MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7b3b5d14375e2c12836e28bb0d9b277a1207e286f8b0386acec60fe2dced747c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 15


Intelligence 15 IOCs YARA 5 File information Comments

SHA256 hash: 7b3b5d14375e2c12836e28bb0d9b277a1207e286f8b0386acec60fe2dced747c
SHA3-384 hash: 202b574b2d26717dafc5cf011cf514c70ddba1e3253001e562dd4e2d8f31cde118e07b1fc3842e04c99d4c0bb7e701d3
SHA1 hash: 6c4373a45f50437b2552f9e6f6239e3cc0707e63
MD5 hash: b4fdee1d0631824ae370ff694468156b
humanhash: hot-quebec-johnny-tennis
File name:7b3b5d14375e2c12836e28bb0d9b277a1207e286f8b0386acec60fe2dced747c
Download: download sample
Signature Formbook
File size:907'776 bytes
First seen:2026-08-10 14:33:24 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'190 x AgentTesla, 20'337 x Formbook, 12'364 x SnakeKeylogger)
ssdeep 24576:HO+L/j/Og3njP5pKH3JIQWS2BT9tXmHQWNUbxsyY:HO+LrPTrKHyQWtPBdVGy
TLSH T1B01522B27369DF19D2B607F44AB6D135A3B67E8DE431D3010ED9ACEB3119B1149183A3
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter adrian__luca
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
HU HU
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Launching a process
Creating a file
Launching cmd.exe command interpreter
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Unauthorized injection to a system process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
entropy krypt packed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-20T12:21:00Z UTC
Last seen:
2026-08-10T10:26:00Z UTC
Hits:
~100
Gathering data
Threat name:
ByteCode-MSIL.Backdoor.FormBook
Status:
Malicious
First seen:
2026-07-22 01:27:00 UTC
File Type:
PE (.Net Exe)
Extracted files:
8
AV detection:
25 of 36 (69.44%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook campaign:ufgh discovery execution persistence rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
SmartAssembly .NET packer
Suspicious use of SetThreadContext
Adds Run key to start application
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Formbook payload
Family: Formbook
Unpacked files
SH256 hash:
7b3b5d14375e2c12836e28bb0d9b277a1207e286f8b0386acec60fe2dced747c
MD5 hash:
b4fdee1d0631824ae370ff694468156b
SHA1 hash:
6c4373a45f50437b2552f9e6f6239e3cc0707e63
SH256 hash:
01ff3e706f0f3928207b5e020eebb9ed38428dfbbf0f8c46aeec328b73519160
MD5 hash:
bbb0d2ca9a21d5a1f6c9059e108ea3ee
SHA1 hash:
5accd45f4a70a26b6ce07e04cc3820e99187a818
SH256 hash:
89b4db829c9223079102f2001f1d9d206fabcf1d5289f7c409af321dc11157ec
MD5 hash:
5b5f9b47ae9247d91a8f00f88fabe3c6
SHA1 hash:
882980da338341f4bc7c4cad107dd47392f1d640
SH256 hash:
8f250946a529285834bb4a8d8d19bccf8535fdf209e809a4fecf4aaf53d61723
MD5 hash:
7db9a7bde6682804d5ab576bfe6cc138
SHA1 hash:
cba298daa42ccffed84dc70c1df79575c9f6255c
Detections:
win_formbook_w0 win_formbook_g0 win_formbook_auto FormBook
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments