MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c51c6c0429b3fbf8f41cb77350efb4c24a989934822957a97e6f39dbbfc1e0f5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c51c6c0429b3fbf8f41cb77350efb4c24a989934822957a97e6f39dbbfc1e0f5
SHA3-384 hash: 6db6a531c21c6919133357092386eef4bbbc4ae3be632f38e94d30e63cf0bc66de5234b20a67d13bc2b110013b74aab8
SHA1 hash: 3a2a0c77dc5cfd75174cdb750236efb4b173766f
MD5 hash: fbaae15cff2328b2934990bd59bd49c4
humanhash: cola-uncle-colorado-neptune
File name:New Order,.zip
Download: download sample
Signature FormBook
File size:287'408 bytes
First seen:2020-06-22 06:16:52 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:IttVatLU/V4zCl+LHsbnmGDLb9X59BQxSHx+hHKVLH1c:IttcO+zvMnvjR+hqpW
TLSH 975422B7356AAC10FEE18233963BE4F5CAA9C47F02E33E79921841897A41E4F7D051E5
Reporter jarumlus
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Swotter
Status:
Malicious
First seen:
2020-06-22 06:18:04 UTC
AV detection:
21 of 47 (44.68%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip c51c6c0429b3fbf8f41cb77350efb4c24a989934822957a97e6f39dbbfc1e0f5

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments