MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a36125e8a672710a0463832718e10bbce9fc7d83daeb5245fcaa7440ca1849f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 4a36125e8a672710a0463832718e10bbce9fc7d83daeb5245fcaa7440ca1849f
SHA3-384 hash: f7fc66ee87bd52b761465438a21be7bb3122b37365399d1295d69242c53d19b63d29449376c0a93c644c426e097d6763
SHA1 hash: a414694b9acc6c579b20d4a32527cf629552bbdc
MD5 hash: 087218c54216a626d5c871dec97a57f7
humanhash: vegan-red-four-saturn
File name:ORDER.exe
Download: download sample
Signature FormBook
File size:1'038'336 bytes
First seen:2020-06-11 13:54:43 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash fcc3385bbfaa041b46f4c7dd3ce950cb (2 x FormBook, 1 x RemcosRAT)
ssdeep 12288:6vBHy1WX0ArqyGdps0QYkZ9n/nJzVEYAX9o+6cHS40jatI2gG3cRUngfMzS:6vvkUXGdp9Qf9n/ZmYKW0yGtIW3nuM
Threatray 89 similar samples on MalwareBazaar
TLSH AE258F26F2918837C1232A3D9C1B97BCAD25BF502E2868877BF55D4C8F397813939197
Reporter abuse_ch
Tags:exe FormBook


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: poydorus.t.mk
Sending IP: 195.26.152.36
From: deni@bomi10.com.mk <deni@bomi10.com.mk>
Subject: Re:Re: New Order
Attachment: ORDER.rar (contains "ORDER.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Backdoor.Remcos
Status:
Malicious
First seen:
2020-06-11 13:56:11 UTC
AV detection:
26 of 31 (83.87%)
Threat level:
  5/5
Result
Malware family:
modiloader
Score:
  10/10
Tags:
family:modiloader
Behaviour
Script User-Agent
Legitimate hosting services abused for malware hosting/C2
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

Executable exe 4a36125e8a672710a0463832718e10bbce9fc7d83daeb5245fcaa7440ca1849f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments