MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0543e932e240ef324e36619739038d15cd3c3a31df9b3ca3222f5120cafe40bd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 0543e932e240ef324e36619739038d15cd3c3a31df9b3ca3222f5120cafe40bd
SHA3-384 hash: 29fff0a5f8a339b687f97bcf919d6c717ee54fefe4b51422dcc5ca0a95c5d0eaa41448dea9b410a9d8b702304863b15f
SHA1 hash: 06845cb630b8245bbc02f67e05ae4c50e737e453
MD5 hash: f75b3a05ea74e22b560604be700318a8
humanhash: twelve-connecticut-carolina-quebec
File name:PT300975-inv.xls.z
Download: download sample
Signature Formbook
File size:321'588 bytes
First seen:2020-11-26 06:40:30 UTC
Last seen:2020-11-26 12:20:21 UTC
File type: z
MIME type:application/x-rar
ssdeep 6144:5FiM3zvgQPxJbPiAIusvKksBR+ZqZZpPDRHvPzU5AqjkKjf2jDsL:5kMjZJJBIuPBR+ZKrpvPzGXOji
TLSH 666423C2EA56D3147924B10F82B163C4015A358AFAF6FA938DD79C2B961F862E13361D
Reporter abuse_ch
Tags:FormBook z


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: ton
Sending IP: 103.225.25.4
From: Jennifer <sales3@aalights.com>
Reply-To: sales3@aalightts.com
Subject: FW: All Outstanding Cleared
Attachment: PT300975-inv.xls.z (contains "PT300975-inv.exe")

Intelligence


File Origin
# of uploads :
2
# of downloads :
134
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.Razy
Status:
Malicious
First seen:
2020-11-26 06:41:06 UTC
AV detection:
9 of 48 (18.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

z 0543e932e240ef324e36619739038d15cd3c3a31df9b3ca3222f5120cafe40bd

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments