MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c3b5dbd271b8f701857d730998df493fb0e9aaa622b6fe89b9c85a0d3adab187. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c3b5dbd271b8f701857d730998df493fb0e9aaa622b6fe89b9c85a0d3adab187
SHA3-384 hash: 9d2a2a81e178eaeafc49991dc70cbeb2c3d92bc4e08ce39bf3c8e889cb1b6c84b4d4d68efbfe0aaefdff7276ea092054
SHA1 hash: f83f7f501c858398fdb7ecdd2850e76a9fe35308
MD5 hash: a1ef01a276d390ae1aba8d07c1413f54
humanhash: equal-princess-queen-virginia
File name:request for quotation and samples Nos 0708090504 0692168035 0567034016 0607089403 0506079436.gz
Download: download sample
Signature Formbook
File size:416'076 bytes
First seen:2020-08-13 11:40:56 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:Qzldw5E5UPzr9yc9e10PUk4ToYbeSMdVXYOzTgt:ylkEkzQ08NEfSSLw
TLSH CD9423E4E97C12595E1220D9CF91BE70128163BCCD9FA4E85E0A7DBE060A23D77620CF
Reporter abuse_ch
Tags:FormBook gz


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: itrad3r.com
Sending IP: 78.47.220.153
From: Inquiry | Mkinn Trading <inquiry@mkinn.com>
Reply-To: info.chematek@gmail.com
Subject: ORDER
Attachment: request for quotation and samples Nos 0708090504 0692168035 0567034016 0607089403 0506079436.gz (contains "request for quotation and samples Nos 0708090504 0692168035 0567034016 0607089403 0506079436.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Taskun
Status:
Malicious
First seen:
2020-08-13 11:42:06 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip c3b5dbd271b8f701857d730998df493fb0e9aaa622b6fe89b9c85a0d3adab187

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments