MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 be8ae15279781ab2ac7f6985d5d611d6533fdeb2be8d783eebccc28e38ab256d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 18
| SHA256 hash: | be8ae15279781ab2ac7f6985d5d611d6533fdeb2be8d783eebccc28e38ab256d |
|---|---|
| SHA3-384 hash: | 9335206449ff18e6c53d59771cf8938059294910157dd177d6a149222802883adc07728c0882e2f02422c14bec0d233c |
| SHA1 hash: | d0fd4803ea9c13c6ab8d9b1589d1d099136f7059 |
| MD5 hash: | 57ffb88b00438dbc952ec3746664ae7c |
| humanhash: | cup-xray-lake-pizza |
| File name: | z88Nuevalistadepedidosadjunta.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 1'119'744 bytes |
| First seen: | 2025-02-18 19:00:06 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'647 x AgentTesla, 19'452 x Formbook, 12'201 x SnakeKeylogger) |
| ssdeep | 12288:R6j1yPs9PgxbjSM7OmtMpLm+0nI8ZRwBOy8E2nYFKJ0uJ:RHs9PgB57qpLm+0nZI8hAKJ0 |
| Threatray | 4'834 similar samples on MalwareBazaar |
| TLSH | T19635603D21E82696D179C6B4CFD0C627B250B8E67097D824DDD2139A125BB0FBDC227E |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10522/11/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| File icon (PE): | |
| dhash icon | e0c4a2a2a4acbcd8 (11 x Formbook, 7 x SnakeKeylogger, 6 x RemcosRAT) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
BRVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
3a3ab32e4de2e4d9b2548961a5af1841fb8ea6e8b661679e6fcb963df324d7e9
d0a427ef5fa5496840ff480c1ba3f2b4a533d516f6fff8b012e131a4d5f6ddc6
0478f76edf55a95129c2dc410864c96e662827e14cda5d63f31456bb66122e42
faa8850d8a28a308c917200981a80bcc481cb089f804f6867a4608a28bf0b2b5
6c9bfc38f2dd0b8e0ff1ae18e0286fd13cc7f27dfadace3a6663ae53ef3c1ed0
ff040c7bf107a9f1287d37bf802069204275ae3e00df7ea4ac0afc8ac41a7af2
926223176c531972a352050b1fe4dc3a2ddc829c3a5ed15dc7fd27905bfbd1e9
e5f7e2beb3d5e6e5beff31347898bcf5124c432b325775a63863b465b2d1f766
c77f55a3137035638939de24d529042f2b234cb72d079737901be9967d74ad08
f5c2ca5c0224f07b3379faeb4d38d468e3266a939731a540700265568c5ee5a6
40808e79d55a9b69542b9c5204fe4e1ed52c75dfdd86a328461754bbfa8ab4b7
a4f1adf9b786fe5e0f9fc1242b00214ec6532f42e75c4d828d368ac1ef7c91da
cc90da2474f808f86cc1b0653b830630f43518e2e798eba2167b52eb4976faa9
009176f8fe52515f6230b0716f1c6fbed3036b6efc285a4a219260814e739e7c
f5416d2c5f567506a87fd4be6b16ff2f5aac8f0176ba08fd57be4580c28e3ff8
45e3b1735df7c76cac0c02dab2bd084220687e4d9786ea6a32e8bca70dc1a4cd
83c356a66a5fca0dcab9029d90a62358cd17822d0d5bfd745a54e3208bf55bca
3e6ec372972312319cb1a060b9fdd000d3ae6c00eedbd0c9599eb43ae2bcd822
f5147495983f1e0eb0d595bcced8d5fceedfef286909fe6f213760c0742493ac
b604d14fff0103500662f72e757d3c0d6138b9715d752ea68096ce75d0da18d6
77598e60e221cf8ad7c6b1a9f1644a06bf336aa69d86739299f4ffb83f844d32
8ec59075771e7d96b57ca7ff32316e03164dd34f1f72d2e033e795d8449af826
027704a79bc8bc9533c0d2d20c15ff824be56a280512e2305ac66dea22e91f70
57356dbebce9198acc6eb6c6d00d66e6bc1ed21a99988fc3bb473f83f5e8f939
287de19d6a0d64d959d34892c6992c6417aa4b4ebe6b3aeced33522a3d15638a
9ca8a8277296e09fa04ce5393ba39a917d69029dfc2a88b3a6a66e3576b5334f
aac33041fefe8ce37a64b94c622ee3c8c5c3e19018f09df1421f8b7f4e5bffc6
a7dcfd4b6de3f06fdfd1a77b23a4ac800db43cfc3772cd6f202f761d2fee1f96
11d67ce2068437cce35f0b601119ebd071921f536daa8a5afff7c4d03ff1a4bc
33b37dc7c77eeab90f5e561dbf89b3e2967b6477e9071d4ee35c09d4354067ae
84bcffa814dc707ae3f97445f3eb61f7ad8afd890c1cd257bae9db4b2de62982
6d27a676ed779a7ebcd1f6f9dd001af1e2ae84fa98a18ec61709bc79878976e9
02ec52f30f2125a25e1b45c2ad3f35a6601a11f1076d2cee29e6beabba3a655a
b7676b450924ebcad663577093f84f96d1228f4bf9e3808e127e1b2a16a70933
081ac62c1a586905a31013cde41b73255650a037652c9eafcc58b801d1853c1c
d1bcf8347e8ae64035086a221d42e0460b49c52d47fdb3dbbdaf94513e9b3271
aba0672f82dcf1487d5b7b5647291ee0974e962018425dbc48ee10438fd6cf07
9b0ca796af0910c7fc67d8c81a0a4f061c53278bfef5a568d6101c2c1eb8af23
f944ca1d7c21680cbe1f62c78655862863170c51861ea0d930e7ed9b22ebc7b2
be8ae15279781ab2ac7f6985d5d611d6533fdeb2be8d783eebccc28e38ab256d
a1e04def7fd209402cfc002db03fb18c9d8694d6707b4201cbaec8ce3303ff53
16ac39458488454a5d43d2f0d250fe014bf22ab1542ee6cbd10c6f69ab8d91d8
347515299470b63f35aa85a7d38f215520456ba07dd7cb43609197d070381b63
ae1a70825040f157d78228d5668ffa7f2759fdf83293e35c351e5b4e8d035c4f
da5672185bdcb791e426127091bc7da56812d6c6cba9fc6aca754e43b59834db
d4e7b1bcebd9b9150dc206559b929744b9b592d3d62baa7902f3979b60336177
b6d1bbc15f5ae144e4801f8188cbe4768f3ba42e2c4dd56f42a7fa5ec9638460
511058d592e007c9fa589f9a703d385c39b7744e9d10bf94ee5ffe8cc5b6dc34
ae88fec8df2e320104325abf884d96a5a5248b174cb42351fe46bb2f43c99ecc
0166d72b8690a6a6982062474e31e4564a737268d61dec45e8edb759536dd963
33a9199e6a15c0cca7a30439f71a166f9b475a0ce4d1ca548845ec8c49f5fd2d
4aee0546da115d551dd0bbaf2c59f17fde0005196484a6a8b6ebdaf0b2dea1b9
ffcdb62a0cc1adb7700c13310a3234fa7b25d0981a97ad089a7433c60e7f5188
5ae6da4b081c085b0fb204312664df1ad1c293e8b2bd59456c4038bba13ef95b
8d8bb9cc17e7e3bfda2630a37f1b8866fed36b43765ef579977684c7fcc6ee7b
0ac64e3c4051edae7fb30c1381b4406e4e79663e313b4dc0b6af84a460e011b0
ce00a14a2991483cdce0604f80100ca50e70073c171e053057b20d336a71966e
2ac5abf0ad9fd254de8135b4313aa1d06a4fdae68bd44db6891fdb3130e124e0
5f80dbe0b909aa3bbf9fa7f841ddcad1687efdaaf31b7523dda11ab6c8a97d94
538a9c0bb4dd4231c1787b894df3322333bd06d98b115b4cc30720e6b7260921
74eaa1d454050b2d1fbea9d50b8bb5c9cfe9c60e79fbdf9018ab37c8349d5955
5a2a58a5c9a50cda175b03b68636c5f68d7dcc73eb19311ceb2940dddc97654e
f332c9615a0633c97e162e3a76c4c75d3a9c64492a3656d0c6d3f06f89383928
055fc07fef20e60123cd7d9760cffff1cfceac4a752a91b810bb708da88b4316
f9925fbe9ba09a653092fabbcf4b097e46651f500ae7cfaf1f68515168b333c5
58c1bb1c19cd551261465044f769a313549a574a345a2754414e48f8fc08bcbf
9ff30e39c38ae46ea0f2ab5017fc68e32580aa9a8d7a237f98ecd5c3d8fefc34
5f1cae07f4460a2eaf90b0363c946e6a4e3af969064fa1cdfb87a3ace03bdfb0
ea3d846cce6aa910a7ff04f5908946c735f94c41576c4cf44ced9c6304491861
dcb42b8ad4e7cc40fe12cfef0f5b97fba6073716a6315784ed6dd8847a51e86d
edcd9db80fa6bb9d601b9827fd5e745b8b0c6057a34b02584ded808f2ede0a48
4af2c738b8b2cc2a5ffdc33dea46b4e82582d32c95af28456127991bb1b50e09
af991ddeba10d3b5f7d23603c840755386967bcb17175e3ff91dd52da78375b4
de54e5225a9f063cfed9c337da862e02590c3007a23dfbaccbc6365b60d27d3d
1696a69754bd81946fa83afad98de0bab251f1334beaef777aba712e9eddb143
0d30580a153ea3c6f4f23970f0ed810824fbd67a98f02b076db6c01db6af6c62
bb69c9e4dc8bbcb1e7c4d7fe8bcc86c87cdb4af34212b992a5ac82ca8e92782d
1eda4ab84c92facd24c30b894a114994122cab19f4fa0f9368fa147dbfc032f9
c7504e19276343cc24118b10ed938822f791425e06c4e1865101c5446eaea08d
3c00e14ee895971b1e91ad04aebc4970b9526b79ee8413c900acbb9b4ae702b8
a69b613b4c99988b72e10c917489d5a7006b53abc75f7706b578e8b27f3252ab
50e7be9654710bc245e54d71c9992052af681f9f7002bda7232474cc7eefcfcd
b00f2a45170a731d423dd77ccad80fdaaab538d52d4f938ad53eca799eba2b23
c11538b1d7c0d04e036eb09f26e4c59576a79b97fc420bb996c617c392bb8aee
aff2d8ebd4a9c0218b8df1314b12fd2dec7706b7f1cea2029c663c53e52ff187
b6e1a7be0cd6d15ce7ba0bc79da9b8f280ab0060bc7754ba3df84555fc28b0db
724bfa1f9bf8b08699e2cb9a8c6fc0a13da0d863ece815e6b9664aab67c3b61e
2c1df05dfc658609d528cc769dbcb60191e7893fac4b46823d69843f6c7ded71
405fe1e5e2f1e04c918ccad650f5f8c035058f182c8388bb755241dd91589bbf
7d358d9073726daef4a05cef7e9a6138aca76ecc4f679d15b4c98c8e23d2e763
2ed7941c78a8b93373502b3b638392b1981785718e31bbbcca4f251d6b21f535
fb98e235d9cd58d96ab4d3389fdacfff82beda19357f313fabd95729bc984ee1
e44b986da4c6d454e98db437793fa0efb393e329b6667291656224a61f4892c5
c95de6e5963a1f5a56a8c768e69b59217aceb0c725760b29054d4bc68c75ea7e
0b757a7d353142364276c6bea7225a9cf67f81206ce9fc8f9291ab4dc911a481
b69b9806518246a9db6ae7d892b6d20b3b2c3381851def105fc5bcb049e717fb
7c0fba40b02bce96b799951c2e559ff3e78ddb5ef096f13483ee206e33f6ad45
ca24c73a0f1820042d015e2d96c97c08a37cda6cda766e609f9e33970f269fee
0297c69a6525dcc36009ebcf3df69478f22e99d788dd81b1a26728c7acb663e9
76ec6af0a17474fbe15708cfbaf20c8a7ccfd68043e539e4ea38f24f34b8dbd8
3f21cc31c22b4ad07980033f0d016966da2743d9f65dc5bc592c46c2e028a074
05d3f3857ab465a1886005e6d6138c84b8c19447b71d1781e8169e48c371c0a3
30437c6991871291a51ae849894d48d0179bc459db221e48d1c4a5bb1cd522c6
b50e43fcbcbb576fcdaa25d54b1c245eb4896659a1418b0c7a2b517f016ee3c7
7453e2691add44d3d800249e0b5b37ab5f1e598b8e2917f8e0b0cebdde109179
eff4be0205784bb6386855f54630e170d8915e387d5a8f9d3b10174d7cc6f47d
fab2b2eddd748ae7fcbc5a1d0c2e0a7f9c75214a114d9450ca41c85ea9e71a09
730f10ea6f19f62c826e980760a20ded9eccbf13c5595ecfcf989722dabb4b27
3fdfd6e43f7328a408c2c5f27faf60cbf213f595c21cfd5b2fdd54170fcd2036
078263b898d23617f9d122ed659a6262ec0e90f284e429af3d08ef6da5d31b47
04b3e24898ad118dfee0013ae96979d83d0dc99c3497fd123b09d3cbf9180cbb
1b7695c083699fbd1a0f577d68a54a9619981a35dc3234b9298538e2021e3a7a
1fa99b813d2291896dd8a8d468345657d677a49b02b70d7c9f60e668aad2cc67
7b9c9e71110c3980f1803a7438f507eadea9b078e59a61d551e21e1cae8ad5e5
87dc8dea6c3860531876193b34e58dcc590cf646bd863e52430baee19b2271a3
72ef04b633c90ce77442104498f7b667e6bcf0deee9c837beb54d8d3bb3503e0
782cf5337d8a428867a0ab13d474628b427dbb1164d4449f7e8dc96bdab3c7b1
da551ab6e000732499227a67f2be68d1256b58d95963a903cc316e2730db9d1e
b6383a5fe17a23dce23e59aee55a9d304e60b25cc7cefe9d97e7703b0886c1bf
7b1d37ad80336e2eda4720deb2dd61b353c9ea2071f9cc2564b4fe28d2ca775c
6e3a3e33b2e7792291afadfd45153795c642eecf859eb01911943cd57a55e478
8bf01e5c0e48ae7f101d2e955f9829fa545449488b22d5bc1d02fc56545cb27e
39bfc41b1b43a5319ca1c0b1df4906b2ff41c120223f372e85a696432667fd93
572ee11cb26d0952d901bc35f226d46264264f01afa9cc1491745400f5e5f360
70a1293f9401485295f29c408954fff91895e3659daf15554f0d36acf01bb04d
73894e9dabbea10e1befbf6d68c03b45dd45e8170cc9cac9a2fa420585010ce0
d003d51384319fc697de30896a9c38c3363e352de173406f78f29410ca3282a4
1fd19f607089ebe45a528376af9057185444bb15a2f1307eca732674d3c39cd3
511af3c08bd8c093029bf2926b0a1e6c8263ceba3885e3fec9b59b28cd79075d
6506e06b9b96e41137ca0ff6be68c11c31804d350277ef345454459d4c2228bf
6b0bef0d0996bc1eed9dd88ee0f01478b1e5d01b016c03b6f18edc6225a72a6e
cef5d5a46f1f6207c526fbe6e55d370b3bf2543bb7cf53750002933881c89b19
920e4d99f8843d65a8339655a864bc81e03366e974a9f3329d860d515b60a0e1
08a38569c56df9d4889cfac468996617a68a149f8ddff7bad16e6609e7c5571c
e87a5cb662913f9eb7a91ba0879b534da9069f26e3176d9418b16b39eef6f9fc
30a2111fc32aa43eb5e19bbe6a17b4653387dc46c7b4c90f2b735fd1e58a05a9
0e96337c9c239e6151b82cd4caca508f1235787b14024e22f75606901016b232
a0ff35101d202ae3367837980c58ebbc2238ddbed52a614b73fee68bccdb7ad1
9b730e4e913091b07a3ac73db0b0bc8424fe5f005aa6ebdc7218287949ca1524
ddd294075c549d450ca2980348b9aa282fbc1cdc1f032b62f12f991365412fa5
8e000211c865431b51b1e3733e0bc6d7efcfb8a3d45631cb10f0d7813b0b2e59
be959c5af412cea0ace74075b381c4a2328160b92cdde26a4dd8739a437be30e
fa5584ac7257747136c877bd58182430e2d23d5c6b4eff9ab240fcaefe526ee5
e2981af6ab5e2643908ddd54773bcb6235122cf6d1d1a77a876edfea51ee4d63
a433c4a4a88ea7ade87bf36dd4ef522a8c6f13619f2ebf2bedbec029d59bb134
a7550382a1454c2310dd59d031924e796feb64e71ddaa26e16c36f30ba3d3197
9b7fee62771dd489a06bd73844e56c4335034872b8d0286cc456ca6077b0e149
9bf5d73a9924bd9e616336e200767e575569869d7d0ab959de9c7ebb37914dfc
2040a0fdd0eddf11176cddce8489b0906e9bb6ed39b2c825f883e26a3309db57
4336ddb80f3875340305306f98bd57efcb38a2182153d71308957167a295c070
36b2c227683d3aea101fb59edb33edb1ba28ec0753a32a5ce42b1959d6716965
d0cff61258d18def7ad7129368ecaccf5d2389eb1fd79b6cbb411c65c5783e0d
003e445ec7e3a973ac6b61b8375e4db13e9ac69a2fb48f3c647571c473eb22c2
9d81ffafe26b6cf9e8c5fb0ff739c279d07c6d96b7f1f3927741e7cb6746b452
be8ae15279781ab2ac7f6985d5d611d6533fdeb2be8d783eebccc28e38ab256d
bb69c9e4dc8bbcb1e7c4d7fe8bcc86c87cdb4af34212b992a5ac82ca8e92782d
b1d422db723db6c2f7293a2c09397b46677407aaea878d24c63b0911edd0c6d0
7df9ceec9c6ece56d60b5264804b0c9360c4f87bc595d9987c5d87990511ba34
f2042d162f33fa6527abd2dc4e593a6f89215f903b6a4afe9b57da3f6da7c6d4
20e542ae3966472a40baa9e22ee751b54547961e6b5b43d23040342625685193
d6ffa7c046b2e2d6268f0e516170f77c2f1aad8fbfa1feba5be0f4fe7963aced
94cabb62a68074520220fe485bf718bb4ff66b76ff39037542845d2f143e35ce
ea4fe51e13f6ab1785535b32345f69ef110e21981bf7dbb09ce02c0bdec1e43c
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | AgentTesla_DIFF_Common_Strings_01 |
|---|---|
| Author: | schmidtsz |
| Description: | Identify partial Agent Tesla strings |
| Rule name: | DebuggerCheck__GlobalFlags |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | DebuggerCheck__QueryInfo |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | DebuggerHiding__Active |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | DebuggerHiding__Thread |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | golang_bin_JCorn_CSC846 |
|---|---|
| Author: | Justin Cornwell |
| Description: | CSC-846 Golang detection ruleset |
| Rule name: | MD5_Constants |
|---|---|
| Author: | phoul (@phoul) |
| Description: | Look for MD5 constants |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | pe_no_import_table |
|---|---|
| Description: | Detect pe file that no import table |
| Rule name: | RIPEMD160_Constants |
|---|---|
| Author: | phoul (@phoul) |
| Description: | Look for RIPEMD-160 constants |
| Rule name: | SEH__vectored |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | SHA1_Constants |
|---|---|
| Author: | phoul (@phoul) |
| Description: | Look for SHA1 constants |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Sus_Obf_Enc_Spoof_Hide_PE |
|---|---|
| Author: | XiAnzheng |
| Description: | Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP) |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.