MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 340c3507fd3a1f599da7d00484ffa9d2ca5bef13e89b584ec7fbcb5b2245b0b0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 340c3507fd3a1f599da7d00484ffa9d2ca5bef13e89b584ec7fbcb5b2245b0b0
SHA3-384 hash: b3e3abc14a4f90781116d02c244d41ded5ab109f072562a6f801149abf2d2faab858d389281eb0bb552ef0048ebc96af
SHA1 hash: 2e9edff5f6dee5a5b6109fef0613cf2121cb68d6
MD5 hash: 5a00f6d76bc7b36d368303515bb136ca
humanhash: minnesota-video-arizona-snake
File name:order inquiry.zip
Download: download sample
Signature Formbook
File size:190'100 bytes
First seen:2020-08-13 03:19:39 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:tS7r7zm2i8xX+ivcIANlCaqYYY+qw6HcEvQYx5Wii2iUOZgnjjLiz6akJc6WOqA4:tS7XzA8xXO3NlIYYYT1D3Wii6OZ0izuc
TLSH BC04226B529F31729412DF6C3F5ED5C9ADC2E7271E029C50333C12801D9231ADF99B82
Reporter cocaman
Tags:FormBook zip


Avatar
cocaman
Malicious email
From: Amy Chang<iluyang@luyangwool.com>
Received: from luyangwool.com (unknown [212.83.46.93])
Date: 6 Aug 2020 20:49:15 -0700
Subject: Ref: Order Acknowledgement
Attachment: order inquiry.zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Injuke
Status:
Malicious
First seen:
2020-08-09 05:26:05 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 340c3507fd3a1f599da7d00484ffa9d2ca5bef13e89b584ec7fbcb5b2245b0b0

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
Formbook

Comments