MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 306dbed9d5976d3969b023df3ca9688819ba4cd31f5d94c6f5005f26e4db51aa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 306dbed9d5976d3969b023df3ca9688819ba4cd31f5d94c6f5005f26e4db51aa
SHA3-384 hash: 924fab2eab02ef1b6672501a30e7e814df3f2f8198712e2616b8442f31d5bebe0c1be78c74b019393bbfd71aca161be0
SHA1 hash: 35b3781b3afafcb3010a800022dc6733c19bf29a
MD5 hash: 4195a630701c2f37f483c4ecdcb331e0
humanhash: connecticut-friend-connecticut-fix
File name:INVOICE SOA.rar
Download: download sample
Signature Formbook
File size:209'288 bytes
First seen:2021-01-13 20:08:02 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:m0YucI/a7bduSjQwvbAoI5lsuaReahiEyyGYGA4hSnVcaf52:rcuavdbQwzAoI5lsFEkiEyDG4V2M
TLSH 6B1422124E613FE03DF0925EDFD57F38665E40BE68A3868B47B58EABFACC44560075A0
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing Formbook:

From: michelle <michelle.sm@emecqatar.com>
Reply-To: info@emecgatar.com, michelle.sm@emecqatar.com
Subject: Invoice & Ledger SOA Reconciliation Request
Attachment: INVOICE SOA.rar (contains "in.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
142
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Spyware.Artemis
Status:
Malicious
First seen:
2021-01-13 20:08:17 UTC
AV detection:
16 of 44 (36.36%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar 306dbed9d5976d3969b023df3ca9688819ba4cd31f5d94c6f5005f26e4db51aa

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments