MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 49fddee873c8d4843926a40baa7649b95621253722953f82f85a4e0ac0bfb26e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 22
| SHA256 hash: | 49fddee873c8d4843926a40baa7649b95621253722953f82f85a4e0ac0bfb26e |
|---|---|
| SHA3-384 hash: | 01de1afb498e211400b54eeafb5ad04c0908cdb3c2f2a2f22970ae581b920130e26682adeba60278ac7f02b5147663fc |
| SHA1 hash: | 81ad4ef4ee6ebd16b63613cbb66cbb90f07ce730 |
| MD5 hash: | 09a7a31b9228d0b3a14cb9c6cc77c71c |
| humanhash: | jersey-nineteen-kansas-finch |
| File name: | SWIFT_75,000EURO.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 579'072 bytes |
| First seen: | 2025-10-06 10:05:06 UTC |
| Last seen: | 2026-05-20 17:38:27 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'076 x AgentTesla, 20'040 x Formbook, 12'353 x SnakeKeylogger) |
| ssdeep | 12288:XC6F1wezQxjF959e9R3gul4DeTP8JcTSC6UNZdiFYA6Ru+Exdyhz+HwSBQ:S6sezQx59S33WeYlCT/OYAASdS+QSW |
| TLSH | T14FC41249152ECF22D5E29BF01A31C1B03771ADEEA924D7878EE12CDBB57A7801356B13 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10522/11/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
CHVendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
49fddee873c8d4843926a40baa7649b95621253722953f82f85a4e0ac0bfb26e
412a097d36135d1c09ef2e81f3fac61e43037670822ff0ddea3a553bb81d0f8f
ac9d39580d471e319f1d7d221e549a09185686902ce9e16e36a54d88e91be120
5492b0429b687f2c61aae539e2d4ed50d8cf47197a121d7e95e30336fc8a47d9
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | CP_AllMal_Detector |
|---|---|
| Author: | DiegoAnalytics |
| Description: | CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.