MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8a91915f32ed87bb6018a8c8feb3775531e4139f89d05bb28f1bf9ba93b1624f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 8a91915f32ed87bb6018a8c8feb3775531e4139f89d05bb28f1bf9ba93b1624f
SHA3-384 hash: e764540dd14e72bb0c44a50bc89932baa8b68e09a016317dd6187485302d80c2d73aaff03809d905e21b4bd7f6fc0c84
SHA1 hash: 2e11150709111ffaec5d05b6f2d8f91ec1617a9f
MD5 hash: 4e40b87de03efe2379211eea7f9dafa5
humanhash: early-lemon-utah-table
File name:August PO.zip
Download: download sample
Signature FormBook
File size:419'815 bytes
First seen:2020-08-17 06:11:20 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:3npiOU8xjlSIE4zRzWGjGtPV6ydDLl7fwp6JoIXUCm2bWP7NDlPFJ03GBWm:3nrU8RlSRgRxjGtvddWhBCmp7hbJ031m
TLSH 5E9423D7B60F1867C6828C908DE2553FE880568CB18EF0D0AF7AA56D2AD707750DB49F
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: 224104.cloudwaysapps.com
Sending IP: 45.32.188.150
From: Hassan. <ch.niklaus@niklaus-baugeraete.de>
Reply-To: agbeloirng@protonmail.com
Subject: Re:Order
Attachment: August PO.zip (contains "August PO.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-17 06:13:08 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 8a91915f32ed87bb6018a8c8feb3775531e4139f89d05bb28f1bf9ba93b1624f

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments