MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f5e3854902bd670152c730527ace633fb8b14798d19ded0e4028c664de88ba6b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 14
| SHA256 hash: | f5e3854902bd670152c730527ace633fb8b14798d19ded0e4028c664de88ba6b |
|---|---|
| SHA3-384 hash: | 7d9a387d6c71cdfd2e174ec1572aa82ebcb12783cd4c6ac8b54f7d8e0bc4b9c2dcc513eb9a51ed8f4d8c48df93d07c97 |
| SHA1 hash: | 94736a4718d1178d96f7b08dda06547bc90c1788 |
| MD5 hash: | 2624156bf9968e87627f9734e2fcbff5 |
| humanhash: | alaska-carbon-lima-fourteen |
| File name: | SecuriteInfo.com.Trojan.MSIL.AgentTesla.NUC.MTB.30512.27998 |
| Download: | download sample |
| Signature | Formbook |
| File size: | 908'288 bytes |
| First seen: | 2022-05-18 14:33:53 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'662 x AgentTesla, 19'478 x Formbook, 12'208 x SnakeKeylogger) |
| ssdeep | 12288:A3WkaWJPEzPkvXS7CcTkX030Z9p00CVECesdcsMeacii7PmIVUW8G5sOX7gV3dTS:A3WkaWJS6XaCcs0Kp0jre4 |
| Threatray | 15'680 similar samples on MalwareBazaar |
| TLSH | T19D15D7AC321071DEE86BD676D9A81C68EAD0746B831B4203A02797ED9D4C9B7DF140F7 |
| TrID | 72.5% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.4% (.EXE) Win64 Executable (generic) (10523/12/4) 6.5% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.4% (.EXE) Win32 Executable (generic) (4505/5/1) 2.0% (.EXE) OS/2 Executable (generic) (2029/13) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
f5e3854902bd670152c730527ace633fb8b14798d19ded0e4028c664de88ba6b
91a6963181690c8f492d07f9eda4defa21e2695f8c8bc3c06ebdd4b82923f1ff
08bac2df27e5bc147a3fbc1eec996d1a9202dfe66cdd7cada83a21ae7ac45bbc
0f87b6c475a0eddbf33a364ed0fbef4f5cd19f8d4776ffad5d0bf0db9d63fc42
5c8cdc3745711d1054704b8663828b005aa7a66535b0004c0364bc5cff832ddc
44e2c23536091b586beb7947e0b37fafef0095b9b209ed113ed08619999f344e
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.