MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 6c8b4de0f39caa11127409b3ee06f410b0c5642b840f10822ad40af5745690cb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 12
| SHA256 hash: | 6c8b4de0f39caa11127409b3ee06f410b0c5642b840f10822ad40af5745690cb |
|---|---|
| SHA3-384 hash: | 19ce5c11ab3505206c23fe89e4633b577dd211a0c331f5e94f5d8da3a49af6b8e9743d40eefe410a30d8ae1637a89cc2 |
| SHA1 hash: | a9f88d989ddadac7292c97ceff83fbad1933c9db |
| MD5 hash: | ebbe664e3b011a22a7a60006a1a13124 |
| humanhash: | north-spaghetti-cat-leopard |
| File name: | 20210618-0089199199.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 253'351 bytes |
| First seen: | 2021-06-19 13:49:49 UTC |
| Last seen: | 2021-06-19 14:34:26 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | b76363e9cb88bf9390860da8e50999d2 (464 x Formbook, 184 x AgentTesla, 122 x SnakeKeylogger) |
| ssdeep | 6144:TBlL/1CpmxnLAbGRnRlicoss2oMNA8rBGRNhThZmaX:Fzz4GFRfs2oMBcvhbmS |
| Threatray | 5'909 similar samples on MalwareBazaar |
| TLSH | B84402F221F048ABC56717B218B7D77ED3B99D195914A05F03D4FEB631322C3A12B26A |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
4d2ca668cdde851a6389ee4d0fb089d3e125e2d951dbd7201767174ecafa66ad
6c8b4de0f39caa11127409b3ee06f410b0c5642b840f10822ad40af5745690cb
66e06710b095c687448e0b08240a99f84dfbfc24882a2c8c9f5b165f58469d8f
031af74c61339ca40eda7563268d9e2e2803064c141d3c46eb20acad3764f4cc
5043b6f2fb2b01edaf96f2ed748a59957da044dd826bbc3070b5d8c60252b33d
ce1c500cc108ae09a1a19f0171e5af77d090669ee75ab3835cc64d888d837db9
8ca372bae777f7250c22113f1312b38955555f48c0b1ed2aaf0c9326abe06001
50ef55dfb72ff4f84955243ea50f9fecbadbe9c4fb9cbe3078771e949b2ab589
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_SUSPICIOUS_Stomped_PECompilation_Timestamp_InTheFu |
|---|---|
| Author: | ditekSHen |
| Description: | Detect executables with stomped PE compilation timestamp that is greater than local current time |
| Rule name: | INDICATOR_SUSPICIOUS_Stomped_PECompilation_Timestamp_InTheFuture |
|---|---|
| Author: | ditekSHen |
| Description: | Detect executables with stomped PE compilation timestamp that is greater than local current time |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.hXXp://www.renaultstoreiran.com/wz6a/
hXXp://www.nomoreink.com/wz6a/
hXXp://www.lkstau.com/wz6a/
hXXp://www.valsinvoguenails.com/wz6a/
www.8146confluencept.com
www.lsxwsj.com
www.setuseny.site
www.whjmglj.com