MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 1d5c6a9f196dc3d9f2e483744d7b872f01a96b8320ce3ffdc66b66542cb7a899. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 18
| SHA256 hash: | 1d5c6a9f196dc3d9f2e483744d7b872f01a96b8320ce3ffdc66b66542cb7a899 |
|---|---|
| SHA3-384 hash: | 4f945388a5a2d04f4c5506aee8dc98bb373587814201985215f43d626b19df3fc41bce362a0a410169521c3ae0924fd6 |
| SHA1 hash: | 35edc921398ba4d5689e5bcced856c0f2d561c70 |
| MD5 hash: | cc0a03d130918f8d5c8d6b46833967b1 |
| humanhash: | ten-magazine-juliet-double |
| File name: | pago.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 602'112 bytes |
| First seen: | 2024-09-14 02:33:54 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'661 x AgentTesla, 19'474 x Formbook, 12'208 x SnakeKeylogger) |
| ssdeep | 12288:2aTdEMYimT/D37YF6oRZyWwJAA9X8gnd7/OKImE3hoTSO3XHL:CMo30pZxwJAA9X8Y/ohoTx37 |
| TLSH | T1D3D401B87778DA99D5E14BB80431D2764B3A7E4DF120D34A9FEA9CE778197012D00BA3 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | exe FormBook xloader |
Intelligence
File Origin
CLVendor Threat Intelligence
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
1d5c6a9f196dc3d9f2e483744d7b872f01a96b8320ce3ffdc66b66542cb7a899
0e95933b378d0fbe6e132bab051ab9a3ab4fa3332828e72a0133749c1150b79f
462338cc416f17bb48135254e384d49b87dde3f0c40e6c51a70ad7abdecfc231
bcdb8d2083ae1e7cdf5894bfcf411cdc5e39059971c545e7485544d55c391418
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
1f58d807c1dc6691d96359fc50f327d1
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.