MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 66b02d69d4eff510190fb38504be6dcf9f94d28f14b0569c7d1cd36bfb78983d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 11
| SHA256 hash: | 66b02d69d4eff510190fb38504be6dcf9f94d28f14b0569c7d1cd36bfb78983d |
|---|---|
| SHA3-384 hash: | 0d71eedd4d9f447576c7f1bf99271e3a8759edc9b90f9e12ad8b0e309f32d6bac8838bf3b82ec9c8a1bdc11765f29d0e |
| SHA1 hash: | a973eec6e0ead9558a5fba6193468a70bcdb1108 |
| MD5 hash: | d59f82dcd426fe19fa03336cbe13a6fe |
| humanhash: | four-east-east-zulu |
| File name: | INVOICE E-4137 REV.1 AND E-4136 REV.1.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 741'376 bytes |
| First seen: | 2021-06-21 05:02:54 UTC |
| Last seen: | 2021-06-21 05:52:16 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 12288:qGYXQWFHmssO2eB56c3fBKuXguhioKIlkzM/XHPSo2ZnOElHhU:qjTHuU6cPBKuQuYoKI2zwXHPJ2 |
| Threatray | 6'085 similar samples on MalwareBazaar |
| TLSH | 22F4BF3039AEA10DF577AF741AE436E29A6FBE637707D95C14D4234A8B23842CF41939 |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
a29d5d9dae6f9937c1f0dcf733031f3478d74f326c1913727eb9e65e53c82ab9
e47843b7ef3c9825c787ff7fae69cfbd4759a21e81da4e800746af5b7937c45b
8a403d5866d98e6da02683d365c982c0089b338f92d2e2fe7b5ae099dbaa635b
19f2101d500dfa2ba71baf220497fe8888667bb7d9c8cf4996087ff67c11d156
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.