MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bc1491b8a210fa777e620200832f4e533fd7ca6ede637b8e6c81d1e0a4786aca. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bc1491b8a210fa777e620200832f4e533fd7ca6ede637b8e6c81d1e0a4786aca
SHA3-384 hash: 0267157d520f490f8d9f2c7ae9d7982a86ebbd3fc7dbcc7746b3602e193cb18a69a2d1784bc02b95c9f83c17775f3033
SHA1 hash: c6d2586a0557914a98758b259ea2559bdce64efc
MD5 hash: c4f109bdf99a3b49c712257e9903c43b
humanhash: sad-pip-alpha-nuts
File name:Pay Day.r11.zip
Download: download sample
Signature FormBook
File size:257'706 bytes
First seen:2020-06-17 10:08:37 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:HT3PZ5sT2jsPYSlSpV1tvioApwCXYjQz3zYcfHrH3yfc2A8JApH+f:HzPZyZJlSj1tvQpw70VPLyk2A8qHS
TLSH 424423AB4D628C3321C1B67ED0DDE3641A806E4713DDFD2AA185537199C9BCFCB6E4A0
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: dunjimwa.com
Sending IP: 167.172.124.42
From: Miss. Jen Scannell <info@dunjimwa.com>
Subject: Payment Day
Attachment: Pay Day.r11.zip (contains "Pay Day.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Bluteal
Status:
Malicious
First seen:
2020-06-17 10:37:21 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip bc1491b8a210fa777e620200832f4e533fd7ca6ede637b8e6c81d1e0a4786aca

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments