MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 d7345ce73fc7ba2e1b2e8176b0fc98295b2613e839506c5ff50992df5d88f38a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 15
| SHA256 hash: | d7345ce73fc7ba2e1b2e8176b0fc98295b2613e839506c5ff50992df5d88f38a |
|---|---|
| SHA3-384 hash: | 722b1661b964274b3a2abac7f573093d3d3233234ce5dd73188710a6983e4bb312c3b3eeb2b4e5dfb1ace64e01b737f9 |
| SHA1 hash: | d35cc37154e93e6196a8e07fa16a4f83c4cb5230 |
| MD5 hash: | 3e06d825a0060b7648a6f3869ae98ded |
| humanhash: | don-enemy-tennis-butter |
| File name: | 3e06d825a0060b7648a6f3869ae98ded |
| Download: | download sample |
| Signature | Formbook |
| File size: | 642'048 bytes |
| First seen: | 2022-04-04 16:20:30 UTC |
| Last seen: | 2022-04-04 17:07:27 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'653 x AgentTesla, 19'464 x Formbook, 12'205 x SnakeKeylogger) |
| ssdeep | 12288:THH8Ub56F1HURPr45tNIVgbokwQgGZSmXh50IOSwMD8VS:5k5o27 |
| TLSH | T164D4AA2A38BA100DB272AD6C6BBCB175911EF3F226365C7B0DF7054A11129F0DB9D627 |
| Reporter | |
| Tags: | 32 exe FormBook |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
3b3339c5adf6214450652108e3cf3122917319dac8516748884b7f27f42a99ac
0bd840a10d4463fe31116ce57b0b674a6d10176d910cf7bcd9ba360cfcb9f3a6
d7345ce73fc7ba2e1b2e8176b0fc98295b2613e839506c5ff50992df5d88f38a
9c5ca29eac3a8ed43997df919e47b72be824cb84564310870b30eb74096a5a57
a85ebc25048221b48dfc17183bf6a17b9c8cdadd06743a08af430bd822a0e02d
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | malware_Formbook_strings |
|---|---|
| Author: | JPCERT/CC Incident Response Group |
| Description: | detect Formbook in memory |
| Reference: | internal research |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | win_formbook_auto |
|---|---|
| Author: | Felix Bilstein - yara-signator at cocacoding dot com |
| Description: | Detects win.formbook. |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.url : hxxp://103.138.109.174/__spacekeep/vbc.exe