MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 998054c2fd09143ef422cfb952491ecb0e456c61ae22bbc8ad17eaf3ef2871f5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 998054c2fd09143ef422cfb952491ecb0e456c61ae22bbc8ad17eaf3ef2871f5
SHA3-384 hash: e574f3c7f24cefd76f61060f55cda0f9eee4712cb3fc285afa80392b0a854b425392b75e33115a614fb957d688429525
SHA1 hash: 8ee2b69b5db8a63f14447b43c65bda7c6b18537c
MD5 hash: 366a64a3956b641c5601ce3b2eb7d7d2
humanhash: fruit-jupiter-river-timing
File name:PAYMENT INSTRUCTION.zip
Download: download sample
Signature FormBook
File size:258'390 bytes
First seen:2020-05-11 06:32:18 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:vrkAogl7BuKRcYbhpvP1fLb3Il3p/eOg9sVK:R/lk+rpb3CXg9MK
TLSH 894422090F9FBDE0E3DC609869DC6253D5017B805240EE9E9AAF1EE7B730F1E14E94A0
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: vps.dailycom.com.my
Sending IP: 162.144.148.93
From: Finance Dept <sales@sellerbulknewsservice.live>
Subject: PAYMENT INSTRUCTION
Attachment: PAYMENT INSTRUCTION.zip (contains "PAYMENT INSTRUCTION.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-11 06:35:34 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
22 of 31 (70.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 998054c2fd09143ef422cfb952491ecb0e456c61ae22bbc8ad17eaf3ef2871f5

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments