MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 b47f0c9d2511489e546b2ee97ba405868eade9a380bb43ffbba62ccf9469cb28. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 13
| SHA256 hash: | b47f0c9d2511489e546b2ee97ba405868eade9a380bb43ffbba62ccf9469cb28 |
|---|---|
| SHA3-384 hash: | 814fa678696df3b56dbd59aa296b3c28e78173e1262a2aa915b121fc3c754fe392f32af36172b232ea97e7cd0bdb57bc |
| SHA1 hash: | a26a70a2b14c69095a3a64e0c1b5181e62a25c40 |
| MD5 hash: | 0333f3f2b1b727753d79fb352682de43 |
| humanhash: | red-one-video-timing |
| File name: | akibet202305091122755.xls.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 656'384 bytes |
| First seen: | 2023-05-18 19:52:46 UTC |
| Last seen: | 2023-05-20 14:51:58 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 12288:32brI5MTbf+CqUVSwMYpNQEX42bGTtUC4nEOXrRh8LOP:orzTbGCqUVLhfQ2bGTmC+E8V |
| TLSH | T1EAD4F13816E6C71AC11B8738D1D1C3F06739DD86F5A2CB570FEDBC5BB68A2BA2221151 |
| TrID | 61.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 11.1% (.SCR) Windows screen saver (13097/50/3) 8.9% (.EXE) Win64 Executable (generic) (10523/12/4) 5.5% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 3.8% (.EXE) Win32 Executable (generic) (4505/5/1) |
| File icon (PE): | |
| dhash icon | 0000000000000000 (872 x AgentTesla, 496 x Formbook, 296 x RedLineStealer) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
CHVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
fd0c237241cf1dd94f69484051725c5c791425fba130a5dadc427069e8b367cd
b47f0c9d2511489e546b2ee97ba405868eade9a380bb43ffbba62ccf9469cb28
c370659751fff9888445826997052a9a734c3619098c05347774ab4d3f7e1e4a
1e2470cf5042f4ff269c98c7a33dd27ca36ddeed91d9fb18df591f40a2d18131
1cdde22ebe2251b7dc0678e7a6a7911384565312929a39976a46154272bfb075
70e6864d836f4750789712dcb97587a60c5317e40ec5bccdbebff3c0fbfd7967
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.