MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 b7bb528bfd86aea46c414f10f8463641a79e357b26d6b1b719d1e203bfa876ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 13
| SHA256 hash: | b7bb528bfd86aea46c414f10f8463641a79e357b26d6b1b719d1e203bfa876ed |
|---|---|
| SHA3-384 hash: | 1212d7955160e106efc532c994bc4c209be00b20163e68b7d298a2f3a04370a6f9392de42f4b3965f8e6f7a13d9ea0ec |
| SHA1 hash: | 7c88313920d2de20664d77e976b82adc7d3e6e3a |
| MD5 hash: | 3ecc4e7fb01e3fde5021bcfcd98281ca |
| humanhash: | one-robin-maine-orange |
| File name: | PO ZXASDC.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 742'912 bytes |
| First seen: | 2024-01-24 14:02:23 UTC |
| Last seen: | 2024-01-29 09:24:28 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'661 x AgentTesla, 19'474 x Formbook, 12'208 x SnakeKeylogger) |
| ssdeep | 12288:dP0yF4VHc8eSqS5wiwEw5Q1sqYKlkrDdntF762labVicUbSWdBi0C0ewpqV:ln0ruQDktnG2lskZxdc03p4 |
| TLSH | T1B2F412397368CBB6E99E06BC849002900376AC17B553D35A1CCEB0AC4D737859667BFB |
| TrID | 63.0% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 11.2% (.SCR) Windows screen saver (13097/50/3) 9.0% (.EXE) Win64 Executable (generic) (10523/12/4) 5.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 3.8% (.EXE) Win32 Executable (generic) (4505/5/1) |
| File icon (PE): | |
| dhash icon | ecf0c68ac2c298f2 (60 x SnakeKeylogger, 14 x Formbook, 6 x AgentTesla) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
HUVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
4000571c4d2e02e55de74268eb9477d61f9f506c567a3eeb55ab7b68b395959d
f7431cb039b7b6deb859f5afd5c813fca0f9a1b47dbcb0cd7bba5ce3a9b754d9
042116c3502dddb64ef3b3cf600cb6488f4e928cc9ec95969a7314286e10a554
aa2a7a45f9361876ba300272fd6c98d32ccdf80927ad088cf114195afcfc78bd
b7bb528bfd86aea46c414f10f8463641a79e357b26d6b1b719d1e203bfa876ed
198596d17d62409a12b4f1f21e0a165774653713a4f9f5918ed710711b72573f
27769f4bb96d0e605bdc282658c6a729e4ceb8447cd9e1f9880c69862258e66f
f84f0208e1ccce6876611ab8d7e4c92f4e02427e9a72283f5346f98bf6539160
77a38968b37bcb562fb8df2e70f08d312cabcaaf5dca09e995ead70240a05a30
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.