MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 59056e5af2e3eb7376c4893b285cb6425d86dc90083df11fab35309278f7e225. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 59056e5af2e3eb7376c4893b285cb6425d86dc90083df11fab35309278f7e225
SHA3-384 hash: a9edfaf79d385d553b62c7e379e92d7d303278677033f35d50914b8a5441e80a3dfe94e5048ba60a6b4f656239d171ea
SHA1 hash: d24cfc98b30292d5f53ebb0460e453040753ab88
MD5 hash: 7a22a64a5c124f9d9c48c9f71601592f
humanhash: triple-magnesium-four-lactose
File name:PO_2576.rar
Download: download sample
Signature FormBook
File size:367'478 bytes
First seen:2020-05-21 09:24:57 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:WQej4E4xWHRSMOzpieL5mm7CqqYXUXC5c8LeEEHgIsGkvRapW5BDqnVCnMuUdHg0:WQBkRSMQL6qqiUXC5c8Km7GkvgpWILR9
TLSH 35742375928AE40D886751ECBA12DF39C4F1E5ADE03F76B7CDCA9418010DE067739AB2
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: qualitech-solutions.cam
Sending IP: 111.90.140.145
From: Sharon Lang <Sharonlang@qualitech-solutions.cam>
Subject: RE: AW: Order sheet/new articles for RFQ
Attachment: PO_2576.rar (contains "PO_#2576.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Malrep
Status:
Malicious
First seen:
2020-05-21 09:36:25 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
16 of 30 (53.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar 59056e5af2e3eb7376c4893b285cb6425d86dc90083df11fab35309278f7e225

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments