MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 511abcad3305adb02bb25c6595b07608ecd8d75532775ee18ed14daf646ac7eb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 15


Intelligence 15 IOCs YARA 5 File information Comments

SHA256 hash: 511abcad3305adb02bb25c6595b07608ecd8d75532775ee18ed14daf646ac7eb
SHA3-384 hash: 64aeb26f485267ddb1b793afa31cdc83803f5a1b9fe52a3e7b4faa0c22ff28dea4e271cb4117630ea319e2b486f9452c
SHA1 hash: c3cf21701572d20277f12d6c42cbabbb1b27bcb0
MD5 hash: 470bbf26ff7c8891376c910df8015ba7
humanhash: kilo-xray-four-november
File name:511abcad3305adb02bb25c6595b07608ecd8d75532775ee18ed14daf646ac7eb
Download: download sample
Signature Formbook
File size:1'158'144 bytes
First seen:2026-06-08 09:15:23 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'066 x AgentTesla, 20'010 x Formbook, 12'352 x SnakeKeylogger)
ssdeep 24576:Qxabt/r0phcJXOHCsdw0/heRmkqeliGDAQ4p1BaKKRzZ5:OaJzTJ+Fd1/heDliG14p1BtaV5
TLSH T11435E1D43A26E70ACD524A319935EEF116B40EACB501BAE38FDD7F5B74AC150AD0CB81
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter adrian__luca
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
HU HU
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
virus micro msil
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a process with a hidden window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Adding an exclusion to Microsoft Defender
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 krypt packed vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-06T03:40:00Z UTC
Last seen:
2026-06-05T00:35:00Z UTC
Hits:
~100
Gathering data
Threat name:
ByteCode-MSIL.Trojan.XWorm
Status:
Malicious
First seen:
2026-05-06 10:52:14 UTC
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook discovery execution rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Checks computer location settings
Command and Scripting Interpreter: PowerShell
Family: Formbook
Formbook payload
Unpacked files
SH256 hash:
511abcad3305adb02bb25c6595b07608ecd8d75532775ee18ed14daf646ac7eb
MD5 hash:
470bbf26ff7c8891376c910df8015ba7
SHA1 hash:
c3cf21701572d20277f12d6c42cbabbb1b27bcb0
SH256 hash:
4c0088d37a335fc5456e90037b60dedc59cea29d85263f1684962dab4836f551
MD5 hash:
93ef3263e9d363d36b729a43c1dbc658
SHA1 hash:
242a9e2ab4f61b28df881f78a2deead9e59f5957
SH256 hash:
c64b7706f0b2e4ae8cabc2d61ad34b7562710e22dbeba97bdfea2721391d70cb
MD5 hash:
cdad3d72599ff9e6576c252d7c3fedda
SHA1 hash:
63d0a28296495a432c6cf65c48f5032f7d1736ff
SH256 hash:
db281f8bacb34517358ff4311d79c7885ed869ccca9f9770e6da16b567fb3af1
MD5 hash:
c4eb368a6d4bceb5e12c70409e4d0881
SHA1 hash:
de3bf4fd51469d0c15bf7181119adbd01bcc6364
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments