MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 fbe9af0d5f4eec35c73a7362af2c095693882f614e7fa42b9acdb0476bb5fb20. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 17
| SHA256 hash: | fbe9af0d5f4eec35c73a7362af2c095693882f614e7fa42b9acdb0476bb5fb20 |
|---|---|
| SHA3-384 hash: | e3c0b206cc970dcc41af65c7cf97e37219069ead3eb55a056b949a9042c46a6b8736a9f489f42558bd4e242ecbb22d2b |
| SHA1 hash: | 17325a50a00ae290d0cdec1c6bc06833ccd336b2 |
| MD5 hash: | e05e0cb637120f45bc28a0c416c7af02 |
| humanhash: | leopard-december-venus-orange |
| File name: | SecuriteInfo.com.Win32.PWSX-gen.3245.1850 |
| Download: | download sample |
| Signature | Formbook |
| File size: | 646'656 bytes |
| First seen: | 2024-02-06 19:29:29 UTC |
| Last seen: | 2024-02-06 19:29:31 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 12288:NUxLvnA7gEfuhhoOfQcfi4eWb4JUaFlD0gMRIoY8Ydr/67F7wAly/PIRuKdkWKZ/:NUx7nA7FfwQcfZ5b4Cut0Bkr5/6TRuYO |
| TLSH | T120D423B87BE038B7D63A52F5996220690330F5253D52DAE03DD370DB14EBF809A55B8B |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| File icon (PE): | |
| dhash icon | f269b44aadd268b0 (3 x Formbook, 2 x RemcosRAT, 1 x AgentTesla) |
| Reporter | |
| Tags: | exe FormBook |
Intelligence
File Origin
FRVendor Threat Intelligence
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
dcef69c94d8166b5bd96de0c8b5cc686bc3ec021c7754b43900a50a7913e0a9b
fbe9af0d5f4eec35c73a7362af2c095693882f614e7fa42b9acdb0476bb5fb20
0615ef112cce9f3111818a05ca04def31168070e160976b0f9f914b1807ef5ba
780749c5cfc69b6f4fc04b09709df33cd35a759dfaa4957c596dafd9a0ff11ab
77950a73e1fe319456c2eb3d13de26a1917cfa965bdb5016ad303f0ce9385501
1370d337f24395dc30833b04e4166d1820bcfc70a947132f15849c81a8f55c64
0df39b8c26a1b395b2389908f7dc4781aabba0aa10f4642baf46b8f1a9e2c426
77b71576856185e15daeb6b0ad20b0745c744a8f14dad72c98f479f2802bf545
494303b1cbd6db4ad8784f03ef83b345bf61105cf975fd1c2021a1d7fb4c5430
314a88c948270abad76c13c0e5800683ccc78392fed92673c50e14aace7576f3
bdf27a5c5327e39ec2d7b3a6a7c5068b68f0d0e46791c7afad0ecd6b1a803ef5
48d92c8ffc4d4b1f994fb5ab97c8a173de561bb7e8a5e08ce6d6042039def6dc
61e617222671bb531f25efd53cfc40311283984ef4d1366dc747a913e8294f40
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.