MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ac48d8b2ef799eb1841b28bb0c954b932547599f8798cf88334d4db9847ba24e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ac48d8b2ef799eb1841b28bb0c954b932547599f8798cf88334d4db9847ba24e
SHA3-384 hash: 6616b520403eedd8cc74aeca1a96baffe6aeea3ebe59a61f138861f58f837456e8f38a1eb6e17a8c72457921049c1953
SHA1 hash: db8a9e597a3051095d7c5bb8e914b5e5a9b83e28
MD5 hash: 0b90c30b7c44a7a194d19e226245ab5c
humanhash: earth-fourteen-yankee-network
File name:attachments.zip
Download: download sample
Signature FormBook
File size:267'740 bytes
First seen:2020-06-12 09:48:25 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:8IVo2+66osRWGE9TEQanrCUB0Lq4gwYEZm1+7lxZqVX7r:8Ii2+6LsR1E9TErCsPwYEbuXf
TLSH 82442347C6B88A77D941FD233B08B7E5524923803DEA26E0EF4831A961C6F7831957E7
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: victim-domain
Sending IP: 193.142.58.27
From: victim-email
Reply-To: wiz2018@bk.ru
Subject: Fw: 2020 Latest Company Memo / Circular
Attachment: attachments.zip (contains "2020 Latest Company Memo Circular.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-06-12 09:50:11 UTC
AV detection:
23 of 48 (47.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip ac48d8b2ef799eb1841b28bb0c954b932547599f8798cf88334d4db9847ba24e

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments