MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 213002db79b1a5e11521190f9f11fcdda96e24ab0f382fff8b9f6347c618631d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 16
| SHA256 hash: | 213002db79b1a5e11521190f9f11fcdda96e24ab0f382fff8b9f6347c618631d |
|---|---|
| SHA3-384 hash: | 061c88864e282dd315825aee81c4052878ad91ab7b575ea936d7741020445a56777df89ae05a6d751a0955ba100b0709 |
| SHA1 hash: | 82fe58fe0fb90f17602d1d3327272a8ca6077d9e |
| MD5 hash: | d4d1bb1618993de77885cd13c7f592d2 |
| humanhash: | fillet-mississippi-pip-mockingbird |
| File name: | RFQ WD-PO-23-6894 - Petrofac Instructions at KSB_PMY-GEN-S-0000.1_Rev.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 306'856 bytes |
| First seen: | 2023-02-28 13:51:46 UTC |
| Last seen: | 2023-02-28 15:27:45 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 61259b55b8912888e90f516ca08dc514 (1'059 x Formbook, 741 x AgentTesla, 427 x GuLoader) |
| ssdeep | 6144:/Ya6Gez0uNEpyOc4FpwBENLZVO3kBhMBFyaU/OuN+aQP:/YYe4uWcOcowWNLW3o6BRyOuQZ |
| Threatray | 2'136 similar samples on MalwareBazaar |
| TLSH | T10864126121A8C9E3D69293303DB867791BF5EE2318399D4F57D42E0D7C603426A2F7B2 |
| TrID | 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 15.9% (.EXE) Win64 Executable (generic) (10523/12/4) 9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 7.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 6.8% (.EXE) Win32 Executable (generic) (4505/5/1) |
| File icon (PE): | |
| dhash icon | b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
213002db79b1a5e11521190f9f11fcdda96e24ab0f382fff8b9f6347c618631d
55c120bb50a6bf06059df09079156abe3e1ada2114e045a5ef56d2f747082995
f018a0aaa8f07136185382357b133ca8689530a8622fcccb3e2aefddf84842c4
182a18ad06cda267927c8475ad7938e688a2f43caebaec5a1dfb59c052fb8f8b
053a64ef6d5565a28e07e24ac18ceb52bda1a23db0ff0d328e5ce3ce597fd93a
7dbb1e7e87b226fcaac5105cc09754505ccc70a9585a09e6df5742e362f2ad90
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | azov_Dropped |
|---|---|
| Author: | Potatech |
| Description: | Azov Detection |
| Rule name: | crime_win32_ransom_avaddon_1 |
|---|---|
| Author: | @VK_Intel |
| Description: | Detects Avaddon ransomware |
| Reference: | https://twitter.com/VK_Intel/status/1300944441390370819 |
| Rule name: | meth_get_eip |
|---|---|
| Author: | Willi Ballenthin |
| Rule name: | meth_stackstrings |
|---|---|
| Author: | Willi Ballenthin |
| Rule name: | shellcode |
|---|---|
| Author: | nex |
| Description: | Matched shellcode byte patterns |
| Rule name: | Windows_Trojan_Formbook |
|---|---|
| Author: | @malgamy12 |
| Rule name: | Windows_Trojan_Formbook_1112e116 |
|---|---|
| Author: | Elastic Security |
| Rule name: | win_formbook_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.formbook. |
| Rule name: | win_formbook_w0 |
|---|---|
| Author: | @malgamy12 |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.