MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5595c5735586355b3ac146aa802ed3b45b5933f2ae8cfc3cdc744368771ff9d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 5595c5735586355b3ac146aa802ed3b45b5933f2ae8cfc3cdc744368771ff9d7
SHA3-384 hash: 57ca02f6355828c6736f17e2762172ae76d16a8eaf5040b29e270dbb746ac61102a167ae6260fbdf05804c9ec95fa7c3
SHA1 hash: 4f1fb6ae48c84b8e8235760ba722e903aff52970
MD5 hash: 9574107cbd9349fbe5b85eaced68c683
humanhash: snake-thirteen-carolina-sierra
File name:PO_No 2545.rar
Download: download sample
Signature FormBook
File size:245'394 bytes
First seen:2020-05-28 06:19:04 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:Dz2ZBxF9chxfePm8rfyzI62/hsJsYdm2AJ896XRZ:Dz8BoWPmiyz0/WJ16BZ
TLSH 213423019FD772B273BAF7F379D1290B67222BCE0D8630D14890A705AC1C1A997979BD
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: qualitech-solutions.cam
Sending IP: 111.90.140.145
From: Austin Schick <austin.schick@qualitech-solutions.cam>
Subject: RE: ORDER INQUIRY
Attachment: PO_No 2545.rar (contains "PO_No 2545.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-28 07:38:32 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
15 of 30 (50.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar 5595c5735586355b3ac146aa802ed3b45b5933f2ae8cfc3cdc744368771ff9d7

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments