MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e1830429d29e6d8dc4c994feccd9953bd2f2761811c855a33c754776b5f6572b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 14


Intelligence 14 IOCs YARA 5 File information Comments

SHA256 hash: e1830429d29e6d8dc4c994feccd9953bd2f2761811c855a33c754776b5f6572b
SHA3-384 hash: c090ef7160121cf34149dc6930046b7f40a48f219fa74d52484238ae711d1bee6e3995b29fba3bc67ddb961c55ef453f
SHA1 hash: c77c48b6a2ae4d6d6447db1e72c8a62c3aed6e77
MD5 hash: cdb901f5bf5bb4239d6aae5bdde7fef3
humanhash: twenty-tennis-idaho-five
File name:e1830429d29e6d8dc4c994feccd9953bd2f2761811c855a33c754776b5f6572b
Download: download sample
Signature Formbook
File size:1'180'160 bytes
First seen:2026-08-10 14:15:01 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'191 x AgentTesla, 20'339 x Formbook, 12'364 x SnakeKeylogger)
ssdeep 24576:sV/MwmWFFQeswgKEoZ6pPVCX0pXyRrbDLnu8tsbO/G6:5PW/LEbd4rbXnu8Kbi/
TLSH T173451214A315E606C5816B38DAB1F2F603F95EEDE801EB538FD9BDEBB836B414844352
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon 3e73715d4d5d7d23 (62 x Formbook)
Reporter adrian__luca
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
HU HU
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Launching a service
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
explorer krypt lolbin packed vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-12T22:59:00Z UTC
Last seen:
2026-08-10T03:44:00Z UTC
Hits:
~1000
Gathering data
Threat name:
ByteCode-MSIL.Backdoor.FormBook
Status:
Malicious
First seen:
2026-07-13 05:08:07 UTC
AV detection:
18 of 23 (78.26%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook discovery rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Program crash
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Family: Formbook
Formbook payload
Unpacked files
SH256 hash:
e1830429d29e6d8dc4c994feccd9953bd2f2761811c855a33c754776b5f6572b
MD5 hash:
cdb901f5bf5bb4239d6aae5bdde7fef3
SHA1 hash:
c77c48b6a2ae4d6d6447db1e72c8a62c3aed6e77
SH256 hash:
7a09d4c71af5d34d449fc0ba91c8993492828bc5d6a1a3300c3f27df63c56e28
MD5 hash:
acbdef84097e8e77e2fa56219b88e479
SHA1 hash:
1d0de023f006931d010e601ff392b6621279ddba
SH256 hash:
97c23fc04cedb4f6a978cb54fb734bb3cb6226cea7df86f12b222a9d946c86ef
MD5 hash:
2218509125c5d27dceaecada27190fce
SHA1 hash:
614d7515836b0a1eecc6ce9021f0bf03510ac55d
SH256 hash:
394055dd0a133f45019ff5eb44ffe92a11fed9870db7cdfb76dba9548a3823e9
MD5 hash:
05a678ded7ee3cb043e96eb01d8898d2
SHA1 hash:
a56339b34f49b270c356101b65ac814f51084bf5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:test_rule_vldslv

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments