MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ef0276d29c0cfa16ddc1f8b615722b00c2306663cdc13c2fc8bdf54a5f353edb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ef0276d29c0cfa16ddc1f8b615722b00c2306663cdc13c2fc8bdf54a5f353edb
SHA3-384 hash: 0ee90a0795bbdf7bfaa225a3daedff2ccea2610c869e6fb9434e9669314a0c947b1e7bf72f4f7c01d02b12f497604169
SHA1 hash: 053d7ae98fa21a7bf96e681c9936b734348d2d98
MD5 hash: 15d02a40a1e54c8e04e32553478649f0
humanhash: double-california-uranus-finch
File name:Picture3.img
Download: download sample
Signature FormBook
File size:1'572'864 bytes
First seen:2020-06-28 07:33:38 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:LCcVhdV/AQxyzse6pqGWDO9xaAKWauiVre493eH:VDhqW/P4xI
TLSH 1875A062F3414937D5331B784C2B63986926BE112E2C58467FF89E4C6F3A7417C2A2E7
Reporter abuse_ch
Tags:FormBook img


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: slot0.oakwoodas.com
Sending IP: 45.95.169.32
From: Nicole Gapes<info@oakwoodas.com>
Reply-To: gapes.nicole@yahoo.com
Subject: Property Purchase & Leasing
Attachment: Picture3.img (contains "Picture3.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-28 07:35:05 UTC
AV detection:
16 of 31 (51.61%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

img ef0276d29c0cfa16ddc1f8b615722b00c2306663cdc13c2fc8bdf54a5f353edb

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments