MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a32c7844a85667f80575a05c422034340f08d167fe5962b0ec9e6d268b1b7451. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a32c7844a85667f80575a05c422034340f08d167fe5962b0ec9e6d268b1b7451
SHA3-384 hash: 1442ee50d35bf4dd75262edd2fe1e221598ed06b9e9fd715ce6fc342e6d2b1a7418969579eb27d8c3aa72e6c2b1b135d
SHA1 hash: 839171850eedea8753d95ad7fddbe14aabd33632
MD5 hash: b20493fecc1eba05003333b66aba391b
humanhash: spring-video-shade-mirror
File name:Mqrkjnc.rar
Download: download sample
Signature FormBook
File size:466'091 bytes
First seen:2020-06-29 12:30:08 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:TXaSzsf4pcrwbung0ChjaSAF8Sirr5CZg/:TKFwbug9h+Z2SirFCZg/
TLSH 4BA423A9B7DBBBED4000BB20E2B746740539DDCEB7068A138A955ADD4C3372365635C2
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: mail.hotspotzavar.sk
Sending IP: 185.98.208.2
From: Mumtaz Ahmed<test@hotspotzavar.sk>
Reply-To: <Elandapos_Eric@163.com>
Subject: Re: Order Confirmation
Attachment: Mqrkjnc.rar (contains "Mqrkjnc.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.BestaFera
Status:
Malicious
First seen:
2020-06-29 12:32:05 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar a32c7844a85667f80575a05c422034340f08d167fe5962b0ec9e6d268b1b7451

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments