MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d993cb21ffe5a2b315ceede2a9e021f65fba6df052e1d0a400afba3ba76c17a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 4d993cb21ffe5a2b315ceede2a9e021f65fba6df052e1d0a400afba3ba76c17a
SHA3-384 hash: 640d90791e1ae62413875d1e208a997ad8a5d18e52fd65307ab5453a517c553de655554eeeb8c01839c916e2159e5543
SHA1 hash: 2aefca3001034e6060c17a0beb5283a92eb38b18
MD5 hash: 5fd9af609fa4e443095cd8e1cfe7f9e3
humanhash: skylark-white-tennessee-ink
File name:order5.exe
Download: download sample
Signature FormBook
File size:1'336'832 bytes
First seen:2020-06-19 12:41:15 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f074fdcbfed5f17d9663ca342d8d6e7a (6 x FormBook, 1 x NetWire, 1 x RemcosRAT)
ssdeep 24576:Gk2X4/w8+GEHGtVlf4H3k6uyefk4DJwPPhvgYO:GkA7N46uyQbDJwXBg
Threatray 87 similar samples on MalwareBazaar
TLSH 8F551721BDAF9432C012C935CD1EB698D8657E006D175B0E6EE43A8CBE35E8DE81635F
Reporter abuse_ch
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.FormBook
Status:
Malicious
First seen:
2020-06-19 12:43:05 UTC
AV detection:
25 of 31 (80.65%)
Threat level:
  5/5
Result
Malware family:
modiloader
Score:
  10/10
Tags:
family:modiloader
Behaviour
Suspicious use of WriteProcessMemory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

Executable exe 4d993cb21ffe5a2b315ceede2a9e021f65fba6df052e1d0a400afba3ba76c17a

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments