MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2166878ac3a285b4b19ba9c5bfa6ab317c8abb3a8996455ff359d4a0196d2517. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2166878ac3a285b4b19ba9c5bfa6ab317c8abb3a8996455ff359d4a0196d2517
SHA3-384 hash: 1a14ae562cf3d5fb56e52574f6571be6d06009e01547976d7f3b5258d80480fd32264441d374823ccebb33cbd8c72b36
SHA1 hash: e3863331aca6c561f6d7cb38810c6ea9d651f10b
MD5 hash: 0bb2528ded308c82ee891438922b7f9c
humanhash: bravo-sierra-king-neptune
File name:REVISED ORDER1.zip
Download: download sample
Signature FormBook
File size:911'634 bytes
First seen:2020-04-21 18:01:55 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:Uw2RDzcYTBbuMLkB7bH8ZdujSX6Hal+nSoZekwzSA:D2RDzcYTtuMYpL83GSq6kX4+A
TLSH FF1533ABE25F730D3BE75C5A856828421E08BA724F72474DED62BCCBE1F6115271DA0C
Reporter abuse_ch
Tags:COVID-19 FormBook zip


Avatar
abuse_ch
COVID-19 themed malspam distributing FormBook:

HELLO: pixel.hostlogic.sg
Sending IP: 103.255.250.151
From: Nassir Bechara <Enqui_ry@hotmail.com>
Subject: COVID 19 PENDIMG ORDER enquiry KH.O2333#
Attachment: REVISED ORDER1.zip (contains "REVISED ORDER")

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-04-21 18:35:27 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 2166878ac3a285b4b19ba9c5bfa6ab317c8abb3a8996455ff359d4a0196d2517

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments