MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 100c3429e7073073fadce72bea60073986c25b7a05b9e7829ae50a81d99db875. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 100c3429e7073073fadce72bea60073986c25b7a05b9e7829ae50a81d99db875
SHA3-384 hash: 90520e1efc8282e29bb5a31fae11dfcd45d6a4860af702f54ec9787af04203fff9186db6bcf060a9f9e6af6617186f6f
SHA1 hash: 1b3de416bed15c08ef24808cb204997a5942b358
MD5 hash: d279821d397fc78397f79cdc8c1d8f49
humanhash: ohio-hot-romeo-louisiana
File name:Payment Copy.zip
Download: download sample
Signature FormBook
File size:479'591 bytes
First seen:2020-08-17 09:22:32 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:YjtYV/3rfx3TMicmYIJTSMrmeONTzBTZWegMp/VcdWqHyZcDAo2EM80CAgNsM+o3:d/3r9oAlSMrmVFgMZiWIwFK+MvavY
TLSH 61A42360921013F0D35FE5473A78E0659B0859369039D6E38BE83743B993DF7CE9A98D
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: incloud.knpinfotech.in
Sending IP: 23.235.195.193
From: service6@puritawater.com
Subject: TT Payment
Attachment: Payment Copy.zip (contains "gregcrypted.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.FormBook
Status:
Malicious
First seen:
2020-08-17 09:23:05 UTC
AV detection:
24 of 29 (82.76%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 100c3429e7073073fadce72bea60073986c25b7a05b9e7829ae50a81d99db875

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments