MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6e1785d1e2f41b68f044ca75e7977282c3850c294e32e62396082990c0188c53. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6e1785d1e2f41b68f044ca75e7977282c3850c294e32e62396082990c0188c53
SHA3-384 hash: b419e4ef0c58f2152ef0dfe87c486846c51cef25856d94daea70635c6ec349fa99f2974fd61c49ef340754cb614ffadd
SHA1 hash: 8066897f76064b5335571aea54673a9675f60f6d
MD5 hash: 0b670f959cd6fb9fb1bbf4d5a4bb2aeb
humanhash: fix-minnesota-ten-cardinal
File name:Scan_sLrV2FM07L8bRiU.zip
Download: download sample
Signature Formbook
File size:215'601 bytes
First seen:2020-07-02 07:54:11 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:GO1J0aeinIrN/rUWOYXu131GXka0e7vWthpTcpAvLIkmtthuyaMmFIdwUEDt81D+:GwWh6OXutorTOpxIkmtW/tFI+FJ8HJG
TLSH 75242299F3F59ADFE3B95399C80DDAA0ABFBE4875B9B221154F09FC201444935B9038C
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: lucky1.263xmail.com
Sending IP: 211.157.147.135
From: Lynn <jiong02@chjhdq.com>
Subject: Re:Re:Re:Re: Confirmation Order (SKYS1523-1742)【Suspected phishing email, please pay attention to password security】
Attachment: Scan_sLrV2FM07L8bRiU.zip (contains "Scan_sLrV2FM07L8bRiU.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-02 07:56:06 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 6e1785d1e2f41b68f044ca75e7977282c3850c294e32e62396082990c0188c53

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments