MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 1e5bcefeb25537b33aa42e005a5fa97a0293d8f2c5e94dd6f4bc8ae2288736a9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 17
| SHA256 hash: | 1e5bcefeb25537b33aa42e005a5fa97a0293d8f2c5e94dd6f4bc8ae2288736a9 |
|---|---|
| SHA3-384 hash: | d2ddcc92f5ca832d44ea9abdceb1923f3548898e32f46dd74a3989b6210571908e81c84aa5990d70517b7480aced2ce5 |
| SHA1 hash: | 53bcc2f8c5dffe685f94661644fdfe0aa10ec047 |
| MD5 hash: | 04b9e29546b1f4d7f73d4032b22fa1fb |
| humanhash: | black-iowa-aspen-bacon |
| File name: | QQ018252-1.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 1'324'032 bytes |
| First seen: | 2026-05-21 14:06:10 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 279daa640d9140f9842860a738abd363 (40 x Formbook, 8 x AgentTesla, 2 x CastleLoader) |
| ssdeep | 24576:/qDEvCTbMWu7rQYlBQcBiT6rprG8al89wXnIGjk0+PTyCKC0ea:/TvC/MTQYxsWR7alX006 |
| TLSH | T17355C0027391C062FFAB92334F5AF6115BBC69260123E61F13A81D79BE705B1563E7A3 |
| TrID | 29.5% (.EXE) Win64 Executable (generic) (6522/11/2) 22.8% (.EXE) Win16 NE executable (generic) (5038/12/1) 20.3% (.EXE) Win32 Executable (generic) (4504/4/1) 9.1% (.EXE) OS/2 Executable (generic) (2029/13) 9.0% (.EXE) Generic Win/DOS Executable (2002/3) |
| Magika | pebin |
| File icon (PE): | |
| dhash icon | aae2f3e38383b629 (2'697 x Formbook, 1'203 x CredentialFlusher, 928 x AgentTesla) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
CHVendor Threat Intelligence
Details
Result
Behaviour
Result
Behaviour
Unpacked files
916de120c4d2812634e1124697edf5bad6eebd8c863e55fec1603fdf5a3f8bf7
c90b07c5a8fc34bd981b78834dcf6822f48c81db37d3c4e078dbd77e64d6d03b
6e91e87caf50bb5082e3a47af60257d589180308263ec48f6d6d11d211b14565
de619620b09f8e87741e0b3976f0441e68223bce0fb5bf0484c433edb39dd362
a42b86a6e286e1f86fdfd5f60d42b7deac0eb1af0fb680950672ac1002ff1b97
572bac7bbc6f0698807db58bdd1004831a71bab2d53d0141cbe31dc853acae07
ec0abef5fb66cd68576c583e78297f1c1e270f66be5a04236b116d99b9ee5b0e
0854c21ed7648b1d45e780c75bf6dc9e72858c93caf2828ff5af718c21f63f13
1561ad922077feff2c52da3e2c2e514c0e8e897a49b3bf74237c53b86eb4e064
1e5bcefeb25537b33aa42e005a5fa97a0293d8f2c5e94dd6f4bc8ae2288736a9
2306569ae53954b8bee076cfb80432410510932168046b66920494c953b17aeb
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | AutoIT_Compiled |
|---|---|
| Author: | @bartblaze |
| Description: | Identifies compiled AutoIT script (as EXE). This rule by itself does NOT necessarily mean the detected file is malicious. |
| Rule name: | CP_Script_Inject_Detector |
|---|---|
| Author: | DiegoAnalytics |
| Description: | Detects attempts to inject code into another process across PE, ELF, Mach-O binaries |
| Rule name: | DebuggerCheck__API |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | golang_bin_JCorn_CSC846 |
|---|---|
| Author: | Justin Cornwell |
| Description: | CSC-846 Golang detection ruleset |
| Rule name: | pe_detect_tls_callbacks |
|---|
| Rule name: | shellcode |
|---|---|
| Author: | nex |
| Description: | Matched shellcode byte patterns |
| Rule name: | TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE |
|---|---|
| Author: | CYFARE |
| Description: | Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments |
| Reference: | https://cyfare.net/ |
| Rule name: | TH_Generic_MassHunt_Win_Malware_2025_CYFARE |
|---|---|
| Author: | CYFARE |
| Description: | Generic Windows malware mass-hunt rule - 2025 |
| Reference: | https://cyfare.net/ |
| Rule name: | VECT_Ransomware |
|---|---|
| Author: | Mustafa Bakhit |
| Description: | Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments. |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.