MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 418fc8f93bfeab75d54ea3b9bf1d91292f6aa1f858dfbf95b03dac82b0c1a4b5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 418fc8f93bfeab75d54ea3b9bf1d91292f6aa1f858dfbf95b03dac82b0c1a4b5
SHA3-384 hash: 61ac49479a266badae74f273fa6a21b005bbd66d7251abbc42569275aee6904d2415b6a841e74e41c1e8f4fc7b2dcfa0
SHA1 hash: 549c4b7527589fe6a7b27e157bf5ebede3849c61
MD5 hash: e4483c7ab0f9beced306226603ecfc08
humanhash: two-nine-pluto-seventeen
File name:KH.O2333.rar
Download: download sample
Signature Formbook
File size:475'129 bytes
First seen:2020-04-15 11:03:17 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:RPpU2K8W7Ac4OLIPJbzvn6WPkWFTiDByoAXUiWL8g:1pUV8MhLqJbzJFJiwoAXUR
TLSH 5EA42361BF7FD8280175583CAC753331197288B4BE44997F86E466089462FCB97FCAE8
Reporter abuse_ch
Tags:COVID-19 FormBook rar


Avatar
abuse_ch
COVID-19 themed malspam distributing FormBook:

RAR->IMG->EXE

HELO: salo.com
Sending IP: 94.177.240.142
From: Chu Lam Yiu <tskiba@besser.com>
Subject: COVID 19 PENDIMG ORDER
Attachment: KH.O2333.rar (contains "KH.O2333#.img" -> "invoice.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Noon
Status:
Malicious
First seen:
2020-04-15 02:14:00 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
14 of 31 (45.16%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments