MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 83b7a7bf23fa39eeab65f07a021bb708f3c173d29441213853015186f46cb703. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 83b7a7bf23fa39eeab65f07a021bb708f3c173d29441213853015186f46cb703
SHA3-384 hash: 68439f98519c24ae0f46d7b36546c98af935e0b88b1d2e80e360e29f707bbc44d8e00dddbed7120e67513c6fe017e9f6
SHA1 hash: f8b5af6629f58d9f4cab9a7d378f16e87e78ac94
MD5 hash: d89a2fa94fe740728bfc9c841556f534
humanhash: carpet-twelve-hotel-oven
File name:products inquiry.rar
Download: download sample
Signature FormBook
File size:217'085 bytes
First seen:2020-07-13 06:27:18 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 3072:ikwB7mGftdAIJoRoyGPkBIwgybeurzVlySH0TbGTCK0Zk98JYtbfEj2n//RKc:5q0IKROkkyb1lJ2jK38JYtDECn//0c
TLSH 2D24120B603559E180A9E36DDE55A68B2E37EF85CE3BDBE66444DA20035C9FF0164BC3
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: cust3.amsconsult.com
Sending IP: 180.250.103.13
From: Andrianto Maulana <andrianto.maulana@tokomodal.co.id>
Subject: Product required
Attachment: products inquiry.rar (contains "products inquiry.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Swotter
Status:
Malicious
First seen:
2020-07-13 06:29:03 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar 83b7a7bf23fa39eeab65f07a021bb708f3c173d29441213853015186f46cb703

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments