MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4fa3305718888d3c7042fa951a23b53e4b17e7ee2648d1d0345175b5da6e7567. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4fa3305718888d3c7042fa951a23b53e4b17e7ee2648d1d0345175b5da6e7567
SHA3-384 hash: 7b5deea9e50d1718371386c70b11d4fa6933977286e5bc4c70dde646b6631f2299a62db015758612476ebdfd496cdd95
SHA1 hash: 38055a05611faf61cedcc755426616658a163c90
MD5 hash: 69a25f91be7ab00e7b434cf1f0c67d85
humanhash: oxygen-violet-edward-alaska
File name:Purchase Enquiry.zip
Download: download sample
Signature Formbook
File size:463'939 bytes
First seen:2021-02-11 10:22:33 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:5SqeKxF581IDTuydVio+kQPpONR2CvlCMWRMMmDYPkR/0h2aMCICIU1ziy+5au5r:5Sqlx45iz+5ENR7QMMMMeEgvai75/UKj
TLSH 5AA423A6DB0B3B560CFF38D4D5FB8224137A723936B008968BF516073A6260F555B4BD
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: tirdonics.us
Sending IP: 172.107.194.103
From: sales011@tirdonics.us
Reply-To: sales01@tirdonics.us
Subject: Enquiry from Tridonic Inc
Attachment: Purchase Enquiry.zip (contains "Purchase Enquiry.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
152
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Infostealer.Stelega
Status:
Malicious
First seen:
2021-02-12 04:16:41 UTC
AV detection:
22 of 28 (78.57%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 4fa3305718888d3c7042fa951a23b53e4b17e7ee2648d1d0345175b5da6e7567

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments