MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 64506ae267aed8afa5cfbb41ca8f5677600747f02fe27b8d8d926d12e3ad99f2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 14
| SHA256 hash: | 64506ae267aed8afa5cfbb41ca8f5677600747f02fe27b8d8d926d12e3ad99f2 |
|---|---|
| SHA3-384 hash: | 03ac26707287d6e8f46743264cf8216fe9715100826ccfaf0d3027acde552c077d9841f7259ec20e1c6470d52f8618e7 |
| SHA1 hash: | 06aebc4b151876e8c1c9e118f90e14aba11b284d |
| MD5 hash: | 596dc288e8914898b0be9d57a0e3d277 |
| humanhash: | alanine-white-venus-finch |
| File name: | NEW_FLF7997_SHIPMENT_DETAILpdf.com |
| Download: | download sample |
| Signature | Formbook |
| File size: | 855'040 bytes |
| First seen: | 2026-10-08 02:51:21 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/vnd.microsoft.portable-executable |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'249 x AgentTesla, 20'536 x Formbook, 12'383 x SnakeKeylogger) |
| ssdeep | 24576:bvCKX8jRLCOo0fQyrQVPwynhO0QE0Bfwh2y:bvCfjg30f9rQVBWto2y |
| TLSH | T12D05F114331ADC13E56257F00970E37197785ED4A461E3E3CEFBADEBB9A67806809683 |
| TrID | 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.6% (.EXE) Win64 Executable (generic) (6522/11/2) 4.5% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| dhash icon | f0e8e8e0f0b2e8e8 (1 x Formbook) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
CHVendor Threat Intelligence
Details
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
354ed74cf297bdc4d920e3bb357fea7202856277501cbe914b1dfbe8813e841c
7a9bffbf3a920d9b72d73b73cf09f3be5dadf025055f42b5dd12761ab7c8dd34
461ba9a7d6b344421967b3c71630ec4796126b5f20bef32111447ac58e9b9202
a36cbacd3c6950de6319523835e895e8b35e32549c3a4673b3ead5215ad0d3e8
a8a6f5ad5f6bc59b64af1cca3bf0d5b6bcc8686a0dd8a8bb5cb244c2edcf3e23
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | HUNT_NET_Loader_ImagePixel_To_AssemblyLoad |
|---|---|
| Author: | Anish Bogati |
| Description: | Hunting: .NET loader that reads pixel data from an embedded image, loads it as a .NET assembly, and runs it via reflection or late binding. Catches bitmap-steganography loaders. |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | WIN_Malware_Derialock_ForgeAuto_3127f957_Extrait |
|---|---|
| Author: | Marjoriefort |
| Description: | Detects Derialock (pe, etat extrait) |
| Rule name: | WIN_Malware_Unknown_ForgeAuto_6717780a_Extrait |
|---|---|
| Author: | Marjoriefort |
| Description: | Detects Unknown (pe, etat extrait) |
| Rule name: | WIN_Sample_Unique_69354b41 |
|---|---|
| Author: | Marjoriefort |
| Description: | Specimen unique (soumission Bazaar) - strings distinctifs propres au sample |
| Reference: | 69354b41e10daf03d3f3af881b32d5c0fec56b1cfe96629fd4c5263413a42854.exe |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.