MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 66c2f1ae37cc9aeff5f094ec8768835b92136369220c0f8e90858d3a25758fe1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 66c2f1ae37cc9aeff5f094ec8768835b92136369220c0f8e90858d3a25758fe1
SHA3-384 hash: 64d3687db556ebb7aff1e2de30345b11612a1c0e12877da7822e045c1b5ceec4e86efac0dd9114e8db724c268da8827c
SHA1 hash: 7bf3103ff2deb292d40359b03a3689740ed8f721
MD5 hash: 0107658b7feaa1e2879d606eb45ee2e5
humanhash: lake-florida-ceiling-nineteen
File name:Quotation-xls.rar
Download: download sample
Signature FormBook
File size:333'407 bytes
First seen:2020-05-19 06:05:46 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:iPAmT0oYh17qnnNp5I/kpnSX6z7VTFy0QJEjZIRgGLnJmjgcWTK6aqKh:iPFTTUSp5bSX6ztFSJysZIgih
TLSH FC642330F0D0B90E91C0524FD4ED7A8D169499A43B6FE2D8E13107A8D2EA6D81D1F9EE
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: cathay-food.co
Sending IP: 111.90.140.123
From: Felype Castro <massif@cytanet.com.cy>
Reply-To: massif@cytanet.com.cy
Subject: URGENT REQUEST FOR QUOTATION DATED2020-05-19
Attachment: Quotation-xls.rar (contains "Quotation-xls.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-19 06:36:50 UTC
File Type:
Binary (Archive)
Extracted files:
46
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar 66c2f1ae37cc9aeff5f094ec8768835b92136369220c0f8e90858d3a25758fe1

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments