MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3dff28a5654a7fcab7682483b16d75b6e6bfcce1c0b0ac3c2e6cded4e40334aa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3dff28a5654a7fcab7682483b16d75b6e6bfcce1c0b0ac3c2e6cded4e40334aa
SHA3-384 hash: 00ad7c8015241fb075a3904b6279f6ce08d774781b6a299d0104238338bd007c06e137c94a7ec0fc253c6c95bd93c54f
SHA1 hash: e4ecec6f47363eacd581e56ecfc9ed230a57133e
MD5 hash: a251c10f6157d28dca613df83ff9a2dc
humanhash: stream-island-mountain-delaware
File name:invoices0000456_pdf.arj
Download: download sample
Signature FormBook
File size:1'053'053 bytes
First seen:2020-05-04 21:14:41 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 24576:fvRa8uKhafO+3ZbpXGWTtw3It7g8Z8bjPr+CCF6/0icUTWy/O69/DFU:f5aai3ZtXnqbrcFG77TWd69/DW
TLSH 492533282A1F628637DAF2E5F62FDC670FD1115D05191EF10A7A1C33336AC9026BAE75
Reporter abuse_ch
Tags:arj FormBook


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: vps-164633.systegron.com
Sending IP: 162.241.107.77
From: Trends PNG Limited|Niumi Distributors Ltd <michelle.havari@trends.com>
Reply-To: michelle.havarj@trends.com, michelle.havari@trends.com
Subject: RE: Updated SOA & Invoices
Attachment: invoices0000456_pdf.arj (contains "invoices0000456_pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Script-AutoIt.Trojan.Injector
Status:
Malicious
First seen:
2020-05-04 21:36:45 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
25 of 48 (52.08%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

arj 3dff28a5654a7fcab7682483b16d75b6e6bfcce1c0b0ac3c2e6cded4e40334aa

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments