MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b6998cb14c536827f5ee6c4ad2b3c74ed0fb2a3e28a5f4f1b132d8918e47f0a7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b6998cb14c536827f5ee6c4ad2b3c74ed0fb2a3e28a5f4f1b132d8918e47f0a7
SHA3-384 hash: 96a29229101e0d58091579de2cedf53fbd3f11ded0ef3113853a6c267eb2e6526854172891f91b993299bb38544a02ee
SHA1 hash: 729278ea30b756c9aed6bbfeb60a0d7a98600fe8
MD5 hash: 4deadfceef6d525b206699982540a3ba
humanhash: fanta-stream-quiet-glucose
File name:PO8973274.zip
Download: download sample
Signature Formbook
File size:273'191 bytes
First seen:2020-07-01 17:53:52 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:w+3tgffLZaXsSdr8wCX/7H4u4LdyBZvy155wNkijC:ndiTZaXxdr8wCXjYu4LdyQ5mZC
TLSH 0B4423EDC05DB9B49ED559023F9CA81D2DDDD6A8F3FDB834EB700405844AA99B0C92E8
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: regular1.263xmail.com
Sending IP: 211.150.70.202
From: 巩腊梅 <julie@ebiltech.com>
Subject: Re:new order
Attachment: PO8973274.zip (contains "PO8973274.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-01 17:55:04 UTC
AV detection:
7 of 48 (14.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip b6998cb14c536827f5ee6c4ad2b3c74ed0fb2a3e28a5f4f1b132d8918e47f0a7

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments