MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b6e5beb3b5ecd6117c5dc8dcd0223fc8465fcaac35222a0301d0bb9a5546cb6a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b6e5beb3b5ecd6117c5dc8dcd0223fc8465fcaac35222a0301d0bb9a5546cb6a
SHA3-384 hash: 920d70b9fcf39ce7ac8e323ee8270d0813b9ae6498b7592b34560a1e1284b40a52ac821fcc30d41b24a8f5b5623b3bd3
SHA1 hash: 849edd6f25cba03856d9f9cfe4f914aec21b69bf
MD5 hash: a3841b22060407a52e5127c0a0120574
humanhash: saturn-december-failed-fanta
File name:Attached is list of our purchase order.zip
Download: download sample
Signature FormBook
File size:514'542 bytes
First seen:2020-06-29 08:58:31 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:yPVzp6xXaMqPT9I0zXsEhay7ndpFzMnCAPyrgB2bGJByQV:ylMrqPpPLhay7naCAPyrg2GbPV
TLSH 75B4232C6E87BD6C62C0166E6CB7060A718DD37409E175DE09B06718EC9CBEAF623375
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: server.linux94.papaki.gr
Sending IP: 195.201.245.217
From: Nissos Kivittis <nissos.k@bwl.com.cy>
Subject: Re: Re: Re: Re: Order
Attachment: Attached is list of our purchase order.zip (contains "Attached is list of our purchase order.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Exploit.BypassUac
Status:
Malicious
First seen:
2020-06-29 09:00:12 UTC
AV detection:
11 of 48 (22.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip b6e5beb3b5ecd6117c5dc8dcd0223fc8465fcaac35222a0301d0bb9a5546cb6a

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments