MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a39334c50e0ccb49d2ea85d615e2eef259a7232f36c4803c2d853b64639b6fa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 16


Intelligence 16 IOCs YARA 5 File information Comments

SHA256 hash: 7a39334c50e0ccb49d2ea85d615e2eef259a7232f36c4803c2d853b64639b6fa
SHA3-384 hash: 3c9773599d5660595144defae674e727a78016d3ae829a277f264e6b6660d2425a07b3f71b09dc9e6ee41c09dbdd09a8
SHA1 hash: e3b93e6c2a7964ab53cdb514f19a9489dc4383b2
MD5 hash: 4128b578cfee06b281d580844fd5872f
humanhash: white-red-comet-social
File name:swift909098878.exe
Download: download sample
Signature Formbook
File size:1'199'104 bytes
First seen:2026-07-24 12:16:15 UTC
Last seen:2026-07-24 12:39:45 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'125 x AgentTesla, 20'138 x Formbook, 12'362 x SnakeKeylogger)
ssdeep 24576:jV/Nfva3P3F9OlGRy/j4fpmir78fLnrdwgaoyHO:zfva3PjOlz/jCkiHQWH
TLSH T1794512602340E512D68467385AB0F3BA23F41DE9B801D342AFEDBDEFB926F114D58693
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon e09a981c04820182 (1 x PhantomStealer, 1 x njrat, 1 x Formbook)
Reporter TomU
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
3
# of downloads :
142
Origin country :
CH CH
Vendor Threat Intelligence
Malware family:
formbook
ID:
1
File name:
Quarantined Messages (17).zip
Verdict:
Malicious activity
Analysis date:
2026-07-14 14:02:05 UTC
Tags:
attachments attc-arch arch-exec formbook stealer xloader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Launching a process
Creating a file
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Adding an exclusion to Microsoft Defender
Unauthorized injection to a system process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
explorer formbook krypt lolbin packed vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-13T08:41:00Z UTC
Last seen:
2026-07-25T23:57:00Z UTC
Hits:
~100
Verdict:
inconclusive
YARA:
6 match(es)
Tags:
.Net Executable Html Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.30 Win 32 Exe x86
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2026-07-13 11:43:42 UTC
File Type:
PE (.Net Exe)
Extracted files:
10
AV detection:
27 of 36 (75.00%)
Threat level:
  2/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook adware collection discovery execution persistence rat spyware stealer trojan
Behaviour
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Adds Run key to start application
Checks computer location settings
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Family: Formbook
Formbook payload
Unpacked files
SH256 hash:
7a39334c50e0ccb49d2ea85d615e2eef259a7232f36c4803c2d853b64639b6fa
MD5 hash:
4128b578cfee06b281d580844fd5872f
SHA1 hash:
e3b93e6c2a7964ab53cdb514f19a9489dc4383b2
SH256 hash:
3a1f3580d425ccdbd81e9d2473311c65547514614a8c53ce91a95f96e245fbb5
MD5 hash:
6b754f8e2c67efe3dd493f46c1bf6047
SHA1 hash:
182cedef8b6d9e256d350f5a7bd1c682cb05be68
SH256 hash:
7a09d4c71af5d34d449fc0ba91c8993492828bc5d6a1a3300c3f27df63c56e28
MD5 hash:
acbdef84097e8e77e2fa56219b88e479
SHA1 hash:
1d0de023f006931d010e601ff392b6621279ddba
SH256 hash:
fdd8060c5ecafe3d2695a4f3b2f7dcbea2225067eddb20b75637f85d8b7d5fd9
MD5 hash:
38bd92442563adc10263245a2a9f8cf4
SHA1 hash:
a1f7bcfa40b7476dcdc3567ecd0d80ea3e7b2ca9
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:test_rule_vldslv

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe 7a39334c50e0ccb49d2ea85d615e2eef259a7232f36c4803c2d853b64639b6fa

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments