MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3f7e84e602506931f1429c50dea18666d20851d26a083a7a8351d2360498dc66. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 3f7e84e602506931f1429c50dea18666d20851d26a083a7a8351d2360498dc66
SHA3-384 hash: 3deaa3c066db273127495cc01933d3daef7de572cc0739ac7d2799daf6b4a368b487e47ce9b4c3210736696c7ba0e46c
SHA1 hash: 80df39d15f8cbfe5c529c851f90e1ec162674a3a
MD5 hash: ec5bdc1349ab1d1fbc5d952d080f1fbf
humanhash: cold-timing-lithium-bacon
File name:RFQ.22.05.2020.rar
Download: download sample
Signature FormBook
File size:269'884 bytes
First seen:2020-05-22 13:55:02 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:lTvSg/b5yxfoWJitWLFSrbgwsohPhGMNg0t4Sa:lyxwW6WJSH33YMNg0t4Sa
TLSH AC44131DFAD75A9250185DFF0DEEEAFBA509FC7ECE45C916C1E78A24003AC8C0583926
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: vmi339081.contaboserver.net
Sending IP: 62.171.133.25
From: Cang Sales Manager (MULTI SERVICE LLC) <info@movingcargologistics.com>
Reply-To: smulti996@yahoo.com
Subject: products inquiry
Attachment: RFQ.22.05.2020.rar (contains "RFQ.22.05.2020.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-22 14:35:54 UTC
AV detection:
14 of 48 (29.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar 3f7e84e602506931f1429c50dea18666d20851d26a083a7a8351d2360498dc66

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments