MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 4a66534fbea74b27fd7fa3262ac4d025d0f9108b20426b5cd7f8a1784affe2fd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 14
| SHA256 hash: | 4a66534fbea74b27fd7fa3262ac4d025d0f9108b20426b5cd7f8a1784affe2fd |
|---|---|
| SHA3-384 hash: | 20b0ebe93b1ebd814cf80d4a487334e043a8d5f64dfc6f8b37b83f020ada43af5a72a598b3f37075b8e80405d0334d85 |
| SHA1 hash: | 346c344c1d3eb89648f38aaea4edd57c8afad68e |
| MD5 hash: | 7952f513efc05bc3c76707a9091b978a |
| humanhash: | finch-burger-uniform-helium |
| File name: | 4a66534fbea74b27fd7fa3262ac4d025d0f9108b20426b5cd7f8a1784affe2fd |
| Download: | download sample |
| Signature | Formbook |
| File size: | 1'008'128 bytes |
| First seen: | 2026-09-10 10:40:55 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'233 x AgentTesla, 20'488 x Formbook, 12'372 x SnakeKeylogger) |
| ssdeep | 24576:4QgVa0MYepJvQfeL5Hg6UIbNOOJrFStXTvSzraVXpGPMg9oKOM4Mfu9:LNBTGeiwbYOvStDvSzra5eMg9oKgMf |
| TLSH | T1BD251215971DCF02E9EE87B70E5AF77003B16E9AB561E2258FED5CEB7A217025801283 |
| TrID | 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.6% (.EXE) Win64 Executable (generic) (6522/11/2) 4.5% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
HUVendor Threat Intelligence
Details
Result
Behaviour
Result
Behaviour
Unpacked files
6e482ca3bf3fcc53e4e91c43c50b1720a48090f3149fe7ff760c447a37c1ef04
cb0346cf3bf9665ec445b882981d5a1d05132601c7682051b234c2a391440750
a2ae20a3dae96a9c013499dda282f8b11a1c1a9758a001c3bedbb0b2184c6650
e5cfe69cb96d8fa21b39cb4a0dc60333fa7bacc7b452ebcd8acfbf58ef0625cf
2baf8b47911e361e0adc4834de3289f162ef118ac8c4cbcab98cb662746c6be3
7cf378dd9652caf18090ef97a17f93d4ec5bfd288b4493cc94d1039f1552f848
5d82d0ccc781b34d9a93164e0a7e723293755c21d6dd0fd23479f5f951d7014b
014d90b220ae7333d1811174a381cf9bce2befbc96f3ce66a3266b28aebcc652
4c67547dfe0e49d3735287dae9596b983bc82faa75363161197640c73fe2f902
4e13359697d315c3010c7d0747349146c428913d1b5bad117630102d1cbd5e2a
003e626ae5b7daa892d5d169f4be988ed47a6338c4f4610e7bf6e803a3972291
f4233e364c6d89eb9c342d7e1647dc0c87feba66b700fd1fff0d89bd5b4a398e
4a66534fbea74b27fd7fa3262ac4d025d0f9108b20426b5cd7f8a1784affe2fd
5690a8784a72840def954a1bfa1ecc493e47d7ff013801feba99a1f75c17f30c
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.