🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fa1d013f5d8f4833ca5e80b1987ce0908625fab234048fe16e293d5ccbb963fa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 15


Intelligence 15 IOCs YARA 7 File information Comments

SHA256 hash: fa1d013f5d8f4833ca5e80b1987ce0908625fab234048fe16e293d5ccbb963fa
SHA3-384 hash: 56f98ad968c06335a0cb5b683ebf68703a667beab38e84ace980cca6f9ce9c311180d1aea8043ad91d3f51d217e130f7
SHA1 hash: 13e07c20dc2e25f48cb91682f2d5f97b9e398148
MD5 hash: 0709e53641829dc93945aece20e2da21
humanhash: kentucky-delaware-quebec-sodium
File name:neue Bestellliste.pdf.exe
Download: download sample
Signature Formbook
File size:858'624 bytes
First seen:2026-10-06 07:04:20 UTC
Last seen:Never
File type:Executable exe
MIME type:application/vnd.microsoft.portable-executable
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'249 x AgentTesla, 20'539 x Formbook, 12'385 x SnakeKeylogger)
ssdeep 12288:QX697n4P0onz5sVZ+vuE66oCKgQXws7toWAaD8uFYwR0Tex3DnFSA9KyR:VdEnqVzEx0w4D8uWwRuexkAXR
TLSH T152059B04221BDB23C65526B0C973E2F90374DD59ED32832F49E9BDB77F36EA0A4541A2
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter lowmal3
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
166
Origin country :
DE DE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-10-06 07:14:29 UTC
Tags:
netreactor

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Сreating synchronization primitives
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
masquerade packed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-10-05T14:20:00Z UTC
Last seen:
2026-10-07T23:02:00Z UTC
Hits:
~100
Result
Threat name:
FormBook
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
Antivirus detection for URL or domain
Found direct / indirect Syscall (likely to bypass EDR)
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Queues an APC in another process (thread injection)
Sigma detected: Suspicious Double Extension File Execution
Suricata IDS alerts for network traffic
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Uses an obfuscated file name to hide its real file extension (double extension)
Yara detected AntiVM3
Yara detected FormBook
Yara detected MSIL Injector
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1982799 Sample: neue Bestellliste.pdf.exe Startdate: 06/10/2026 Architecture: WINDOWS Score: 100 28 www.heike-mebus.xyz 2->28 30 www.teciecabs.com 2->30 32 19 other IPs or domains 2->32 54 Suricata IDS alerts for network traffic 2->54 56 Antivirus detection for URL or domain 2->56 58 Multi AV Scanner detection for submitted file 2->58 62 10 other signatures 2->62 8 qAzFqG8huWdWA.exe 2->8 injected 10 neue Bestellliste.pdf.exe 3 2->10         started        14 G9AHZyZNW4wA8o.exe 2->14 injected signatures3 60 Performs DNS queries to domains with low reputation 28->60 process4 dnsIp5 17 recover.exe 13 8->17         started        26 C:\Users\...\neue Bestellliste.pdf.exe.log, ASCII 10->26 dropped 64 Injects a PE file into a foreign processes 10->64 20 neue Bestellliste.pdf.exe 10->20         started        22 neue Bestellliste.pdf.exe 10->22         started        34 www.desyki.site 66.29.152.174, 49773, 49774, 49775 NAMECHEAP-NET-NamecheapIncUS United States 14->34 36 www.gangseo-noraebang.com 121.254.178.253, 49793, 49794, 49795 LGDACOMLGDACOMCorporationKR South Korea 14->36 38 12 other IPs or domains 14->38 file6 signatures7 process8 signatures9 40 Tries to steal Mail credentials (via file / registry access) 17->40 42 Tries to harvest and steal browser information (history, passwords, etc) 17->42 44 Modifies the context of a thread in another process (thread injection) 17->44 52 2 other signatures 17->52 24 firefox.exe 17->24         started        46 Maps a DLL or memory area into another process 20->46 48 Queues an APC in another process (thread injection) 20->48 50 Found direct / indirect Syscall (likely to bypass EDR) 20->50 process10
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.46 Win 32 Exe x86
Threat name:
Win32.Backdoor.FormBook
Status:
Malicious
First seen:
2026-10-05 16:30:02 UTC
File Type:
PE (.Net Exe)
Extracted files:
11
AV detection:
20 of 24 (83.33%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook discovery rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Family: Formbook
Formbook payload
Unpacked files
SH256 hash:
fa1d013f5d8f4833ca5e80b1987ce0908625fab234048fe16e293d5ccbb963fa
MD5 hash:
0709e53641829dc93945aece20e2da21
SHA1 hash:
13e07c20dc2e25f48cb91682f2d5f97b9e398148
SH256 hash:
e2f9041bea41bb5fb6b4e74bea5a04c21591aac07e2b4ab54ddc33a7ba294c4c
MD5 hash:
2a534625a42e519937f3c0ccc1cee192
SHA1 hash:
fa6fff97448409778d052a51f2f04e8280b6e0a9
SH256 hash:
bc89b029b24fde6683984750f02da267e9def9c83d1e19f7a355b9ddc01b000a
MD5 hash:
d746d27eb694af7fd0ba01a5d1816f6a
SHA1 hash:
de6a212d427410f3ea8b486d7f48ea01a3b53129
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:HUNT_NET_Loader_ImagePixel_To_AssemblyLoad
Author:Anish Bogati
Description:Hunting: .NET loader that reads pixel data from an embedded image, loads it as a .NET assembly, and runs it via reflection or late binding. Catches bitmap-steganography loaders.
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:WIN_Malware_Derialock_ForgeAuto_3127f957_Extrait
Author:Marjoriefort
Description:Detects Derialock (pe, etat extrait)
Rule name:WIN_Sample_Unique_69354b41
Author:Marjoriefort
Description:Specimen unique (soumission Bazaar) - strings distinctifs propres au sample
Reference:69354b41e10daf03d3f3af881b32d5c0fec56b1cfe96629fd4c5263413a42854.exe

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments