MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 27fe8f5e23c268d3ea03fa5e5977ea73e7297ab2e8ab42f2f76a48830a0a989d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 27fe8f5e23c268d3ea03fa5e5977ea73e7297ab2e8ab42f2f76a48830a0a989d
SHA3-384 hash: 097fa51372c02c168e5a0e217ed5e00e2ae4faa42922dcd2695f0a64d89b0c694e8dac0622093a53ef545c23ba57c696
SHA1 hash: 29b8c009fe4a977bf73ddb2bd23348a370466342
MD5 hash: 670833accac4f514d63df0b0795b6424
humanhash: gee-wyoming-william-georgia
File name:WHITE SPIRIT MSDS_pdf.rar
Download: download sample
Signature FormBook
File size:731'648 bytes
First seen:2020-06-18 05:27:31 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:zrYV4uANZqTM3dB/GO+c/yR+VDIUNmyfY201hBInkTfe8AfnI4u+MxMawtK6MilZ:zNueqTMjJ+cfVIoH01AJ8MnJtjtcBQ
TLSH 3FF43354C68E2ABBCA2D235BC07C8BB2BA24426F65B3E011321CDF515FFB31576E4468
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: server1.bluecloud.jo
Sending IP: 81.95.158.149
From: Seacon Shipping Co.,Ltd <edison@seaconshipping.com>
Reply-To: edison@seaconshipping.com
Subject: Re: Request for quote - Nagoya/Japan
Attachment: WHITE SPIRIT MSDS_pdf.rar (contains "WHITE SPIRIT MSDS_pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Predator
Status:
Malicious
First seen:
2020-06-18 05:29:04 UTC
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar 27fe8f5e23c268d3ea03fa5e5977ea73e7297ab2e8ab42f2f76a48830a0a989d

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments