MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 83d2b579e4bca53955f5147e0ab5208cdb10d05d2ebee44fdd237ee84caeddcf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 83d2b579e4bca53955f5147e0ab5208cdb10d05d2ebee44fdd237ee84caeddcf
SHA3-384 hash: dc17b922373ddc30e2bfc856a3e1410c459de70f36381dcb4745673f2617dd24e4c0c81f2dff2ca89b6f76a508f791f3
SHA1 hash: eb8c8eaaac871a6aef95dd081c25c9ab4728cd78
MD5 hash: 67a6c8c3a7366acc16de77924df7c31f
humanhash: happy-tango-louisiana-neptune
File name:PO-0810044-09-pdf.arj
Download: download sample
Signature FormBook
File size:402'207 bytes
First seen:2020-05-20 05:53:51 UTC
Last seen:2020-05-20 09:07:24 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:E3Oy8GNiIBfS0ByadvPlfqqtDnuzvDQijBrzFV:W8GNiiDTvPRqqtjuTDZ5b
TLSH 6A84232E44880A17F7DA57687F832C010E3B3FACBE553B61513570A460E52C79EF6D96
Reporter jarumlus
Tags:FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-20 04:44:42 UTC
File Type:
Binary (Archive)
Extracted files:
294
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 83d2b579e4bca53955f5147e0ab5208cdb10d05d2ebee44fdd237ee84caeddcf

(this sample)

  
Dropped by
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments