MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 083a56cd6197597aae81782b47d6aaead5b6ec08245b6603845aaa425645dd1e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 083a56cd6197597aae81782b47d6aaead5b6ec08245b6603845aaa425645dd1e
SHA3-384 hash: 13a11048b472f1cee2483de800a1c9a20e4b3662f8f562a4e3a8e827eb40ea23d94689e2f97997a78531dc71b9477039
SHA1 hash: 419326e1d2c8aec89f59b796c6da57eb12c5acfa
MD5 hash: d625f80e4f8359aa969eef872133ad03
humanhash: london-pasta-nitrogen-undress
File name:счет-проформа pdf.zip
Download: download sample
Signature FormBook
File size:380'180 bytes
First seen:2021-04-21 16:14:19 UTC
Last seen:2021-04-21 16:19:24 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:5aBOoHI+pf3rFrsKiUY3IDKL1/iFyYl6jMt2pATgEyILjJaSQ5a68f4y9HcE:5aBZou9sK1Y3hLC6jM8GyIBaSR68wyCE
TLSH F18423DDD0F7C16DA767F2A1442CCCAC2AAA6D8E225851159721FBAE408F5D80E31CB7
Reporter cocaman
Tags:FormBook zip


Avatar
cocaman
Malicious email (T1566.001)
From: "sekretary <bogdanov_BY@mail.ru>" (likely spoofed)
Received: "from hs-1959.servidores-dedicados.es (unknown [82.194.90.139]) "
Date: "Thu, 22 Apr 2021 03:46:41 +1200"
Subject: "=?UTF-8?Q?=D1=81=D1=87=D0=B5=D1=82-=D0=BF=D1=80=D0=BE=D1=84?=
=?UTF-8?Q?=D0=BE=D1=80=D0=BC=D0=B0?="
Attachment: "счет-проформа pdf.zip"

Intelligence


File Origin
# of uploads :
3
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Downloader.Serokuping
Status:
Malicious
First seen:
2021-04-21 14:11:33 UTC
File Type:
Binary (Archive)
Extracted files:
10
AV detection:
24 of 29 (82.76%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 083a56cd6197597aae81782b47d6aaead5b6ec08245b6603845aaa425645dd1e

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
FormBook

Comments