MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5f4ebfa62a41b397df2f9c86198334b32d6b477833b2843b576ce17c3e3b6f66. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5f4ebfa62a41b397df2f9c86198334b32d6b477833b2843b576ce17c3e3b6f66
SHA3-384 hash: 17fe49657ff1c971be5a4f666ecc7a84b6d6abe850a2d6514934bdd434f3d27d13537f55dd9434173571b55404935fa1
SHA1 hash: 768f2fd2c812fb391066a87f04394005b77756c2
MD5 hash: 63c113ff403f5d83a737d85f14b7aca8
humanhash: five-winter-five-oxygen
File name:采购订单号4122681.rar
Download: download sample
Signature Formbook
File size:197'930 bytes
First seen:2020-12-29 07:59:55 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 3072:PW2UeA8b8bXTJj5GO43/ddM0NAFrubuSGHOk2kiExIvK0wgeB7C6dHaKvIR8:ceCX1EzPIuAHOkWryVggDaKj
TLSH F714221E85C75C5EBEECD2DA728A06B040228F07D4B6BC7E606430F6DEEC5890AD661D
Reporter abuse_ch
Tags:rar


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: alnassar.com.sa
Sending IP: 162.244.93.110
From: 杰夫 <jeff@hncomax.com>
Reply-To: jeff@hncomax.com
Subject: 采购订单号4122681
Attachment: 采购订单号4122681.rar (contains "采购订单号4122681.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
162
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Fugrafa
Status:
Malicious
First seen:
2020-12-29 08:00:10 UTC
AV detection:
15 of 48 (31.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar 5f4ebfa62a41b397df2f9c86198334b32d6b477833b2843b576ce17c3e3b6f66

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments