MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b13501e945916887127724be4cc8e8aaed8e0a2c50d6ef77949e6a746ec58124. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b13501e945916887127724be4cc8e8aaed8e0a2c50d6ef77949e6a746ec58124
SHA3-384 hash: 481dbb7a271751691e02ecb189c60a7ce88752792abd61338b275c3ac14277ca865b19eb02dee080f406df8bd1bd8b5f
SHA1 hash: d11cd250c7412b8874905c9b18e2c91af866c4e7
MD5 hash: 10346ef677f04ca45500e134fded332c
humanhash: grey-echo-hawaii-bravo
File name:Bank letter for SOA Payment pdf.zip
Download: download sample
Signature Formbook
File size:483'991 bytes
First seen:2020-04-20 14:24:16 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:ylGooyTdbXUs1gZQD7by1tKfb/WVWQuiUz7SvD8iitt:ZObUsCZQotkLn8vIh
TLSH A2A4230D3D62DD2BF4BF93BA0A8451A87E7318854AF97EC06A27F1D49D8B84CE04D05B
Reporter abuse_ch
Tags:COVID-19 FormBook zip


Avatar
abuse_ch
COVID-19 themed malspam distributing FormBook:

HELO: dias.adhoc.gr
Sending IP: 188.40.170.194
From: Daeho Shipping Co., Ltd. <joanne@borneodream.com>
Subject: RE: Delayed SOA Payment Due To COVID-19 Situation,
Attachment: Bank letter for SOA Payment pdf.zip (contains "Bank letter for SOA Payment pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-20 01:16:28 UTC
File Type:
Binary (Archive)
Extracted files:
51
AV detection:
29 of 48 (60.42%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip b13501e945916887127724be4cc8e8aaed8e0a2c50d6ef77949e6a746ec58124

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments