MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 06ea697012e1457cfd989366cd25932bc0b87d578155e918f5f31f478ac4dde5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 06ea697012e1457cfd989366cd25932bc0b87d578155e918f5f31f478ac4dde5
SHA3-384 hash: fb5dcdfd96101a1947c5ce26810ce71172d54a54e26a77c2f2568e320d39754ed98264ae8d9548b9f7b837f408d87b53
SHA1 hash: 26bfe095fdf0284f138665090f7d32c991df5d19
MD5 hash: 7fca206a8d994d624dc8538d55cc5f34
humanhash: enemy-saturn-lemon-cola
File name:PO FOR COVID-19 PRODUCTS.arj
Download: download sample
Signature FormBook
File size:15'403 bytes
First seen:2020-03-30 12:13:01 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 384:S8CejhFyx8c9LRil7ouyBSowjrEzHahlV:S8NjAV9Oouy09
TLSH 0462D0DAE3378619E52FCBA1C32F9FC2CD276D936A8C4239AB5247193070952D753409
Reporter abuse_ch
Tags:arj COVID-19 GuLoader


Avatar
abuse_ch
COVID-19 themed malspam campaign distributing GuLoader->FormBook:

HELO: mata.com
Sending IP: 173.82.151.178
From: Candice Medpace Medical Device B.V. <edyth@carrollndixon.us>
Subject: Purchase Order (PO For-COVID-19 Products) (contains "PO FOR COVID-19 PRODUCTS.exe")

GuLoader payload URL (FormBook):
https://drive.google.com/uc?export=download&id=1UY-m7ByYJgaXFwe_acHJZrBf3_z99-DK

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-03-30 12:35:25 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
15 of 47 (31.91%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments