MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 bfac76ed38d1b5d2737a76ce7c59f1651040d11c1ec63388364e4cd37cc4fbee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 13
| SHA256 hash: | bfac76ed38d1b5d2737a76ce7c59f1651040d11c1ec63388364e4cd37cc4fbee |
|---|---|
| SHA3-384 hash: | d44b46103e942d7624a7d04a5c33ff77fcbc271108f18649d0486d02230886b7cd2c5297297e2b7e66868fb340479294 |
| SHA1 hash: | 1a9c8c3399b4589a6214b2388698573dd0df2312 |
| MD5 hash: | 3384eb6578fff4306e70f2d50f61b9cb |
| humanhash: | apart-ack-zebra-florida |
| File name: | NUEVA ORDEN DE COMPRA.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 626'176 bytes |
| First seen: | 2022-08-29 09:31:48 UTC |
| Last seen: | 2022-09-06 11:59:30 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 12288:aHsEU2IHeYCEcGIaXZVGeVwj9Yu26HrUOjlylSx1GKqw7O4IOi2:aM1fBSCQHrUwg |
| TLSH | T1BCD4AE0C79E877FEC863DD3199A45DA496A364B71B4F930E4D8306B8DEDD583AE08063 |
| TrID | 72.5% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.4% (.EXE) Win64 Executable (generic) (10523/12/4) 6.5% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.4% (.EXE) Win32 Executable (generic) (4505/5/1) 2.0% (.EXE) OS/2 Executable (generic) (2029/13) |
| File icon (PE): | |
| dhash icon | ccb2a698d4d4d8e4 (4 x AgentTesla, 3 x Formbook, 1 x SnakeKeylogger) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
4cb742927b299c24ca04c80d3ea10a5e3b4a5aa6508aba92c0e9e5fce2eebab1
637f702a6f06a32c6b1794df68ccf1e7f29a2aa38b468b296816ba9010606a1a
61e02739fb76c2e56860acdbeda1ed43769648fc4e7908c31b7194ff94a3981d
9238603739f090fa4b311ab4c76739c1b54d21e410139c6be208025b4dd7a33f
61c8ca02306264110104d4803a15eacc1949f65dd2b1723f159ed3f93553a384
663a1d5b9cec98717c0c4007942db9627fd88ec897d21f80e6fa0ddce642e22e
bfac76ed38d1b5d2737a76ce7c59f1651040d11c1ec63388364e4cd37cc4fbee
7f247f33a3cfc5c0282c5a8730ff0ec2a37b20983832fe1de65d86eb1114e38d
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.