MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c66ea75e3bcbbd23e40db565c6766ef5f8cd41bc00dc3fd0fbbbc45483670bfb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c66ea75e3bcbbd23e40db565c6766ef5f8cd41bc00dc3fd0fbbbc45483670bfb
SHA3-384 hash: 48a281a2c051f4bda201b9695e6455082f91c5f784817511ecbb6e306a0b2c536aade27a7f3183efc3f647c16c7fda2b
SHA1 hash: 5b5da7cac01a94ebc79985ba0ee87d99c8443fd5
MD5 hash: 3e4b5559edefd0d92327bb672f1be319
humanhash: enemy-batman-xray-shade
File name:offer.zip
Download: download sample
Signature FormBook
File size:393'401 bytes
First seen:2020-08-13 11:10:54 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:ayEgabetPoCC986igMR0B51YrCwIxQWorr/R3hzM5:anUPoVn80lYrHv9xy
TLSH 978423ECF08E3F250ACAFB6BFDBBE0DBA14D0596506C7473B84742911B779D81166288
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: profesionalesenriesgo.com
Sending IP: 50.115.112.102
From: Adrian Zlate <lnino@profesionalesenriesgo.com>
Subject: requested offer
Attachment: offer.zip (contains "offer.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-13 11:00:34 UTC
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip c66ea75e3bcbbd23e40db565c6766ef5f8cd41bc00dc3fd0fbbbc45483670bfb

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments