MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 69785e004f3bf684c91c8f188058022933f954154f42d4dc41047be3713397ea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 15
| SHA256 hash: | 69785e004f3bf684c91c8f188058022933f954154f42d4dc41047be3713397ea |
|---|---|
| SHA3-384 hash: | 001af3b9d103736a9d7c9398633c20fc5c026159d8a000e7d469aaa303fe5d9cc68fc15e4131619bad734c6c2a6d3620 |
| SHA1 hash: | 6a5396e09daa0f2b1cfa176f3959bf6797bf2464 |
| MD5 hash: | a39ae766c3a35121c99d23a351fb7f9a |
| humanhash: | floor-pluto-missouri-twelve |
| File name: | SOA FOR RAC-098.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 321'045 bytes |
| First seen: | 2022-03-29 14:04:27 UTC |
| Last seen: | 2022-03-29 16:11:28 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 56a78d55f3f7af51443e58e0ce2fb5f6 (719 x GuLoader, 451 x Formbook, 295 x Loki) |
| ssdeep | 6144:GbE/HUXB0SzdeC/XNbTD+6ihA2PuNAbWxe0hkTkQx5VwmypVTcY:GbbuSzdeEZCnG4dvPSmyHoY |
| Threatray | 14'685 similar samples on MalwareBazaar |
| TLSH | T14B64010073619C27CC6E5A326875D279876B6D14EC611EF7EFB33E5A3D73A800A1D6A0 |
| File icon (PE): | |
| dhash icon | 8431f0ccccc42144 (1 x Formbook) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
04464b5872e342d59c8f4c85443fb3198a35544a9844d9a20618b7808f649464
d03f00ecce22cef615ed1cc86894e3b57dad4e78ef7a34af16f7479be9f84cf1
69785e004f3bf684c91c8f188058022933f954154f42d4dc41047be3713397ea
37b1b8d180f05d9be7c5a9821e9313993e5becaf03a5e46f4dc9711ad44ceaaf
7ecfcfe4b4c8d6f50a38131f50bb86329510a038d22abf1d556d45552b5c06cd
6f297bb4016558a90be2eacf5707f91010ae324f55ca20ec983c32c853389458
93147c02e1b23c567066353a89bf3ed2dcf0b1e7e2e1ee3c435cdd3b085d4f9b
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | malware_Formbook_strings |
|---|---|
| Author: | JPCERT/CC Incident Response Group |
| Description: | detect Formbook in memory |
| Reference: | internal research |
| Rule name: | win_formbook_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.formbook. |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.