MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 622005562c5173731b5dd6d5942e9804f792136364bece7e9504a3e99d309370. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 622005562c5173731b5dd6d5942e9804f792136364bece7e9504a3e99d309370
SHA3-384 hash: 1d879b00a2e942c6812abc304477300e14d4a34061278c132083386e89410fe8f621f8091033e4478210918932735c43
SHA1 hash: 9dd4912ebfce65f1c9699ec96c50d9ff48c13b28
MD5 hash: 59580b9a634b9c8c048c1ae869aa4df9
humanhash: juliet-india-magazine-muppet
File name:P.O-DT1692.img
Download: download sample
Signature Formbook
File size:1'245'184 bytes
First seen:2021-02-11 10:17:28 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:Ovv0/iei9k8mOalFu027X1m8qz+oSKIJ8NK0MXz7nm1pLZR8dtoErIgHN2SRV6vJ:08Zi970Kq7wJ8Nm7nsva84IMF68sDD
TLSH 6F45F2291FAC4F1AD2297F790E70A22863FDD1012E15D316FE9C2DD85B3DF899E40A94
Reporter abuse_ch
Tags:COVID-19 FormBook img


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: imsantv71.netvigator.com
Sending IP: 210.87.250.171
From: Sales Dept. <info@thaibednets.com>
Reply-To: <info@toolprofession.co.vu>
Subject: Fw: victim-domain Here New Is Our New Order For Project, Peace and COVID Relief 2021: EONRO3761278DLQ
Attachment: P.O-DT1692.img (contains "P.O-DT1692.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
166
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2021-02-11 11:39:35 UTC
AV detection:
3 of 47 (6.38%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

img 622005562c5173731b5dd6d5942e9804f792136364bece7e9504a3e99d309370

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments