MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9c3d1181ce23bba35e82fe27f2a1c3726f880e045be58ada8bf919c4b59375d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: b9c3d1181ce23bba35e82fe27f2a1c3726f880e045be58ada8bf919c4b59375d
SHA3-384 hash: 32cb4fdd2dfc1fd764c1f4fda9f5929c2b33cafcaa628f57f18925f0299c1ff8bfa9ffaa495dede1304103a7b0b86ede
SHA1 hash: 3bb70a53f4bbfc65eb5680be4621e8d9305c7b69
MD5 hash: eb79958e4ad5f2e3a130926dbc8a059b
humanhash: social-jupiter-pizza-illinois
File name:license.ini.dll
Download: download sample
Signature Formbook
File size:797'752 bytes
First seen:2026-02-03 14:45:01 UTC
Last seen:2026-02-03 15:35:28 UTC
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 12288:N+Nuw7qIBVnpoKbhVeSCtMP4CqqLdWVtyDHK0ifh6adlDo1ct:44w7qIBZpoKbrekUqk0ifhnUct
TLSH T14605FB7F99629126DA4A80FC34494B625971B33B03B41FF701A69130271B9B2EED73F9
TrID 39.8% (.EXE) Generic Win/DOS Executable (2002/3)
39.7% (.EXE) DOS Executable Generic (2000/1)
20.0% (.SCORE) Music Craft Score (1007/6)
0.3% (.DBF) Sybase iAnywhere database files (19/3)
Magika pebin
Reporter James_inthe_box
Tags:exe FormBook signed

Code Signing Certificate

Organisation:Wenzhou Xihao Jiafang Co., Ltd
Issuer:Thawte Code Signing CA - G2
Algorithm:sha1WithRSAEncryption
Valid from:2012-06-26T00:00:00Z
Valid to:2013-06-08T23:59:59Z
Serial number: 0f775a4c2a20bd3f63efd8045b1f8a3a
Thumbprint Algorithm:SHA256
Thumbprint: 4d76f2564b95b30201de3ee28bec54d16a550465155bb63972db6466929d2391
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
125
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
_b9c3d1181ce23bba35e82fe27f2a1c3726f880e045be58ada8bf919c4b59375d.dll
Verdict:
No threats detected
Analysis date:
2026-02-03 14:50:14 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
expired-cert masquerade packed signed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-02-02T21:01:00Z UTC
Last seen:
2026-02-05T05:47:00Z UTC
Hits:
~1000
Detections:
HEUR:Trojan.Win64.Agent.gen
Gathering data
Threat name:
Win64.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-02-03 02:08:40 UTC
File Type:
PE+ (UEFI)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
b9c3d1181ce23bba35e82fe27f2a1c3726f880e045be58ada8bf919c4b59375d
MD5 hash:
eb79958e4ad5f2e3a130926dbc8a059b
SHA1 hash:
3bb70a53f4bbfc65eb5680be4621e8d9305c7b69
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments