MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 637073642bda3275e0047ae8e09d7ef51537d400fa5f53931db9d22f2287cff7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 637073642bda3275e0047ae8e09d7ef51537d400fa5f53931db9d22f2287cff7
SHA3-384 hash: 03c6f845fa9dddb3aa364a905e867c30e83118371b21dc21a0b8d0a2a5f8b3a6d8d2abe5ffe9720de39975a1e96b1ffd
SHA1 hash: be044e63dbbc100bb07d58ea2605e24f6576a077
MD5 hash: 9bfaf22877d99dc0f8b0b2d9edc88225
humanhash: potato-magnesium-moon-shade
File name:Document2.img
Download: download sample
Signature FormBook
File size:1'245'184 bytes
First seen:2020-07-09 07:47:56 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:51uSw3tWopwOdOGakJ1olUL+zUQJ75wQnGateqDaitL8SU:5kx308tOGakJ1gh4QJdwQGMxDaML8SU
TLSH 79457D52F6C09877D02B1A7D8C5FD664683ABE052D24D84A3ADA7E0C4FF6341343B69B
Reporter abuse_ch
Tags:FormBook img


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: slot0.sapoibest.com
Sending IP: 45.95.169.186
From: Ryan Todorovich <info@sapoibest.com>
Subject: Urgent
Attachment: Document2.img (contains "Document2.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Ymacco
Status:
Malicious
First seen:
2020-07-09 07:49:04 UTC
AV detection:
17 of 28 (60.71%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

img 637073642bda3275e0047ae8e09d7ef51537d400fa5f53931db9d22f2287cff7

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments