MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5114955491d5400511f2c6d6efdc4338d0f7ef7b85f4f3b1d66ffa78f796b81a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5114955491d5400511f2c6d6efdc4338d0f7ef7b85f4f3b1d66ffa78f796b81a
SHA3-384 hash: 6317fcf6031921818d2344dce7fd3c1ec8e68383a6053edef79101a914f2105dd730efecf0cab4c1752d2031f4d4cb97
SHA1 hash: 4394db5449fd92bfda74a60d482466ca3b16a482
MD5 hash: c9ff3c2135d57620806738a498933592
humanhash: maryland-robin-magnesium-wisconsin
File name:Demand.zip
Download: download sample
Signature Formbook
File size:281'084 bytes
First seen:2020-05-01 13:21:21 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:/2ZwzpE/nO5W89GL9ponIpiNK4ZFVyOMlroAUpxJTyDrN6GecGzq:YQZ5W8cmaIZFOlUAUIFvtb
TLSH F754231428CDD2269BF81764E362334FE4B9263F800FF5109AB76775EAFC09A93A4D51
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: wikiweblog.com
Sending IP: 96.9.210.250
From: Louise <info@wikiweblog.com>
Reply-To: louise@bezi.com.au
Subject: Rate Required for PO - 01-05-2020
Attachment: Demand.zip (contains "Demand.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-01 13:35:44 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
26 of 48 (54.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 5114955491d5400511f2c6d6efdc4338d0f7ef7b85f4f3b1d66ffa78f796b81a

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments