MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 25e3c5024b79296131093e8ee80112ed5f5761e52447ec558c1745a2cf61ff9c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 25e3c5024b79296131093e8ee80112ed5f5761e52447ec558c1745a2cf61ff9c
SHA3-384 hash: c5169d79957cb510166b1770ba30212a21a9f1fc1b3cf7b3949ee45fe7a8890422eaf1caca73d4c2d3f2e63c641a892a
SHA1 hash: 7a385725f071d53a5ecca522149357b72bc06b4a
MD5 hash: bf75daf5d10d1472a85ad93c44973884
humanhash: lithium-north-green-pluto
File name:orderquantity.rar
Download: download sample
Signature Formbook
File size:185'852 bytes
First seen:2020-06-02 06:46:22 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 3072:fJTdfr5iVQXPABF17VRj2tnpVRpLnXIiROW32aOXIvV4QDB42cTSn2lxujmj2pqa:fxdD5iVQXS17VRKRpxnXItWmXAnNDcTm
TLSH 0B04130F87D8B6131F9BF5262958F8D906FC8FDE561AA29C1151BF1B874532E1CACC11
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: postal.zeregabertrading.info
Sending IP: 176.107.177.184
From: Mohammad Hijazi <sales@steelpipespe.co.za>
Subject: Purchase Order100502020
Attachment: orderquantity.rar (contains "orderquantity.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-06-03 02:35:00 UTC
File Type:
Binary (Archive)
Extracted files:
8
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar 25e3c5024b79296131093e8ee80112ed5f5761e52447ec558c1745a2cf61ff9c

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments