MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 31791ad0d3707ca7ffcc7d970c9a70853fded91505dc019d7f7460a42814317e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 31791ad0d3707ca7ffcc7d970c9a70853fded91505dc019d7f7460a42814317e
SHA3-384 hash: bc5b7c26cf9e695d81b46f170436c366eb04c4be50541130dfa04bab761df5439652da273f350c42cde0c51627e185a2
SHA1 hash: 53c9b81ab30ced6032fd110374bafe42ff9a54b5
MD5 hash: 219b8eea3a397ce0a31333fa6bae9d46
humanhash: wyoming-robert-item-romeo
File name:RFQ47692762531096734.PDF.z
Download: download sample
Signature Formbook
File size:362'273 bytes
First seen:2020-08-11 13:53:34 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 6144:Eg1Cnpe6nf6QOckn57NAIQkvLj9thRGAm+789qFlZhy6k2lM/1Ifd:Tonk6gz1X9JGn+o9q/Zo6kW1d
TLSH AD7423123C91B96ED7EE065115BA690535DB1DDFBE3684846EE3F880BD1B20C0FC2E68
Reporter abuse_ch
Tags:FormBook z


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: server1.swisspac.es
Sending IP: 119.18.63.233
From: Bhavik Nayee <purchase@tascoindustries.co.ug>
Subject: RFQ
Attachment: RFQ47692762531096734.PDF.z (contains "RFQ47692762531096734.PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.Androm
Status:
Malicious
First seen:
2020-08-11 13:55:05 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

z 31791ad0d3707ca7ffcc7d970c9a70853fded91505dc019d7f7460a42814317e

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments