7c924
cae28876b4d13e974995f686d84fdb7e48b4eb583e76cdd53f393dc8921faa63
1aac9a73533b5745a863e565e556ecc624619b3cecb917c9e8aee7b141976bb2
a8c5b384b32f2a117fda2336ec2692bfc44e37a56327217454b63eb28ec0701b
8e405b6451c62462b5df1a0490175f4b9712ee1b1ab25a52f7e3a1f736400439
82d5d5ef76ff7a708df5ea9135cb18117428ad1cbdcaa938989a3559a6ff5b97
7346f558f4e3b55028c7d199dcfed4eb1eac0f81f7962e700ff82ba22c7c428f
864492d660b1978cc4b0ceb1008c334704d049cb77f98ddf8179660c7f2125cd
e7bfd7c73781e7cd0c6b73b00f5ca45abae5f134157c355e8684a936ec02a64f
d2b976a493c6d3b694dba0e139cea1d4943c0176a807109a9ab045a6b23b75c1
ce5ef050cbfe862b46edb70c1d3ee90b1fc3940ef93ee7fffe642589673d331b
dde5521f4b34414e6850fc869de027df46f3e4d5a1cb3cbb483c2900abe49c0d
6f7495ea749aac3582ea29a192a2c35e7c39194ae2d531f5452b2f27e5c2830a
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_SUSPICIOUS_Stomped_PECompilation_Timestamp_InTheFuture |
|---|---|
| Author: | ditekSHen |
| Description: | Detect executables with stomped PE compilation timestamp that is greater than local current time |
| Rule name: | pe_imphash |
|---|
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.