MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 21dd47c7e7f3130359a5fb633e91edfdf5183b90becfcf24fc0bab4b15b3d756. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 21dd47c7e7f3130359a5fb633e91edfdf5183b90becfcf24fc0bab4b15b3d756
SHA3-384 hash: ccd41bbdc2f9c3a4b01cdd13a424d9bd9074cb1486b3796b7cd19395c5d0551173da45bcd128fec10c6f74c1bd82ef4a
SHA1 hash: a8037ab684132b412b49a29d2e6c49f955e04014
MD5 hash: 996bbc55a78979fba3e4e1502a9017f9
humanhash: leopard-tennessee-tennis-december
File name:Remittance Details.pdf.gz
Download: download sample
Signature FormBook
File size:278'517 bytes
First seen:2020-07-06 08:26:01 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:ivXDE05uOX74qJWOhAbPxEXAxOBOuEjNBRY8bD3bdN9ZeVwe:ifDEyusMnOSbnMOZNB6aDLZZHe
TLSH AE44231A763BA93DDF5307B6B35B2F32B68F9DD23C42F42E99E5944052BC7080725922
Reporter abuse_ch
Tags:FormBook gz


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: ngay7.localdomain
Sending IP: 45.127.62.126
From: Gaetan Cyril Maudric <gaetan.mei@lafargeholcim.com>
Reply-To: gaetan.mei@lafrageholcim.com
Subject: RE:Payment with Value Date: 06/07/2020-Confirm Remittance Details
Attachment: Remittance Details.pdf.gz (contains "Remittance Details_pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-06 08:27:06 UTC
AV detection:
31 of 48 (64.58%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 21dd47c7e7f3130359a5fb633e91edfdf5183b90becfcf24fc0bab4b15b3d756

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments