MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 875cbbf7f0bba4587075e250ed3eff8a71dca14ef835c8fe20d86fc1d30731d0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 15
| SHA256 hash: | 875cbbf7f0bba4587075e250ed3eff8a71dca14ef835c8fe20d86fc1d30731d0 |
|---|---|
| SHA3-384 hash: | f05fcd6be872ca062c2297de6538b7cdbed1088f0c89ad89fe16afb50bcf522e22fee48fc3bbc9cf405498efb3809149 |
| SHA1 hash: | 651e7c4e0cafa630913b1eec139a27dfcc03859e |
| MD5 hash: | 9ad4fc7be041b35881663f015277c011 |
| humanhash: | cardinal-bakerloo-river-india |
| File name: | 875cbbf7f0bba4587075e250ed3eff8a71dca14ef835c8fe20d86fc1d30731d0 |
| Download: | download sample |
| Signature | Formbook |
| File size: | 1'074'176 bytes |
| First seen: | 2026-09-04 20:19:16 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'218 x AgentTesla, 20'417 x Formbook, 12'370 x SnakeKeylogger) |
| ssdeep | 24576:oYSawfiZIRQojCvDGqO8qwINd9t8S/nCubR8kEpQSoS9MrI:oYSawqaCv6gtIpt/nCeEeDW |
| TLSH | T16B351224AB29E912D48653710676F7BA16744D9CF521C343AEFABCFB7875A1A7C083C0 |
| TrID | 72.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 6.5% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.4% (.EXE) Win64 Executable (generic) (6522/11/2) 4.4% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.EXE) Win16/32 Executable Delphi generic (2072/23) |
| Magika | pebin |
| dhash icon | f0d8d8c979f0d4f0 (4 x Formbook, 1 x AgentTesla) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
HUVendor Threat Intelligence
Details
Result
Behaviour
Result
Behaviour
Unpacked files
3c3f7642fc630e950f56417576a195dffe6ae556fcc4e1515014da4ac9e8a126
d7dcb1ff49dde80a00723de8c39a39a08a369d23c6d3167d45afb2f597a8376f
3c703ac22142ad4cbbef50be0acb299626d90e74aba4897d1943faea42f5993d
ffa4185c830b224ced767c5e8e2d0abbabb7e8aff9c544fecbcde4e73cce5937
382519802f7fbc808b168534ce2cab6eae2ac8c8725bc5c56e2cad087fd16605
a48a5576dffe0abd8dd33883fa903fb8c053626e8c21818db5e925d821c3ff4f
83e6b8db5fe7b1cfd7ace610a66dcb7e671f611e3755574b950a058b2541698b
5f10aa88783c63192e261cfc7f1281976844bb888f6427398807fb8de74a6294
875cbbf7f0bba4587075e250ed3eff8a71dca14ef835c8fe20d86fc1d30731d0
f48d95d60766961eb4f706868eb7e1ba7f43168cb977fe341b1cdeb50381353e
8e370b615f82d904e7d5238d51372f81fbc6f0ed56a9452cae774be372e6247e
a5350fb5b4e5a8dce705883533f71826d48cd3001cc423de68ad8e071f5a88ce
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.