MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 56894556c6084824d0cd4dee2fa4b9fca6552f864aacd3978b99b11f4d425ab0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 56894556c6084824d0cd4dee2fa4b9fca6552f864aacd3978b99b11f4d425ab0
SHA3-384 hash: b7eac0652679672d9bbf67bd9fdaa2c9a8f1d13455449d0660a6cfef94e22711f09ceadea8537322289aea7cd09f8962
SHA1 hash: ea3ef34a4e0bd890a3681179f61a46e29dd5d5e9
MD5 hash: 0a11e44d0b242e06db1ed216bb1d3c4c
humanhash: jupiter-kentucky-wisconsin-happy
File name:RFx_3700017066.ace
Download: download sample
Signature FormBook
File size:456'270 bytes
First seen:2020-05-04 17:41:01 UTC
Last seen:Never
File type: ace
MIME type:application/x-rar
ssdeep 6144:OZYFBTFNen5q1z1pAPzTjcFp+IbQ8p+atmEi68SoxD/Qt090Zp9zTHIxSSJQZI:9rgq1z0zsz+IbQ8A6ot4kq9PHIxSSJoI
TLSH BAA423862E07AD0F6A498AE4AB424D1578DE0E42F2871D47CED03EA65B70C5DB3D2FD0
Reporter abuse_ch
Tags:ace FormBook


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: se6h-iad1.servconfig.com
Sending IP: 173.231.241.30
From: Shoaib Laghari <slaqhari@engro.com>
Subject: EFERT Request for Quotation against Reference# 3700017066 DUE DATE 07-05-2020
Attachment: RFx_3700017066.ace (contains "RFx_3700017066.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-04 18:36:04 UTC
File Type:
Binary (Archive)
Extracted files:
22
AV detection:
21 of 31 (67.74%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

ace 56894556c6084824d0cd4dee2fa4b9fca6552f864aacd3978b99b11f4d425ab0

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments