MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 72c6697907363b49b380a98519bd1301562ed640b1d4d98f5a4bc08cddeb5ab7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 11
| SHA256 hash: | 72c6697907363b49b380a98519bd1301562ed640b1d4d98f5a4bc08cddeb5ab7 |
|---|---|
| SHA3-384 hash: | af7d61ffddd742dd3444b7a34f24454a608b49686494373d0ccd970b165c465e93d79d56ae77865c93a7f5af27682704 |
| SHA1 hash: | a965f3eb9f7dcf7fc3dd0920012ea92ba5d0b0bd |
| MD5 hash: | 5d795e196dd6a162a9316480acff2f6d |
| humanhash: | uniform-oven-texas-massachusetts |
| File name: | Urgent! confirmation of Invoicepayment.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 874'496 bytes |
| First seen: | 2021-06-30 13:08:21 UTC |
| Last seen: | 2021-06-30 13:52:31 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'657 x AgentTesla, 19'469 x Formbook, 12'208 x SnakeKeylogger) |
| ssdeep | 12288:ZQNFpw9v5gqopRY8cWovOI9j1Pu2bs0C0l1R53VKM2A5Eb+9NmCIB87FpGbLDYXl:2Axi/Y8cTTY05x3 |
| Threatray | 6'090 similar samples on MalwareBazaar |
| TLSH | 5B056CAC325475DEC467C6BACAA8AC74AA613C76431B8107909709DFAE0DB97DF101F3 |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
9e69822e8d8f6b6a0754129ac18a4dd50c7ddd352572fbee32f83eace5e868ae
2f149eeefba021804e56e884c6a0b9b20a0205104976741b9f7255ec60e4872f
2348867be2e6f27aa4cd8d07826357169e66667108b4784ae3144576e2e16377
97710e37b088b72c870ceb2a4c03a04625f800a83549ed4537dc64893fc33587
985c930f9f983d8ec93977335ebff73b477d7aaa678c163be58714525fb9f273
72c6697907363b49b380a98519bd1301562ed640b1d4d98f5a4bc08cddeb5ab7
5e9c90440f0d540744ddb95c83098baecf9c43111c4ac834eb62ef0cb749214b
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_SUSPICIOUS_Stomped_PECompilation_Timestamp_InTheFu |
|---|---|
| Author: | ditekSHen |
| Description: | Detect executables with stomped PE compilation timestamp that is greater than local current time |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.