MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 68ac6f0ad7bce72b24cd1ed92e0ddeace4268c51281bfe030c4b8c3f38af6ec7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 68ac6f0ad7bce72b24cd1ed92e0ddeace4268c51281bfe030c4b8c3f38af6ec7
SHA3-384 hash: e83a3484bd45f9a02f7e949037cdd0a9ce452efbe47dd3da158f6419e8c0a75e5c959fb1d173fa9228525cf8141e48b5
SHA1 hash: 15d1c8954c852f8da67155aef5edd9a36a3b0799
MD5 hash: 50adff2b73c2d25ac4a3a40086f8cc18
humanhash: apart-magazine-speaker-skylark
File name:KRD2020000000002 PDF.zip
Download: download sample
Signature FormBook
File size:495'704 bytes
First seen:2020-07-29 10:32:07 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:5vLBQMs74KQrd9qRFZUhYpwkh369izhKsAqULZkIu6K:5vLBJsGqRFVpPE9Q7AplkIu6K
TLSH E0B42373D190BF8A6471A015E1543CC8FDF504E69738BA290E7BE2C718B7A3C195B86A
Reporter abuse_ch
Tags:FormBook geo TUR zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: www.inviva.com.tr
Sending IP: 185.135.222.66
From: arif@ozanadolu.com
Subject: 28.07.2020 tarihli, 872 TRY tutarlı, KRD2020000000002 numaralı faturanız
Attachment: KRD2020000000002 PDF.zip (contains "KRD2020000000002 PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Swotter
Status:
Malicious
First seen:
2020-07-29 10:34:06 UTC
AV detection:
25 of 48 (52.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 68ac6f0ad7bce72b24cd1ed92e0ddeace4268c51281bfe030c4b8c3f38af6ec7

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments