MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 083a56cd6197597aae81782b47d6aaead5b6ec08245b6603845aaa425645dd1e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
FormBook
Vendor detections: 5
| SHA256 hash: | 083a56cd6197597aae81782b47d6aaead5b6ec08245b6603845aaa425645dd1e |
|---|---|
| SHA3-384 hash: | 13a11048b472f1cee2483de800a1c9a20e4b3662f8f562a4e3a8e827eb40ea23d94689e2f97997a78531dc71b9477039 |
| SHA1 hash: | 419326e1d2c8aec89f59b796c6da57eb12c5acfa |
| MD5 hash: | d625f80e4f8359aa969eef872133ad03 |
| humanhash: | london-pasta-nitrogen-undress |
| File name: | счет-проформа pdf.zip |
| Download: | download sample |
| Signature | FormBook |
| File size: | 380'180 bytes |
| First seen: | 2021-04-21 16:14:19 UTC |
| Last seen: | 2021-04-21 16:19:24 UTC |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:5aBOoHI+pf3rFrsKiUY3IDKL1/iFyYl6jMt2pATgEyILjJaSQ5a68f4y9HcE:5aBZou9sK1Y3hLC6jM8GyIBaSR68wyCE |
| TLSH | F18423DDD0F7C16DA767F2A1442CCCAC2AAA6D8E225851159721FBAE408F5D80E31CB7 |
| Reporter | |
| Tags: | FormBook zip |
cocaman
Malicious email (T1566.001)From: "sekretary <bogdanov_BY@mail.ru>" (likely spoofed)
Received: "from hs-1959.servidores-dedicados.es (unknown [82.194.90.139]) "
Date: "Thu, 22 Apr 2021 03:46:41 +1200"
Subject: "=?UTF-8?Q?=D1=81=D1=87=D0=B5=D1=82-=D0=BF=D1=80=D0=BE=D1=84?=
=?UTF-8?Q?=D0=BE=D1=80=D0=BC=D0=B0?="
Attachment: "счет-проформа pdf.zip"
Intelligence
File Origin
# of uploads :
3
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Link:
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Downloader.Serokuping
Status:
Malicious
First seen:
2021-04-21 14:11:33 UTC
File Type:
Binary (Archive)
Extracted files:
10
AV detection:
24 of 29 (82.76%)
Threat level:
3/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Tinba
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Dropping
FormBook
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.