MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0f62500183c45e1300fd51bf800fa7ef94d0cb4be11dc5c4e264d47ab315096b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry

Intelligence 2 File information 4 Yara Comments

SHA256 hash: 0f62500183c45e1300fd51bf800fa7ef94d0cb4be11dc5c4e264d47ab315096b
SHA3-384 hash: 5e2ab9820c200f4f45bd2721fa2ffef0cb95ae1cc36422b075dbd6217aaca38287d6dae01bee3f88468c954c39f56213
SHA1 hash: 458bd1cb7d9a48fc2c51f22422169de90388ada6
MD5 hash: f4b0462ce74e2dc8e6350f619565443c
humanhash: early-steak-echo-vermont
File name:Payment Slip_GS2004011507 _ GS2005014760.pdf.arj
Download: download sample
Signature FormBook
File size:293'971 bytes
First seen:2020-06-30 06:03:16 UTC
Last seen:2020-06-30 11:41:36 UTC
File type: arj
MIME type:application/x-rar
ssdeep 6144:ssHDJ5aYTxdBegoJcvtJKAisVD9RIAqmqXLjiD:tHDJ5aYTxdUg7v7IU9RIAqXQ
TLSH CE54238686559CA1CA65014F1A99CFC88E1A4F1D57D71B7B81FFB0083830E89A7EC6F2
Reporter @abuse_ch
Tags:arj FormBook

Malspam distributing FormBook:

Sending IP:
From: ChinPhil Marine Services <>
Subject: PAYMENT for Invoice GS2004011507 & GS2005014760 100% Deposit(OVERDUE DATE-06 MAY 2018)
Attachment: Payment Slip_GS2004011507 _ GS2005014760.pdf.arj (contains "Payment Slip_GS2004011507 & GS2005014760_pdf.exe")


Mail intelligence
Trap location Impact
CH Switzerland Low
Global High
# of uploads 2
# of downloads 29
Origin country FR FR
ClamAV Sanesecurity.Malware.27382.Rar5Heur.UNOFFICIAL
CERT.PL MWDB Detection:n/a
ReversingLabs :Status:Malicious
Threat name:Win32.Trojan.Swotter
First seen:2020-06-30 06:05:08 UTC
AV detection:12 of 48 (25.00%)
Threat level:   5/5
Spamhaus Hash Blocklist :Malicious file
VirusTotal:Virustotal results 11.86%

File information

The table below shows additional information about this malware sample such as delivery method and external references.



arj 0f62500183c45e1300fd51bf800fa7ef94d0cb4be11dc5c4e264d47ab315096b

(this sample)

Delivery method
Distributed via e-mail attachment