🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 210c94d2fc3ffd7cb7ee6e51c78c9a85f49cd213cb0a24e79f8976f284beea49. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 15


Intelligence 15 IOCs YARA 4 File information Comments

SHA256 hash: 210c94d2fc3ffd7cb7ee6e51c78c9a85f49cd213cb0a24e79f8976f284beea49
SHA3-384 hash: 0b01bb016983a808bd06f5761f1aa701bb3a78ed7f47d019c43c91632bf73b1c69ac296c06f19b1e152b39057ce704c9
SHA1 hash: 2f2356b0856da11245aaa34acfd34c1e8c3f8cb8
MD5 hash: 67cfe6d11110f707c0ab1db18df76cfb
humanhash: cold-delta-papa-asparagus
File name:210c94d2fc3ffd7cb7ee6e51c78c9a85f49cd213cb0a24e79f8976f284beea49
Download: download sample
Signature Formbook
File size:1'046'528 bytes
First seen:2026-09-10 11:17:53 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'249 x AgentTesla, 20'539 x Formbook, 12'385 x SnakeKeylogger)
ssdeep 24576:Ko+O17aRVhU4o/MIuxAKe8NNfk5M9zpsXiwPKO+H:Km1mRs/TWAKe8TTHMPy
TLSH T1FE2512657319EA01CA7A1BFA4AB5E3391BB24E8FE431E31B8DDD8DDB38507026C45943
TrID 72.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.5% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.4% (.EXE) Win64 Executable (generic) (6522/11/2)
4.4% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.EXE) Win16/32 Executable Delphi generic (2072/23)
Magika pebin
Reporter adrian__luca
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
116
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-09-10 14:21:32 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
packed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-08-27T06:31:00Z UTC
Last seen:
2026-09-11T10:16:00Z UTC
Hits:
~100
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.44 Win 32 Exe x86
Threat name:
Win32.Trojan.NegaStealer
Status:
Malicious
First seen:
2026-09-06 05:41:00 UTC
File Type:
PE (.Net Exe)
Extracted files:
4
AV detection:
18 of 23 (78.26%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook discovery rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
System Location Discovery: System Language Discovery
SmartAssembly .NET packer
Suspicious use of SetThreadContext
Family: Formbook
Formbook payload
Unpacked files
SH256 hash:
210c94d2fc3ffd7cb7ee6e51c78c9a85f49cd213cb0a24e79f8976f284beea49
MD5 hash:
67cfe6d11110f707c0ab1db18df76cfb
SHA1 hash:
2f2356b0856da11245aaa34acfd34c1e8c3f8cb8
SH256 hash:
dc1c6cffffaa815d1ba5f7b55339e0977933e0b36704ce7a477b13fb34f3838d
MD5 hash:
45258ea367a3385feafdb038ff58d7de
SHA1 hash:
05d2562181b927755dfc1fcfa689519660d61fbc
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24
SH256 hash:
2b0a3e1c220e8a98eb358a391da117b853882e411df4c9bbf54acc7ae629061f
MD5 hash:
38181717c94e497221567b84b23a75d0
SHA1 hash:
48332b950e1ee5fb10c3ee5eb8705e01e603edda
Detections:
INDICATOR_EXE_Packed_SmartAssembly
SH256 hash:
77773802174eb237f819f765ec522bffaff01225a68be1857116cfeb0c1704bb
MD5 hash:
37ff0139d5929450c9d8c0cdbde2ca7b
SHA1 hash:
cbf41319b331bb912cc6317a0d6c227f8317d228
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments