MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2c5c22690587b3fb1355a9e569dc739f559ef2fbfe41652214d363f494402b30. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 2c5c22690587b3fb1355a9e569dc739f559ef2fbfe41652214d363f494402b30
SHA3-384 hash: aaa645d90ea3fdbdd7c81c0937dbbde1762c1c1ddfb876bd12b537b494d27293a0016e1f09b8a4e2b39f0796a54c9f5d
SHA1 hash: ee3a8a5b0a048da01ec8a4f886f16ffb2937189a
MD5 hash: 20db2292886cd1390fb7ad9d5b091e13
humanhash: washington-georgia-edward-november
File name:OD-14102020 PDF.zip
Download: download sample
Signature Formbook
File size:621'988 bytes
First seen:2020-10-15 10:40:49 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:XBEEQ7qf8+Tf7ahqJjTa+Z4ym/Ix9RMv8FX0oNitD:7QqU+j7ahL+Z4yWI508FX0RD
TLSH C7D423880460F773DA5F9967DBD70A81A32C904704A07315E69121F1EAF6A3C9DBBF9C
Reporter abuse_ch
Tags:Endurance FormBook zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: qproxy1-pub.mail.unifiedlayer.com
Sending IP: 173.254.64.10
From: sales3 <fikriye@samyag.com>
Subject: NDT project request 14-10-2020
Attachment: OD-14102020 PDF.zip (contains "OD-14102020 PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Stelega
Status:
Malicious
First seen:
2020-10-14 17:53:30 UTC
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 2c5c22690587b3fb1355a9e569dc739f559ef2fbfe41652214d363f494402b30

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments