MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fc1f390e22dcce4ac08458bc9b8c9f44c83a347102d79aee65d95695e0c34cba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fc1f390e22dcce4ac08458bc9b8c9f44c83a347102d79aee65d95695e0c34cba
SHA3-384 hash: 63b831d175f158e0d2d4313aeb13fa47f749e179bea6d65e01e929fc085d2636d36d8cfb62e511c2cf97dd016f30bbd1
SHA1 hash: a41f4eb02ab0603cccafadd8cb9e63108549a40e
MD5 hash: b368e8f189aedab2759464e66d690b81
humanhash: pennsylvania-juliet-black-oxygen
File name:Purchase-order_62297.rar
Download: download sample
Signature Formbook
File size:279'403 bytes
First seen:2020-05-14 11:21:31 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:mVqawwoWT0G2rHwWBherQ6OrNs8gogaz3oxi0u7pP+:ra1jTAkWBhQQ3Ngogaz3oxi0uV+
TLSH 79542388A208F11229E1C91F346724FA278EDFF4A51EE2A70D3C3772B7851D6A9573D1
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: mout-xforward.gmx.com
Sending IP: 82.165.159.131
From: egarcia@planetmail.net
Subject: Re: Re : Purchase-order_622978
Attachment: Purchase-order_62297.rar (contains "Purchase-order_62297.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-14 11:36:23 UTC
File Type:
Binary (Archive)
Extracted files:
13
AV detection:
18 of 31 (58.06%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar fc1f390e22dcce4ac08458bc9b8c9f44c83a347102d79aee65d95695e0c34cba

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments