MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5f4ebfa62a41b397df2f9c86198334b32d6b477833b2843b576ce17c3e3b6f66. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 4
| SHA256 hash: | 5f4ebfa62a41b397df2f9c86198334b32d6b477833b2843b576ce17c3e3b6f66 |
|---|---|
| SHA3-384 hash: | 17fe49657ff1c971be5a4f666ecc7a84b6d6abe850a2d6514934bdd434f3d27d13537f55dd9434173571b55404935fa1 |
| SHA1 hash: | 768f2fd2c812fb391066a87f04394005b77756c2 |
| MD5 hash: | 63c113ff403f5d83a737d85f14b7aca8 |
| humanhash: | five-winter-five-oxygen |
| File name: | 采购订单号4122681.rar |
| Download: | download sample |
| Signature | Formbook |
| File size: | 197'930 bytes |
| First seen: | 2020-12-29 07:59:55 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 3072:PW2UeA8b8bXTJj5GO43/ddM0NAFrubuSGHOk2kiExIvK0wgeB7C6dHaKvIR8:ceCX1EzPIuAHOkWryVggDaKj |
| TLSH | F714221E85C75C5EBEECD2DA728A06B040228F07D4B6BC7E606430F6DEEC5890AD661D |
| Reporter | |
| Tags: | rar |
abuse_ch
Malspam distributing unidentified malware:HELO: alnassar.com.sa
Sending IP: 162.244.93.110
From: 杰夫 <jeff@hncomax.com>
Reply-To: jeff@hncomax.com
Subject: 采购订单号4122681
Attachment: 采购订单号4122681.rar (contains "采购订单号4122681.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
162
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Fugrafa
Status:
Malicious
First seen:
2020-12-29 08:00:10 UTC
AV detection:
15 of 48 (31.25%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.