MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0197d075a81601f972b144b529ce29ad60272682b4520509a9bb4c6ec94ce303. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 0197d075a81601f972b144b529ce29ad60272682b4520509a9bb4c6ec94ce303
SHA3-384 hash: 06414543435daec3d7a2758d001bfa63808cfed57dd573255b07c65cb4468dd4a22c93cf0b49b44c51f814e5361d0536
SHA1 hash: d9033667fabbedcbea104fb58183c7e4d103488a
MD5 hash: 369e1ddf130fc93260ed106ab9b689f9
humanhash: lake-fruit-arkansas-golf
File name:Swift Copy.7z
Download: download sample
Signature FormBook
File size:241'926 bytes
First seen:2020-05-27 08:32:56 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 6144:kbjxhzVQsIiJacqnQ36mQqC8HDLSCfHQTA8SQY534s:kbjPiVgacsQKmxC4nrH/x
TLSH 403423916B6091AFF6D5BC131264A4800396EA5BD6E75B1D418CFB62EEB6033D3C630D
Reporter abuse_ch
Tags:7z FormBook


Avatar
abuse_ch
Malspam distributing FormBook:

From: howell@georgetexidor.com
Subject: Swift Copy
Attachment: Swift Copy.7z (contains "Swift Copy.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-27 04:19:08 UTC
File Type:
Binary (Archive)
Extracted files:
8
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

7z 0197d075a81601f972b144b529ce29ad60272682b4520509a9bb4c6ec94ce303

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments