MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 bcfc27ac62a86bb98e019ba5eb2c6032fd5a56f6aacee84974b07217c2c1fe7f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 16
| SHA256 hash: | bcfc27ac62a86bb98e019ba5eb2c6032fd5a56f6aacee84974b07217c2c1fe7f |
|---|---|
| SHA3-384 hash: | 7b032905d9483bd9c2837fb862e06818cca735e57c8e1a00282413b1328f167c14151a0f455bd7c1863fc4473ff4a083 |
| SHA1 hash: | 66ba57445342ddb993dacb92b6c480601bea23a7 |
| MD5 hash: | 058b00db790aec74669bb53a0b567f89 |
| humanhash: | stairway-ceiling-seven-cat |
| File name: | jkjn.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 282'451 bytes |
| First seen: | 2023-03-13 00:13:33 UTC |
| Last seen: | 2023-03-13 01:28:44 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 61259b55b8912888e90f516ca08dc514 (1'059 x Formbook, 741 x AgentTesla, 427 x GuLoader) |
| ssdeep | 6144:vYa6P7wtR+RUxyzof0+B8YBxoaT8QXxHDCg4heID:vY9ktR+qykc+Qq8QXVOPV |
| Threatray | 2'294 similar samples on MalwareBazaar |
| TLSH | T1FC5412603DB08DB2E46206B51E3786BF8BF6911647B4BB47276422487D52A87F32F391 |
| TrID | 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 15.9% (.EXE) Win64 Executable (generic) (10523/12/4) 9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 7.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 6.8% (.EXE) Win32 Executable (generic) (4505/5/1) |
| File icon (PE): | |
| dhash icon | b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla) |
| Reporter | |
| Tags: | DHL exe FormBook |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
cc83e0a51f3dcd04a4c9b1a2ba3049227459cac541da52b518ee5ebcfbed4796
93f922ec0297bd12a61774a11f85689c86f59f77f5d4641bbd2c403e135bd252
bcfc27ac62a86bb98e019ba5eb2c6032fd5a56f6aacee84974b07217c2c1fe7f
b90e0459fdb810054fc751ecbdf0e66e282f41a66d346aff061769712f1b360c
b819e0dd1a5dc229d16fa74251262ce7fdd7581a71f66c9dec61149a7c4c7a76
cf05a6c9248904af6ebb0a728f582c2ca34e11fe7cd9a2e4ebf876ea253256ad
bbfb2aacf1ff431d0ed71b54c499d3a56b6bcc90d5137cd78097b40c354c2353
87c35ff97227cac466f0dae47ba41a1b81fc197ba4a2dfc87cb855226e0f327f
c59154416f276d2f20a57bcef306c39ca0c3276c1ae4383003b0deb9efa08a0b
90144e9ed70c41764f7db4608bad61d08ec7d62f6e105fe862886cd44216d3d8
3fb2ea468d879582791fb74c6ef0898e45f62b2e22c6b6b1311def934957cde2
ef20282677db7a5c43185fa1c317ca08ba225107e3543a10e4bf5c922139c278
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | azov_Dropped |
|---|---|
| Author: | Potatech |
| Description: | Azov Detection |
| Rule name: | cobalt_strike_tmp01925d3f |
|---|---|
| Author: | The DFIR Report |
| Description: | files - file ~tmp01925d3f.exe |
| Reference: | https://thedfirreport.com |
| Rule name: | meth_get_eip |
|---|---|
| Author: | Willi Ballenthin |
| Rule name: | meth_stackstrings |
|---|---|
| Author: | Willi Ballenthin |
| Rule name: | shellcode |
|---|---|
| Author: | nex |
| Description: | Matched shellcode byte patterns |
| Rule name: | Windows_Trojan_Formbook |
|---|---|
| Author: | @malgamy12 |
| Rule name: | Windows_Trojan_Formbook_1112e116 |
|---|---|
| Author: | Elastic Security |
| Rule name: | win_formbook_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.formbook. |
| Rule name: | win_formbook_w0 |
|---|---|
| Author: | @malgamy12 |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.