MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5f291bf8758df145ea948779f8c32b8d963d06db0541989e00c2af9e8035d742. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5f291bf8758df145ea948779f8c32b8d963d06db0541989e00c2af9e8035d742
SHA3-384 hash: d287c06f8ce1fde7898417c755c53c10675b83dfb9f9b7d4358a386934c0565060db6930aad2173f6f419ba7effeb335
SHA1 hash: f5feaaada0d0176be731d55aa819a944eeb51605
MD5 hash: 7a737d7e5061776762ee8553623e3df8
humanhash: tango-butter-don-stairway
File name:PO_29064.rar
Download: download sample
Signature Formbook
File size:452'524 bytes
First seen:2020-10-28 08:56:38 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:pY3UZ1QiApKRYnFjBsza7NFvoWCHfCOrWLBs:pws0KeFlXo79rWLS
TLSH 70A4237933068F8A207EFD74AE91AED48675AA5C61C2F06B1347A5F52F44C1F939038A
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: vps.eca-pp.uk
Sending IP: 45.145.185.42
From: Sherly <office@eca-pp.uk>
Subject: RE: REQUEST FOR QUOTATION
Attachment: PO_29064.rar (contains "PO_29064.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
104
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Barys
Status:
Malicious
First seen:
2020-10-28 05:53:07 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar 5f291bf8758df145ea948779f8c32b8d963d06db0541989e00c2af9e8035d742

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments