MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ea53473f2d34f3f4be44753b59ea19bc4644020e8bfa04fbb0185d17e64d7999. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ea53473f2d34f3f4be44753b59ea19bc4644020e8bfa04fbb0185d17e64d7999
SHA3-384 hash: fa958432ba7c263f346924f713120bd4d7adc84dae6a8317e427d8e98b13d1b330641801e06ad4e7d04e0d910e4ac0f1
SHA1 hash: 615081e04eacd0da5c55438eb966df38c991287f
MD5 hash: 5db10ffbcfa2755ca1c1415f82564967
humanhash: three-ohio-magnesium-oven
File name:S01 Enq0423 28_PDF.zip
Download: download sample
Signature FormBook
File size:511'256 bytes
First seen:2020-05-13 06:18:12 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:5el2n1KCv+PaPF37CC90M0hfQmavY84lHPm9gXiEslCfgco:jYC2+770hfeyPj3skBo
TLSH 88B423E19F6AA4544AA836838DCC59994C008FA0FABD5F42C7168F0B98FF5B61F1743D
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: hostdetrazos.es
Sending IP: 188.164.198.15
From: Sales | Hart Middle East <sales@hartme.ae>
Reply-To: Sales | Hart Middle East <jessivafi@gmail.com>
Subject: Quotation for S01 Enq0423 28
Attachment: S01 Enq0423 28_PDF.zip (contains "S01 Enq0423 28_PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-13 06:37:20 UTC
File Type:
Binary (Archive)
Extracted files:
294
AV detection:
26 of 48 (54.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip ea53473f2d34f3f4be44753b59ea19bc4644020e8bfa04fbb0185d17e64d7999

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments