MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 40519328e5690783cfc2b695315712675722442c18a882a2064e46d616092a77. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 40519328e5690783cfc2b695315712675722442c18a882a2064e46d616092a77
SHA3-384 hash: 1f173ac0053378d96f13554b0c0a7b1cd68e12d4cd3f5eb7bdb2625195aff6f69f33fd18ddfaea9df64b421d310749d1
SHA1 hash: 891745f239ca8da8bd1f6e5bc249536bb6d0784d
MD5 hash: 7495288c4aa0fb280f8e772fdd860e33
humanhash: ohio-eleven-mississippi-nevada
File name:CANAL PDA SUPPLIES RQT-pdf.arj
Download: download sample
Signature FormBook
File size:450'352 bytes
First seen:2020-05-27 05:12:05 UTC
Last seen:2020-05-27 05:41:11 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:2y/lAJ6/Prqgaf0QXepbvM8gE3lnjdMapPOfF:2y/lc6LDacTyEVjNNGF
TLSH 64A42342EFA60990CFEAF4D967F20C47E0CE99A42552D4D7C875F6385BCBDCC0A6A940
Reporter jarumlus
Tags:FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-26 23:30:35 UTC
File Type:
Binary (Archive)
Extracted files:
265
AV detection:
21 of 31 (67.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 40519328e5690783cfc2b695315712675722442c18a882a2064e46d616092a77

(this sample)

  
Dropped by
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments