MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1f705ed8894ca4141e6b438400025cfcf8f058b95f2a0350fbbf84f23836fa1d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1f705ed8894ca4141e6b438400025cfcf8f058b95f2a0350fbbf84f23836fa1d
SHA3-384 hash: ab1da6d4c3a3651b5858efa33950c6dbfd0f0c54332868cbbbb9584f1405595ccb9bbeca4849afb5de3aacdce166577f
SHA1 hash: 3226e21cb427ecdded4d4def289d5799f252fb15
MD5 hash: 50b202dd9e72205f21ceb21c6e9b0112
humanhash: nineteen-bacon-south-tennessee
File name:15-6.zip
Download: download sample
Signature FormBook
File size:278'108 bytes
First seen:2020-06-15 14:01:23 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:aln6Oe5ddDWhc55o4/4YMajDZ8rtb7k4yaQLT4F3D1E:alIbZW65o4/4de87Re4ZRE
TLSH AB44230B3CEF32AA5FC25874DBF70DC20EA8FA2778571097A38B8779506694D83B0524
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: slot0.mcleeria.com
Sending IP: 45.95.169.81
From: Syazwani <info@mcleeria.com>
Reply-To: Syazwani <mailreply01@mail.com>
Subject: PO J0256. J0255
Attachment: 15-6.zip (contains "15-6.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-15 14:03:04 UTC
AV detection:
14 of 48 (29.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 1f705ed8894ca4141e6b438400025cfcf8f058b95f2a0350fbbf84f23836fa1d

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments