MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 94509d1a6070cfbaeeee0e3de30bf14dce5f4b28bfeef4ab3cf9bedbd0a07dd1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 14
| SHA256 hash: | 94509d1a6070cfbaeeee0e3de30bf14dce5f4b28bfeef4ab3cf9bedbd0a07dd1 |
|---|---|
| SHA3-384 hash: | 8032b5415b121e84aefa27d3a80623fde3a6e417fc3cf1294e8d17e27802fdb7b7a78111ca497afebdb16c3d644a64ec |
| SHA1 hash: | 6a0290c82cb922e60e949b7f52e9c9fe031433f1 |
| MD5 hash: | 4b13c07a48e57799e54f6e38e34ff6be |
| humanhash: | chicken-island-yankee-london |
| File name: | Invoice.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 278'696 bytes |
| First seen: | 2023-07-20 10:00:31 UTC |
| Last seen: | 2023-07-20 10:37:15 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 61259b55b8912888e90f516ca08dc514 (1'059 x Formbook, 741 x AgentTesla, 427 x GuLoader) |
| ssdeep | 6144:/Ya6xeXPYBCWD04uosQ3v4nDR/dxo0u4pSDZJhFlrUdGv:/YbefYQ6eBQfMR/no4m/HKd4 |
| Threatray | 3'345 similar samples on MalwareBazaar |
| TLSH | T11B5412002AD4D86BE4565B319FF66B36E9F2910925A4C70F1B90DFC578B2AA1E70F313 |
| TrID | 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 15.9% (.EXE) Win64 Executable (generic) (10523/12/4) 9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 7.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 6.8% (.EXE) Win32 Executable (generic) (4505/5/1) |
| File icon (PE): | |
| dhash icon | b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
DEVendor Threat Intelligence
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
572e8b2c173dc361f25400cbbba7a980cea2dcdf91e1245902f31d05387cec1f
fd4e8f61142ea384a48b69dd3b5d3b081680c3e7c6508bb5ba3cf646b813ad45
2b4b15b5d5d397385ff0c94694b64f604a284fabcf60b227356ece67a5b64ee7
0090f5c3f38d949a7c6c9d165e822cc82ad48bba628c7e9776567002ad4f67db
25d490e5ecd01bf73186267d8636482ee4f1f3012e64f214268cee4748cb5369
3ee58f59d9f63943f9b78d31c503027f416c7f5cb4ed606768c4c8767133c854
a164652a4336afd460b41b4b744547c5f7999e35ae5b8ccf1abbc6bb2d2c5a32
3931d6780f87facdf721f6e730ec38738afe7bb5378247824a1374802e2d04af
b9cf0848d2bba746fab74aae513f2b9815a1bb134e198e99c12d280568b1210a
459e929fa858fe59c50dc6887ce7fa9a79f13719dc5c759aa069559d2956e6c8
94509d1a6070cfbaeeee0e3de30bf14dce5f4b28bfeef4ab3cf9bedbd0a07dd1
7f16701eeca94cea23e593f41578c9e1d919a18d5b67c72537df507ebbba9267
c79762f99daabb3053394d3b98d951a346c1aeb957606fde0040d3905aca3dfa
5d95b52efcb12349fe0a0734622162be408c34b0b970239e3dd374bb47b133ac
9292d7b24e619b853df2eefe4a41acee5fd6e7af72a42baf497bfa1d17154629
8e16e5a2e8da8e98b9caa9c492cd7fa65c4845102a8687309c4b40a921c91f11
3a99f6960db39c701811edf0ec230f829ac336e829c551f8b849c997e334188a
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | meth_get_eip |
|---|---|
| Author: | Willi Ballenthin |
| Rule name: | shellcode |
|---|---|
| Author: | nex |
| Description: | Matched shellcode byte patterns |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.