MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 b7c5766632cab4527cafb24de5fe81cdfbf2daf41711fb5e6874ee99df8e1b96. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 16
| SHA256 hash: | b7c5766632cab4527cafb24de5fe81cdfbf2daf41711fb5e6874ee99df8e1b96 |
|---|---|
| SHA3-384 hash: | 166f878aa0f85f1a255b97fa3e151cd4c7e210b30a259d201b2f1028da3d7fd2d5ffdd89d9ce6e545f007d4840c77801 |
| SHA1 hash: | 65dc6cf4e21a68cfd8a133c10645567c7fabf403 |
| MD5 hash: | 380c3c5e4eb89b4de9600736ec309452 |
| humanhash: | london-lithium-mars-quiet |
| File name: | SecuriteInfo.com.Win32.PWSX-gen.12983 |
| Download: | download sample |
| Signature | Formbook |
| File size: | 803'840 bytes |
| First seen: | 2022-09-19 06:45:21 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'748 x AgentTesla, 19'643 x Formbook, 12'245 x SnakeKeylogger) |
| ssdeep | 12288:LzPp/DadsRJ/iC3l5ntYjLq04sT3do/ZvcdX:HPp/Dads+CAV4sT3dKF |
| Threatray | 15'442 similar samples on MalwareBazaar |
| TLSH | T15005C014137AC90BC869A575D8D2F3711EAC5DD4936FC24B88DC3C7BF63A3A468813A6 |
| TrID | 72.5% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.4% (.EXE) Win64 Executable (generic) (10523/12/4) 6.5% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.4% (.EXE) Win32 Executable (generic) (4505/5/1) 2.0% (.EXE) OS/2 Executable (generic) (2029/13) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
9eac243170351e71427a1376189c741b8d688adda3c91c028406cb1148ffc156
34db5de68222be2c4f1dab052209f06db2828dd04203b8f186e7d9238a0b3e33
b7c5766632cab4527cafb24de5fe81cdfbf2daf41711fb5e6874ee99df8e1b96
aae3b05849c586ce6103d0406369daf088d30359683580d2169dce88da0343eb
ccaea8ce020819c5c2c55cf1d77082bf9a4525f5fbf892f16d906d527d9c5726
a319609cff7e85f39ca69cdafd98380c93a007c56c2a62f75eeffcc564a7412e
2853b7b132646233f680fa71fc9040730267c5b5ab76f428fb0d67797577327b
7b7e01b69b15ad71f9f31365a61fe070f956e768fc943738e8c661a27904bab6
8c8f774034203771ed942e0c4a07b3bace7e8455993f57ed046d53cb6bfb1e1c
9504f87921d60985764ed9b28d02ab003258d5b79e2b6b568a50def6de7bfdf0
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.