MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6f63c45ad33d0bcef6f6fe01e4b8174f10c3ccebb10968cd879679d52b794c4b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6f63c45ad33d0bcef6f6fe01e4b8174f10c3ccebb10968cd879679d52b794c4b
SHA3-384 hash: ecbb08a5942cbf3ae538a329fee051ef273aa622c546941ff3bee3e922844d4633c365a62ab3812f264330d4533ffb4b
SHA1 hash: b17769434566355ec4b4939800ab625ff458b2e2
MD5 hash: 522698d406153f4e0f5a60405cb00cd2
humanhash: river-xray-utah-uranus
File name:PROUCTLIST-RQU_23523542354.IMG
Download: download sample
Signature FormBook
File size:1'245'184 bytes
First seen:2020-06-12 06:41:19 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:qlFZXBrPyCBHhBPSOim3JVgjwW9M11yXtsGJTs12KsyeW+m+ESMgBM3PUULeUW:Mxra8BNkyJEy11yXtsGhfo2MgBKa
TLSH 0845E024325A432FC17909B11DB6A2D527F6352BBB00C78D7DED229D5BE3B830B1169B
Reporter abuse_ch
Tags:FormBook img


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: tpslmc.com
Sending IP: 103.114.104.116
From: Eric Nicholas<cch.wirote@tpslmc.com>
Subject: RFQ_Utracon_Supply_5625866588
Attachment: PROUCTLIST-RQU_23523542354.IMG (contains "PRODUCTLIST-RFQ_3475872475.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-06-12 06:43:06 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

img 6f63c45ad33d0bcef6f6fe01e4b8174f10c3ccebb10968cd879679d52b794c4b

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments