MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 9dc2a5da6e549eff0358485278342915ecec6ef3d666a1234e6595163cbc6f60. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 15
| SHA256 hash: | 9dc2a5da6e549eff0358485278342915ecec6ef3d666a1234e6595163cbc6f60 |
|---|---|
| SHA3-384 hash: | b14d983112f117acafce9c5ed7a0de82db25392a6c61bca6da492b175ba6e83c23c58be262884f874ba878672c450edc |
| SHA1 hash: | af129a3502b1cbf5676059ac20d86854ad772c97 |
| MD5 hash: | 6addf4842ae23a4f6568794c23751ac5 |
| humanhash: | lithium-delaware-pip-coffee |
| File name: | 6addf4842ae23a4f6568794c23751ac5.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 232'339 bytes |
| First seen: | 2022-11-17 15:20:45 UTC |
| Last seen: | 2022-11-17 16:53:06 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 29b61e5a552b3a9bc00953de1c93be41 (174 x Formbook, 82 x AgentTesla, 81 x Loki) |
| ssdeep | 6144:MEa0N8zbkRk7bcWR3JKGmxPwUtKIjomDhCR:X8UyndJK9DcgomDI |
| TLSH | T18F34121367C29C77EDA326334972CB35C33AC648805310DF57B16EA6273A64BED1B64A |
| TrID | 48.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 16.4% (.EXE) Win64 Executable (generic) (10523/12/4) 10.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 7.8% (.EXE) Win16 NE executable (generic) (5038/12/1) 7.0% (.EXE) Win32 Executable (generic) (4505/5/1) |
| File icon (PE): | |
| dhash icon | b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
de6181f19146a4af8180634312316afb68576d5ae8d3da8ccc8cc5cbf8f17960
d4c48b5aefc7225b307e2e8c3f2d158b14fc6b736c83d36dc36a9d7c2e6eec29
0ef758cdcdaa95ecd6689cf13a719dd95def885bd1c5812295c2ed65d34b735d
0817943597641dc344c58a61071528b41db751494afc47a2e94ff39e8c6b9907
3f50e7d6a5865b6e508599fa5ef24d3450b45d2786629c3cb76854ac4bb0ee4d
22a8a048d90bb54c4bd72b1e91ca54eab47fa6eebf0b5e7cf903e9a822ccb25e
d1ab1ec4719acae215a39e45635f7acf7ac864b33c7a23cb5a89b8f90baf2e40
13dbe1ed2b3326581cfdd70ea9c9f43ae8a7cea9c1c6a50b7ea03ae6ee451eec
9dc2a5da6e549eff0358485278342915ecec6ef3d666a1234e6595163cbc6f60
08cec239baa56802c36475d7fff582d729dcef0375732b9879bd67fb0260d1c6
65996ea370508dfd2177caf453f833b53ed343c95e93b4c000382ae261173c65
b757c82d494f1f23816a87fc609e8f5227fbe921aa80c5fcddd95fde653c8523
d7c2f69689d1a1e95671fefa4ee708f62d29f078443bb31259ce2100bf5c37f5
523437805fcc7f3356f98479d5f7c268717886b41240a8b4466188fea8644f60
22d3aa3de84b7d01eccdf2471c93da8cbdbf39afc3a1c149d2109f2f9644f5d7
25d4c0553804fbcb055f1465780cfd4b920fb2d9e9eaaac87f7c1d0cd8e9f584
99c56c4551be01e229f63d5159d90f28c0b3fc18e7beae133aeea99a07f7feeb
12a921f6abb929d4f8b28924868dcc468299e44745c37db3aa7e4ac9bfe38869
856e9dc2812c572a9023f02503c471addbf8a82be5aed8454cc6254f899caccb
9afee5e6dd1d97f008641020ac405b40512c4c8f3ac1a9ee278eb75d18556bd8
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | meth_get_eip |
|---|---|
| Author: | Willi Ballenthin |
| Rule name: | meth_stackstrings |
|---|---|
| Author: | Willi Ballenthin |
| Rule name: | Windows_Trojan_Formbook |
|---|---|
| Author: | @malgamy12 |
| Rule name: | Windows_Trojan_Formbook_1112e116 |
|---|---|
| Author: | Elastic Security |
| Rule name: | win_formbook_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.formbook. |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.