MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0fa91b5908e67e139b25b626a047da5ab3003187d0b22ccad00cce2e503a350f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0fa91b5908e67e139b25b626a047da5ab3003187d0b22ccad00cce2e503a350f
SHA3-384 hash: b113fd4c5e5690e9ebee168e971b60893da11ee5b093019d3b290db6b91f19f4fbb9e951297b54002b28a6a540b8bdcf
SHA1 hash: 656151329ba5e185306fd771e8a77ba2bc77d0fb
MD5 hash: c607e8da28ea05a0d8af082f73a1e889
humanhash: island-floor-maine-juliet
File name:New Order.zip
Download: download sample
Signature FormBook
File size:624'565 bytes
First seen:2020-06-15 05:36:59 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:YC4m/mMiT2BxvcN5+/NbR6h4xvtQPCsKxKuUADbClaW1J+KHOUNwME3q4SlRl9:YKuMiaxvcNYNbRC4xvtQPCsKmAD2laW9
TLSH 7ED4234B282D8B47F628BE5A03C235A2D3C7E9C011FD72BF1488DC19E915E21A597F1B
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: orange11-orange404.mynewserver.com
Sending IP: 185.29.25.171
From: info@lstc-lb.com
Subject: Re: Re: Re: New Order
Attachment: New Order.zip (contains "New Order.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2020-06-15 05:38:10 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 0fa91b5908e67e139b25b626a047da5ab3003187d0b22ccad00cce2e503a350f

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments