🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 faf4efd14cfe28db1bc8fe68f9b8920207663ae936409aa2576eda80c1cb87cc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 19


Intelligence 19 IOCs YARA 3 File information Comments

SHA256 hash: faf4efd14cfe28db1bc8fe68f9b8920207663ae936409aa2576eda80c1cb87cc
SHA3-384 hash: 822ddc848ea308ee93889d981f1cba81ad4db7d4e137e5a83d267f266e651a3ca4063994a233ae51f583e9a0faf8ca9e
SHA1 hash: 2b82a41eb2162bf0673eda98ea5e97b75213e0db
MD5 hash: 565250285d77211d7a92878d1f3fa5f1
humanhash: kilo-mountain-yankee-carpet
File name:faf4efd14cfe28db1bc8fe68f9b8920207663ae936409aa2576eda80c1cb87cc
Download: download sample
Signature Formbook
File size:1'067'520 bytes
First seen:2026-09-10 11:03:03 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'249 x AgentTesla, 20'539 x Formbook, 12'385 x SnakeKeylogger)
ssdeep 24576:ZjP/2oSdvHWBc9jJqfMtsyNrDxuLehlZk:Zb/2oSJWAqEsyFDxIj
TLSH T13B3502582127DC12D1D61FB048A1E3B517A44F80E923C303DEFA7DEBB97B79A6E44291
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon c0cc8e96c6c6d6d2 (4 x Formbook, 1 x Stealc, 1 x RemcosRAT)
Reporter adrian__luca
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
98
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
formbook
ID:
1
File name:
DOC-J1674 + 674-1 + 1674-2.rar
Verdict:
Malicious activity
Analysis date:
2026-08-25 00:59:41 UTC
Tags:
arch-exec netreactor formbook stealer xloader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
shell virus msil
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a process with a hidden window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Adding an exclusion to Microsoft Defender
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-08-24T04:45:00Z UTC
Last seen:
2026-09-12T08:18:00Z UTC
Hits:
~1000
Verdict:
Malware
YARA:
12 match(es)
Tags:
.Net .Net Obfuscator .Net Reactor Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.67 Win 32 Exe x86
Threat name:
Win32.Backdoor.FormBook
Status:
Malicious
First seen:
2026-08-24 08:01:22 UTC
File Type:
PE (.Net Exe)
Extracted files:
16
AV detection:
27 of 36 (75.00%)
Threat level:
  5/5
Result
Malware family:
formbook
Score:
  10/10
Tags:
family:formbook campaign:ge11 discovery execution rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Checks computer location settings
Command and Scripting Interpreter: PowerShell
Family: Formbook
Formbook payload
Unpacked files
SH256 hash:
faf4efd14cfe28db1bc8fe68f9b8920207663ae936409aa2576eda80c1cb87cc
MD5 hash:
565250285d77211d7a92878d1f3fa5f1
SHA1 hash:
2b82a41eb2162bf0673eda98ea5e97b75213e0db
SH256 hash:
0d5db9542d16364e40394a0367b85d57365dfa216f1e6d29f8ed291f41a10f05
MD5 hash:
11206d5b4a2c1fa6f0927545d63259d2
SHA1 hash:
53ffd9ee189a8cc27a162ccca59adc0b387cd588
SH256 hash:
0a99bef3e2a5e2a9652e42a8c2d80007cc480f502b863555fb387fcb5f260482
MD5 hash:
7298282b56515393e6db1783ab938dd0
SHA1 hash:
b5c8d0eaa9447b5fba56ff07ea11b5bcee48369b
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments