MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 20cdcfc958897b318418dce7c7f6308e3481731f09fac0772d0fd27d4e66e528. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 15


Intelligence 15 IOCs YARA 29 File information Comments

SHA256 hash: 20cdcfc958897b318418dce7c7f6308e3481731f09fac0772d0fd27d4e66e528
SHA3-384 hash: 1ad8145a9d469347034c6f96dbf1a364e0c7948a83311bb11fe8028a3fefda46cb5d86acb61ea6f9a615278d535fde1c
SHA1 hash: 9a3b226cfa0779946211730a3b2099c0e02bb332
MD5 hash: 7ad4e09741ed2bee5735319598f78945
humanhash: kentucky-cola-nitrogen-item
File name:DHL_AWB#6078538091.exe
Download: download sample
Signature Formbook
File size:854'528 bytes
First seen:2026-08-03 11:22:09 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'192 x AgentTesla, 20'344 x Formbook, 12'365 x SnakeKeylogger)
ssdeep 12288:+sFXqBNPEKt10ka9f4/cMCayYP6GNZsQtgzpqjdvs+thwKObjslZuYy1Rl+H1I:+sCNOk+bMCayAldUMjdHhwLbjiuDf+
TLSH T13B05F04077BB2F56D27D93F1D652682063B6652F6124E70B0FE220E63E66BC489D0F93
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter TomU
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
CH CH
Vendor Threat Intelligence
Malware configuration found for:
DeepSea FormBook RoboSki
Details
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Launching a process
Adding an exclusion to Microsoft Defender
Unauthorized injection to a system process
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
masquerade obfuscated packed
Verdict:
Malicious
File Type:
exe x32
First seen:
2024-03-01T01:39:00Z UTC
Last seen:
2026-07-31T19:07:00Z UTC
Hits:
~10000
Verdict:
inconclusive
YARA:
10 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.39 Win 32 Exe x86
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2024-03-01 04:45:25 UTC
File Type:
PE (.Net Exe)
Extracted files:
1
AV detection:
25 of 36 (69.44%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
Formbook unc_loader_037
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook adware collection discovery execution rat spyware stealer trojan
Behaviour
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Checks computer location settings
Command and Scripting Interpreter: PowerShell
Family: Formbook
Formbook payload
Unpacked files
SH256 hash:
20cdcfc958897b318418dce7c7f6308e3481731f09fac0772d0fd27d4e66e528
MD5 hash:
7ad4e09741ed2bee5735319598f78945
SHA1 hash:
9a3b226cfa0779946211730a3b2099c0e02bb332
SH256 hash:
d4e9623277d53f4118c37e2957fc7cc2355b58ff45cd78489a5b06bf9bad2665
MD5 hash:
eac170b887631f6c40a1cb48aa625b1f
SHA1 hash:
02e8ab0307850aaf41a6af789c0611e82bb22a2b
SH256 hash:
95fb0011ca791fb15ac04b6912d300f460b97b4f34f34828133927e8b79faf67
MD5 hash:
a845e5310a24b6f606b267e085d275cb
SHA1 hash:
4480c495a2b1f6e88fd9acd3af0afcff5395a2cb
SH256 hash:
b29a70d730f184338c7a9e20867eaccab01394e984d144212e726055b0c1f1f8
MD5 hash:
2084521bda851981abcf5b7010e0ae5b
SHA1 hash:
68b6852e411b13f8f658ac4ddc3621cc2c6ffd53
SH256 hash:
4274bcec55cad35d52daffe54a07c0b3c330bdd898f111cbbc596ce1dc19f6b1
MD5 hash:
cca99e48fc61fa1f894a65f69a843ec0
SHA1 hash:
bd84254c1d0e04d5b5e94e9ca0777bf943254928
SH256 hash:
bf6510a4e8362b5a59aeaf48825b205990faf5133ab22a38d402961826af9b76
MD5 hash:
d576188a4b57fbe1053ea7493d249260
SHA1 hash:
e8bc9477c4fd2dd1e4400edd4043ca6bf6ca3f18
SH256 hash:
bf120163192ff5c11c38a442fcb67c729fadbc9d7ad403aa6b24ad96bcf3c6fc
MD5 hash:
a8df38d63d24bb5c50210c3e38e041e8
SHA1 hash:
f0ffb98cff345d3acf0e32ad63ee33630f8f9c14
SH256 hash:
a1641e650531f49b704a7097303941766fbbbc355e96d9a38d37ee59fcfbf803
MD5 hash:
503070be34bb3b7304901df0c718a291
SHA1 hash:
1bfcaebc578fc50415b9c56e254cf7a412bd12d8
SH256 hash:
579b472056397fd592d04da2a052dd0e05c650776815acbaa21d17396d3de662
MD5 hash:
7d5a3037583b65de4cb31ab4b17d444a
SHA1 hash:
8eef1505aa6cfe71b9d4cbd5f02965fc29ffb7aa
SH256 hash:
72638f4b30cc9dab51d31216991957bf1cd118b8a8743227b3e8f9c4805f7628
MD5 hash:
2a8240bba06e832ee5d136a0a7e5b5b9
SHA1 hash:
de49d9b33004a4a622a4279b3ee2b3e3e5cd012b
SH256 hash:
b3f2bcb08ae6ed77b51186dc73ac27afc31c9e3b175914fbc7e932a053024057
MD5 hash:
8edcf081ada9f28a2722afb40ac6e099
SHA1 hash:
9a1d6568a6063fccac7eef51a12cbdaa81b82262
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__GlobalFlags
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Active
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Formbook
Author:kevoreilly
Description:Formbook Payload
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:maldoc_getEIP_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:Windows_Trojan_Formbook
Author:@malgamy12
Rule name:Windows_Trojan_Formbook_1112e116
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/formbook-adopts-cab-less-approach
Rule name:win_formbook_w0
Author:@malgamy12

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe 20cdcfc958897b318418dce7c7f6308e3481731f09fac0772d0fd27d4e66e528

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments