MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54d9e41dc860087321eb979b18858f109d7d45c73da540a19d343fc17cce8ccb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 54d9e41dc860087321eb979b18858f109d7d45c73da540a19d343fc17cce8ccb
SHA3-384 hash: 2cd22cbecf7d4e8e0ecf6dd981b3782fbd6791daf0234bcffcfa71addbb063f2f06455bfe7e42c6495d2c985121b96d5
SHA1 hash: a0a9c0522febf8ccb1354a37f0a42d7b4ce6fd74
MD5 hash: 7db666b1c7e2b5814d4ddb8def92a8d5
humanhash: oregon-shade-bulldog-ohio
File name:yeni sipariş.zip
Download: download sample
Signature FormBook
File size:506'547 bytes
First seen:2020-08-03 14:14:17 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:HyLPXZfLrjUMXP0ie7nXkVxuN26jd/fyk:SrpfLrjTPyusN2kkk
TLSH EEB42388D036C52FEBA863855C625FC2B9687B645D37A2A03B329DFB70858C3DDF8450
Reporter abuse_ch
Tags:FormBook geo TUR zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: server107.neubox.net
Sending IP: 174.136.28.112
From: Ismail Cinkilic <proveedores@promedic.com.mx>
Subject: Re: yeni sipariş sorgulama
Attachment: yeni sipariş.zip (contains "yeni sipariş.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-03 14:16:06 UTC
AV detection:
24 of 48 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 54d9e41dc860087321eb979b18858f109d7d45c73da540a19d343fc17cce8ccb

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments