🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a6d4a7d43d4868e871e0caac0ac2cbaa742a1c0a2416ce70c43a5e1c418d4a64. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 14


Intelligence 14 IOCs YARA 3 File information Comments

SHA256 hash: a6d4a7d43d4868e871e0caac0ac2cbaa742a1c0a2416ce70c43a5e1c418d4a64
SHA3-384 hash: 2268d1821ff41e879e6f0e97aab92a4f2eab460730e1659ef0245c547fe8aa650a3e650f5f793108105a4fcfac97588d
SHA1 hash: 7e2a19a78582bbd5043adbf08a74951bc78b62e0
MD5 hash: c99a6f0ab9d6577cfb961b911bead78f
humanhash: white-hot-shade-hot
File name:DHL_AWB#6078538091.exe
Download: download sample
Signature Formbook
File size:734'720 bytes
First seen:2026-08-03 11:22:06 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'247 x AgentTesla, 20'516 x Formbook, 12'379 x SnakeKeylogger)
ssdeep 12288:+GbXRFbxQ4sVlmZfR3hI5TzK0EnXOt2cka6A0aKyRROpDbN:+MRFNh2kfRRqwXOt2cka6ph7pD
TLSH T17AF42315A6A49327C1AD47F553E3127013F13C493222C61D998DB8FFACB2B48A6E47E7
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
File icon (PE):PE icon
dhash icon 31f0e4b8ccf0f811 (1 x AgentTesla, 1 x Formbook)
Reporter TomU
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
CH CH
Vendor Threat Intelligence
Malware configuration found for:
FormBook RoboSki
Details
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Launching a process
Adding an exclusion to Microsoft Defender
Unauthorized injection to a system process
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
masquerade packed
Verdict:
Malicious
File Type:
exe x32
First seen:
2024-02-25T17:34:00Z UTC
Last seen:
2026-08-03T07:02:00Z UTC
Hits:
~10000
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.26 Win 32 Exe x86
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2024-02-25 20:24:18 UTC
File Type:
PE (.Net Exe)
Extracted files:
11
AV detection:
26 of 36 (72.22%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
Formbook unc_loader_037
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook adware collection discovery execution rat spyware stealer trojan
Behaviour
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Checks computer location settings
Command and Scripting Interpreter: PowerShell
Family: Formbook
Formbook payload
Unpacked files
SH256 hash:
a6d4a7d43d4868e871e0caac0ac2cbaa742a1c0a2416ce70c43a5e1c418d4a64
MD5 hash:
c99a6f0ab9d6577cfb961b911bead78f
SHA1 hash:
7e2a19a78582bbd5043adbf08a74951bc78b62e0
SH256 hash:
7ce9ec8fdca6d924e30b6e3534d131c069d2acb212d1de95340d97bd5474f641
MD5 hash:
c5edaecd6bf8dcf19ae16e51e695c11c
SHA1 hash:
2742f128e65eac4c021a47744881e2675cdd8478
SH256 hash:
dad1607bc6e8eae197e60b56156a2c58f4cee1df8878e25d8a89cdcfd31409d6
MD5 hash:
0bc42fa7a870fb979f205da7ed72b11d
SHA1 hash:
43a96fa1de276e6e24df4c1791b6ca9da3c01b8e
SH256 hash:
cb786ea9eecfd63f13e5fd76f0292bfc721c12ed11f54cf45da367200a17b650
MD5 hash:
b96fa539189344a71d86410131bd8d6d
SHA1 hash:
504f63cac33c0375cdf86cce874324886641eb39
SH256 hash:
b5cb63a875c3796079a9728309230ca73c8faea5c4670f0b4552cfd9bd0753fe
MD5 hash:
7f20b768ab693eef476326fe90fdf778
SHA1 hash:
63294023b2050313f3a3fdf10fb4226babad3a6f
SH256 hash:
9581494ef9655b0e0bfae15ebca5388be2839b907c7b9337e5b6d16cf15bbfb1
MD5 hash:
f91ddcc223813605e8ce94691312372f
SHA1 hash:
795f8036ce50ac3b5938a9ab93a846c4c4ccefe3
SH256 hash:
1a434cbe6e3f89f8f84b2ba6e739579ed983d0076c6ed151b8d9db5ac525d5f4
MD5 hash:
22f7a9e6bcf74d1c3ee530114c935c44
SHA1 hash:
f5a867c977d394706db008ca630f76c61d927fe7
SH256 hash:
a6d4a7d43d4868e871e0caac0ac2cbaa742a1c0a2416ce70c43a5e1c418d4a64
MD5 hash:
c99a6f0ab9d6577cfb961b911bead78f
SHA1 hash:
7e2a19a78582bbd5043adbf08a74951bc78b62e0
SH256 hash:
5679785975ae6dda33fe97da50fa8406990331659b82aa59a17facc5dfcbc111
MD5 hash:
e092c3d65840dd16051a5b831f20b774
SHA1 hash:
61dbc99eac4d792aea822ee3a3f0adabe55ad8e2
SH256 hash:
72638f4b30cc9dab51d31216991957bf1cd118b8a8743227b3e8f9c4805f7628
MD5 hash:
2a8240bba06e832ee5d136a0a7e5b5b9
SHA1 hash:
de49d9b33004a4a622a4279b3ee2b3e3e5cd012b
SH256 hash:
7bed34a35df83d8d68c0228b51e0207e003f77901f0b8c7db5072c79ace174d5
MD5 hash:
4907c0cd77756283cb3723cea41aac20
SHA1 hash:
de5230c5072367387ecadad0f8a605af2a1c800c
SH256 hash:
b3f2bcb08ae6ed77b51186dc73ac27afc31c9e3b175914fbc7e932a053024057
MD5 hash:
8edcf081ada9f28a2722afb40ac6e099
SHA1 hash:
9a1d6568a6063fccac7eef51a12cbdaa81b82262
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

Executable exe a6d4a7d43d4868e871e0caac0ac2cbaa742a1c0a2416ce70c43a5e1c418d4a64

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments