MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ea02015ebbadefdbc7d4e33ab4982ef6db3cfe2ed42f19e8bef70358e219ec2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ea02015ebbadefdbc7d4e33ab4982ef6db3cfe2ed42f19e8bef70358e219ec2f
SHA3-384 hash: 346ea74ff38b9fceb43a579a46f872b3a4ddadf65b62b43ab7462a3773d5641c64bd433e773b42ec64f7310d7fa5d203
SHA1 hash: be0b892fded59755957b6dcf70ac7c4f87dd7906
MD5 hash: 119ede5d5ee880f593d56a1d1ed1c1db
humanhash: muppet-emma-eleven-colorado
File name:SWIFT COPY.zip
Download: download sample
Signature FormBook
File size:385'838 bytes
First seen:2020-05-05 07:40:46 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:ZgNkd5Rg4ZtwGLV1ih9EeoDTgM8UJWuQamKzKaDY8OPad7OPwDYp/Ma4gnhc80ta:7jNY1PkFWBcz7TmOKwDVvcZL9F
TLSH 87842382C516950AFAB3A293BBDF6C044ED0C0C2B60735FE573805526A5B9A79037EE2
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: winghin.com
Sending IP: 38.68.46.250
From: tkteoh@winghin.com
Subject: ! payment (Bank Copy)
Attachment: SWIFT COPY.zip (contains "SWIFT COPY.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
91
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-05 08:36:32 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
20 of 48 (41.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip ea02015ebbadefdbc7d4e33ab4982ef6db3cfe2ed42f19e8bef70358e219ec2f

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments