MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2d5ae2b3a546c4e1269cbeb309e7fa2a4a53fb1aa165b80650cf0a25f352beee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2d5ae2b3a546c4e1269cbeb309e7fa2a4a53fb1aa165b80650cf0a25f352beee
SHA3-384 hash: a48ce528226143fb80747de93252363b84c278d1436320982d998c3a352ed4643bfd03ddbcf9428437d27387fc7d6dda
SHA1 hash: 9805db791952f2bc7b391a2ef7f3bcf62eebb80a
MD5 hash: 3aec1d028c779fa928c80fd6761c3f65
humanhash: timing-michigan-mango-failed
File name:Quotation for RC outdoor project.zip
Download: download sample
Signature FormBook
File size:511'327 bytes
First seen:2020-07-15 22:54:21 UTC
Last seen:2020-07-16 09:20:31 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:majVk2qG7oK0M0bGgnZQ+UHu6fWXtUvijNssDBBNYSseGm8:mEVZopDGgZQ+yn0dsmTNhJGm8
TLSH 75B423407492B0B3B8E77BE8DBEA61885B653590016F6F2D827783245D2FF1D99C1CB2
Reporter jarumlus
Tags:FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-15 10:44:51 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 2d5ae2b3a546c4e1269cbeb309e7fa2a4a53fb1aa165b80650cf0a25f352beee

(this sample)

  
Dropped by
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments