MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3d6bae246cd5b26065ebc3259bc955c5be5410e0313a9ae5c31fbe680bbb6798. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 10


Intelligence 10 IOCs YARA 6 File information Comments

SHA256 hash: 3d6bae246cd5b26065ebc3259bc955c5be5410e0313a9ae5c31fbe680bbb6798
SHA3-384 hash: 9f60a6424a4bfb11138df5a6c25835b6e8cd2f012253723ef03d7d3d292465b3701f6ca372fb0f51f4aa75f58fa1e5ee
SHA1 hash: 62ff201f0f1dd265a33b9793a980fdc067fa2670
MD5 hash: 20112908bc6ae179949343f72b27a55f
humanhash: quiet-oxygen-jupiter-finch
File name:JJCSHKRY600_NOA.zip
Download: download sample
Signature Formbook
File size:957'459 bytes
First seen:2026-07-03 17:54:16 UTC
Last seen:2026-07-03 17:56:13 UTC
File type: zip
MIME type:application/zip
ssdeep 24576:pHARdacQUrf0iTTTaa/qV0F+EQbcQENAY1MJ5Nri:pHARdacQUb0iN/qKqbpENAY1MJ5NG
TLSH T1481533C402A97A7B9E56344EF603FDE9F5543B895A5C936E34D23E96CCB539340C430A
Magika zip
Reporter TomU
Tags:FormBook zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
81
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:JJCSHKRY600_NOA.pif
File size:1'030'656 bytes
SHA256 hash: a73cd72f82f334e31d4669d43ec819a033c3f088dc96f5fc21002941ace6b61e
MD5 hash: 91b84b14b1e6d72dc63caf997a338c87
MIME type:application/x-dosexec
Signature Formbook
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
virus shell msil
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
net_reactor obfuscated packed packed
Verdict:
Malicious
File Type:
zip
First seen:
2026-06-18T06:32:00Z UTC
Last seen:
2026-06-18T06:45:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Leonem
Status:
Malicious
First seen:
2026-06-18 11:03:02 UTC
File Type:
Binary (Archive)
Extracted files:
11
AV detection:
16 of 23 (69.57%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 3d6bae246cd5b26065ebc3259bc955c5be5410e0313a9ae5c31fbe680bbb6798

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments