MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 efa23692aeb1a3c3365ba0c850e3248f4f0009bf386ff101dcd8dafe65f70024. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 16
| SHA256 hash: | efa23692aeb1a3c3365ba0c850e3248f4f0009bf386ff101dcd8dafe65f70024 |
|---|---|
| SHA3-384 hash: | 557b3868d1275c6091b8ffeea3df96ca96b347fea8b8e10b0e63a858524ecd1fcb21f8a3ab6d77899b7477bef00ec9ce |
| SHA1 hash: | a9ca20449144f01accfab92c209c81d1cce40400 |
| MD5 hash: | bd136c4407daa43a5bda0b7a11cac0e7 |
| humanhash: | music-butter-hot-music |
| File name: | PO-220183_EH EUROPE GMBH_PDF.exe |
| Download: | download sample |
| Signature | Formbook |
| File size: | 1'174'528 bytes |
| First seen: | 2025-06-17 15:34:43 UTC |
| Last seen: | 2025-07-07 14:08:06 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 3d95adbf13bbe79dc24dccb401c12091 (881 x AgentTesla, 737 x FormBook, 236 x SnakeKeylogger) |
| ssdeep | 24576:Ptb20pkaCqT5TBWgNQ7av3O5dRzDIdOMCn6A:MVg5tQ7av3ozDIwMY5 |
| Threatray | 2'373 similar samples on MalwareBazaar |
| TLSH | T1FE45D01373DE8361C3725273BA25BB01BEBB782506A5F96B2FD4093DE920121525EB73 |
| TrID | 40.3% (.EXE) Win64 Executable (generic) (10522/11/4) 19.3% (.EXE) Win16 NE executable (generic) (5038/12/1) 17.2% (.EXE) Win32 Executable (generic) (4504/4/1) 7.7% (.EXE) OS/2 Executable (generic) (2029/13) 7.6% (.EXE) Generic Win/DOS Executable (2002/3) |
| Magika | pebin |
| dhash icon | aae2f3e38383b629 (2'034 x Formbook, 1'183 x CredentialFlusher, 666 x AgentTesla) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
USVendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
0c38914220795dbd1b8adbdb2ba2b7d2236099f7720f0d4426a77b15e0a2934b
4fe0933a0bf1ade46b1dfe96a881c8528246b40d32aa3d08c18ab25d71e0946c
efa23692aeb1a3c3365ba0c850e3248f4f0009bf386ff101dcd8dafe65f70024
e5fbe89156a39d6398a8536176f3e983b9b052c2e2e79b61f270e033328edf3b
23323a33069681bab514aeb89322790e97f02099685bcfbeefd43afccca67141
10c502a060f3625e5ec841bf87e3f1e04f1ef0794edfcdc4225dd7d6cde0e2f1
5b3289beac94dff2d22258090d7b1a8af7f5527606fc7e0e24f772e94f5cf7a1
2256f1e172b1ea07f131b3963557469893c4a78de76c62c10ae5399a13b51b00
0b4068937a44dd0cae5a1bb2eac56a4d60da190adbcf43a5dc05332dd97857b6
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | AutoIT_Compiled |
|---|---|
| Author: | @bartblaze |
| Description: | Identifies compiled AutoIT script (as EXE). This rule by itself does NOT necessarily mean the detected file is malicious. |
| Rule name: | DebuggerCheck__API |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | Formbook |
|---|---|
| Author: | kevoreilly |
| Description: | Formbook Payload |
| Rule name: | golang_bin_JCorn_CSC846 |
|---|---|
| Author: | Justin Cornwell |
| Description: | CSC-846 Golang detection ruleset |
| Rule name: | meth_stackstrings |
|---|---|
| Author: | Willi Ballenthin |
| Rule name: | pe_no_import_table |
|---|---|
| Description: | Detect pe file that no import table |
| Rule name: | RIPEMD160_Constants |
|---|---|
| Author: | phoul (@phoul) |
| Description: | Look for RIPEMD-160 constants |
| Rule name: | SHA1_Constants |
|---|---|
| Author: | phoul (@phoul) |
| Description: | Look for SHA1 constants |
| Rule name: | shellcode |
|---|---|
| Author: | nex |
| Description: | Matched shellcode byte patterns |
| Rule name: | Sus_Obf_Enc_Spoof_Hide_PE |
|---|---|
| Author: | XiAnzheng |
| Description: | Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP) |
| Rule name: | YahLover |
|---|---|
| Author: | Kevin Falcoz |
| Description: | YahLover |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.