MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0f62500183c45e1300fd51bf800fa7ef94d0cb4be11dc5c4e264d47ab315096b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0f62500183c45e1300fd51bf800fa7ef94d0cb4be11dc5c4e264d47ab315096b
SHA3-384 hash: 5e2ab9820c200f4f45bd2721fa2ffef0cb95ae1cc36422b075dbd6217aaca38287d6dae01bee3f88468c954c39f56213
SHA1 hash: 458bd1cb7d9a48fc2c51f22422169de90388ada6
MD5 hash: f4b0462ce74e2dc8e6350f619565443c
humanhash: early-steak-echo-vermont
File name:Payment Slip_GS2004011507 _ GS2005014760.pdf.arj
Download: download sample
Signature FormBook
File size:293'971 bytes
First seen:2020-06-30 06:03:16 UTC
Last seen:2020-06-30 11:41:36 UTC
File type: arj
MIME type:application/x-rar
ssdeep 6144:ssHDJ5aYTxdBegoJcvtJKAisVD9RIAqmqXLjiD:tHDJ5aYTxdUg7v7IU9RIAqXQ
TLSH CE54238686559CA1CA65014F1A99CFC88E1A4F1D57D71B7B81FFB0083830E89A7EC6F2
Reporter abuse_ch
Tags:arj FormBook


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: mail.emsbd.com
Sending IP: 202.40.181.229
From: ChinPhil Marine Services <s.juaniza@chinphil-marine.com>
Reply-To: s.juaniza@chinphil-marine.com
Subject: PAYMENT for Invoice GS2004011507 & GS2005014760 100% Deposit(OVERDUE DATE-06 MAY 2018)
Attachment: Payment Slip_GS2004011507 _ GS2005014760.pdf.arj (contains "Payment Slip_GS2004011507 & GS2005014760_pdf.exe")

Intelligence


File Origin
# of uploads :
2
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Swotter
Status:
Malicious
First seen:
2020-06-30 06:05:08 UTC
AV detection:
12 of 48 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

arj 0f62500183c45e1300fd51bf800fa7ef94d0cb4be11dc5c4e264d47ab315096b

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments