MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fe4c3440aa06ea22895d8021e17a528d2698f18fdf8b687930319050f91d289c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: fe4c3440aa06ea22895d8021e17a528d2698f18fdf8b687930319050f91d289c
SHA3-384 hash: 353eb55ac11db044872cade717dc8a4c3b4e0ba57bab3efb6e55da229da86cc73058db3f1ef4c405fa82c523334003a7
SHA1 hash: 874193126ef8de6aaf81746ad2e31884c6523817
MD5 hash: c5851d66732990dc928aac8cb2f8f33c
humanhash: ohio-delaware-maryland-monkey
File name:Shipping document.pdf.arj
Download: download sample
Signature Formbook
File size:408'037 bytes
First seen:2020-08-18 13:27:29 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 12288:XMlRwO9BmhsVTgfJrE+fTJnD5vhP/81/+:XMvwO9BmLfVffTxDVhPEA
TLSH 1F942329AA7D03316EF1C5D73D0FE154688A865F082C2E1566996EBA14FCC0D787F362
Reporter abuse_ch
Tags:arj FormBook


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: qaysarpizza.com
Sending IP: 173.236.86.67
From: GOLDSPRING CO., LTD. <operation@goldspring.com.hk>
Reply-To: operation@goldspring.com.hk
Subject: Shipping documents
Attachment: Shipping document.pdf.arj (contains "Shipping document_pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-18 13:29:05 UTC
AV detection:
33 of 48 (68.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

arj fe4c3440aa06ea22895d8021e17a528d2698f18fdf8b687930319050f91d289c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments