MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b32d05c6d0606ae99980ac52e9acbae681e7c35936abca1aa7bbc66bc25bb0e5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 16


Intelligence 16 IOCs YARA 3 File information Comments

SHA256 hash: b32d05c6d0606ae99980ac52e9acbae681e7c35936abca1aa7bbc66bc25bb0e5
SHA3-384 hash: 03a5c7ef39abc269fe06a0b3de04e1bcc37c75918d95c66105005a53ea52fa630f14a37b10623bf815316ccdc8e3d39f
SHA1 hash: 6023b8e28f9dd68bf7188da8c4d7489ab30040c2
MD5 hash: 482a15e9f8f6d5ccdc2d1897368acbbf
humanhash: jupiter-zebra-pluto-louisiana
File name:swift copy.exe
Download: download sample
Signature Formbook
File size:956'928 bytes
First seen:2026-02-09 15:50:07 UTC
Last seen:2026-02-09 16:33:09 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'818 x AgentTesla, 19'741 x Formbook, 12'286 x SnakeKeylogger)
ssdeep 24576:5cFguQf8FUuSyBzExr14er4vBstc3A5tDmZNv4:GyuiURSyBgxr14er15tDmZ
Threatray 2'691 similar samples on MalwareBazaar
TLSH T1B91512B032ADDD59C09D27B5B132E37557F59E96E413C32A8EE9BCEF7A2A7804404342
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10522/11/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter James_inthe_box
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
136
Origin country :
US US
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
_b32d05c6d0606ae99980ac52e9acbae681e7c35936abca1aa7bbc66bc25bb0e5.exe
Verdict:
Malicious activity
Analysis date:
2026-02-09 15:50:23 UTC
Tags:
auto-startup susp-lnk

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
94.9%
Tags:
autorun shell spawn sage
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
krypt packed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-02-09T05:11:00Z UTC
Last seen:
2026-02-11T11:24:00Z UTC
Hits:
~1000
Detections:
Trojan.MSIL.Crypt.sb HEUR:Trojan.WinLNK.Powecod.e VHO:Trojan-PSW.Win32.Stealer.gen Trojan-Spy.Noon.HTTP.ServerRequest Backdoor.Agent.HTTP.C&C Trojan.Win32.Agent.sb Trojan.MSIL.Agent.sb Trojan-Spy.Win32.Noon.sb PDM:Trojan.Win32.Generic HEUR:Trojan.MSIL.Crypt.gen Trojan.MSIL.Inject.sb
Verdict:
inconclusive
YARA:
8 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.15 Win 32 Exe x86
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook discovery execution rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
SmartAssembly .NET packer
Suspicious use of SetThreadContext
Checks computer location settings
Drops startup file
Command and Scripting Interpreter: PowerShell
Formbook payload
Formbook
Formbook family
Unpacked files
SH256 hash:
b32d05c6d0606ae99980ac52e9acbae681e7c35936abca1aa7bbc66bc25bb0e5
MD5 hash:
482a15e9f8f6d5ccdc2d1897368acbbf
SHA1 hash:
6023b8e28f9dd68bf7188da8c4d7489ab30040c2
SH256 hash:
48fa91de316a3b8b9b173548ff297a529e8045cfba133655cb8d7bf2517df628
MD5 hash:
54f2d8dcde429e9fa2c0cef39b6bb0e7
SHA1 hash:
1b0181a02d9f36613fdd5170d1b84a5a8358b2af
SH256 hash:
85bb8ef5c4fac99e6de28220bd7c79ae48a772502476b8d986b3c7583ba050d8
MD5 hash:
0ed556f6302b2955e576c6701284d5ec
SHA1 hash:
91581f0e3418fe20d4b1bb5cfd1c3d12c065f043
SH256 hash:
a8850e5399e30145bbda601299e29222ff1ed8eaff85f6924e30c800715dda89
MD5 hash:
63a158cbef1228bbc723810fb919484d
SHA1 hash:
9316bdaaf63cf43eccf6c032c21e4be0373e2411
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24
SH256 hash:
dddf639b5c328b1638dd15376a4738d2baab816a3c9c18c548662d4ac24656f1
MD5 hash:
c8ea43307579cb38d192a5b81337ac06
SHA1 hash:
eddd1afa414de2b1078b4f86160097aa30ee614a
Detections:
win_formbook_g0
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments