MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7fdc2d9334b1b8e7db7783af34be5a0b687eb2a1924c0341bb25c1e2b01e0e9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b7fdc2d9334b1b8e7db7783af34be5a0b687eb2a1924c0341bb25c1e2b01e0e9
SHA3-384 hash: a8ee17c3032e8201e6b998e0d8b6afbd67635ea6f25c8d7a4ff39ca1edd8770200aee28e4e3feef0b7caa89162be93cc
SHA1 hash: 3e67222e26bc9461bafa08804aa35c17168b9708
MD5 hash: f29e6522253cf741b927633fb5f5e47a
humanhash: romeo-lake-echo-six
File name:Inquiry.zip
Download: download sample
Signature FormBook
File size:485'462 bytes
First seen:2020-07-05 07:20:01 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:m+9j8fJXsytN0QN+4YbnCwixWapcq0qd32s:mWjW8yP0QN8bs1KAR
TLSH 43A4239CA31BBAAA61097F5FC1FC4B5105EB2D206ABDCF67782413A8187E1C0DD39865
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: mx1.toucamail.com
Sending IP: 91.99.103.189
From: IBCCO-Commercial <supply@ibcco.midhco.com>
Reply-To: IBCCO-Commercial <supply.ibccomidhco@protonmail.ch>
Subject: Fwd: Draft of Proforma Invoice for IBCCO
Attachment: Inquiry.zip (contains "Twsukkd.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-05 07:21:05 UTC
AV detection:
14 of 48 (29.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip b7fdc2d9334b1b8e7db7783af34be5a0b687eb2a1924c0341bb25c1e2b01e0e9

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments