MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d1385115e76ee9953b959bfb963aaee1a77a2862842b6995dc057fef332bac10. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 14


Intelligence 14 IOCs YARA 4 File information Comments

SHA256 hash: d1385115e76ee9953b959bfb963aaee1a77a2862842b6995dc057fef332bac10
SHA3-384 hash: 623b1068fff6190bce0041419b2cae206493e2a223e0b1c2e9909d0f4261936574f519c9b624ab75de30498e84c8fa19
SHA1 hash: 5d2c70794598be26a77dcbdc009bd9730f4c67cf
MD5 hash: 7503c336e6854e0fd68af9dca257b930
humanhash: hamper-crazy-shade-victor
File name:QUOTE.exe
Download: download sample
Signature Formbook
File size:1'072'640 bytes
First seen:2026-07-25 15:30:31 UTC
Last seen:2026-07-27 06:28:52 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'125 x AgentTesla, 20'148 x Formbook, 12'362 x SnakeKeylogger)
ssdeep 24576:29m2d07VES6WanbpA6d8agynZ7t8K7fhkSiKYzyp:liSQ6yZh/kSL
TLSH T15835023B8DC76F62C53C0F7881AA044C23F489579262E76F3FFD01A69FA17A48636591
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter JAMESWT_WT
Tags:exe FormBook Spam-ITA

Intelligence


File Origin
# of uploads :
2
# of downloads :
193
Origin country :
IT IT
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
QUOTE.exe
Verdict:
No threats detected
Analysis date:
2026-07-25 15:32:06 UTC
Tags:
netreactor

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
obfuscated obfuscated packed vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-24T00:40:00Z UTC
Last seen:
2026-07-27T13:39:00Z UTC
Hits:
~1000
Malware family:
Malicious Packer
Verdict:
Malicious
Verdict:
inconclusive
YARA:
11 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.84 Win 32 Exe x86
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-25 02:32:13 UTC
File Type:
PE (.Net Exe)
Extracted files:
27
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook discovery rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
.NET Reactor proctector
Family: Formbook
Formbook payload
Unpacked files
SH256 hash:
d1385115e76ee9953b959bfb963aaee1a77a2862842b6995dc057fef332bac10
MD5 hash:
7503c336e6854e0fd68af9dca257b930
SHA1 hash:
5d2c70794598be26a77dcbdc009bd9730f4c67cf
SH256 hash:
e73743a45eb537cf9796496f0a31ffc882f7bbba65ae3cdf82cffd4c3cbeb977
MD5 hash:
1c66265ed46ff34ceae29f2a9ad73358
SHA1 hash:
8e2935c331474c410723b34eb0ce75d7eadb1e3a
SH256 hash:
c452e33e70a96d20b8ec1e9f00048b7d294cee5ce2617e0f2fcf750795d4e54d
MD5 hash:
4930bc9a31f378e1d10352c0939a7ef8
SHA1 hash:
9000199dc601c374007c3486204ca46c39fcbeb9
SH256 hash:
2c9a6d18cb8782c2887d81ee366bdaffd3907d39457a67945234e5e60f9345b1
MD5 hash:
daf39b51064c8f36ab287d89234d5316
SHA1 hash:
c444d046e4c88ab0cfe66cf69ab8a1d47a7eeb26
SH256 hash:
796acfd240499a90c15a6b08743e334334c66575d99272f8ee90890abce844ae
MD5 hash:
44a2713e340b64cdee04451c7c9f0d61
SHA1 hash:
080cd9fa4e567bae63bb797ef96b1970d202eda6
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments