MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6f4ef07076ebad36eea92eeaeb42b91bdf910d4e93bc0bf6b4fc40e6d191ed83. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 17


Intelligence 17 IOCs YARA 8 File information Comments

SHA256 hash: 6f4ef07076ebad36eea92eeaeb42b91bdf910d4e93bc0bf6b4fc40e6d191ed83
SHA3-384 hash: 27ba373f19ad656a5f73787c79378d6450e89cdb873e6eeb9a341f1aa628c112c109b8853e7d1c6ab8b704fa9af63f22
SHA1 hash: e5a7b7eb96343d506ab16b17868d281cc0d9188b
MD5 hash: 1e07f9e0e115b0d56b8c051c9e38563e
humanhash: oregon-mexico-three-saturn
File name:Novi upit #876567-AWB.exe
Download: download sample
Signature Formbook
File size:651'784 bytes
First seen:2024-08-11 07:02:31 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'122 x AgentTesla, 20'134 x Formbook, 12'360 x SnakeKeylogger)
ssdeep 12288:NRzAiSeURm5WoixfKTYZAOqjygs3+ER4X0VgdOeHH51zo1sSzKihJgAjkR:NRzAOUemxSUZAyZDFiz611gA2
Threatray 3'326 similar samples on MalwareBazaar
TLSH T128D4235BE7448F49C9DE5BBF53F745014B3292530AA9DF0B25D088C86EC17A82A5FB83
TrID 60.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.8% (.SCR) Windows screen saver (13097/50/3)
8.7% (.EXE) Win64 Executable (generic) (10523/12/4)
5.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
File icon (PE):PE icon
dhash icon 589898801666e6e4 (6 x AgentTesla, 5 x Formbook, 1 x AsyncRAT)
Reporter abuse_ch
Tags:exe FormBook