MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6f825a42b2676b0b7d5aae79bdcc3791fdd0372bca413b887c356ac97eece501. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6f825a42b2676b0b7d5aae79bdcc3791fdd0372bca413b887c356ac97eece501
SHA3-384 hash: c843b444420cb9040f3a629e5de2adaedad8ea19ef422e07c78dab09bb97e9a34a2abfa56868df46e4ea2ffc00f2c288
SHA1 hash: 039511868390c79b6ada236499d516511c30d49c
MD5 hash: fb64fe6d34e88075bb411a56a836f78a
humanhash: equal-coffee-arkansas-nineteen
File name:Conti Srl PO352ELJ3524.rar
Download: download sample
Signature FormBook
File size:294'250 bytes
First seen:2020-04-29 18:30:22 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:AZn3aqKWNecKxbXYtCuMWOwuApf32BQqfahRYKag0EFadBNF:AZnKqycKxEKwuApfmuqC8y0F
TLSH F45423992CEDC4B5780512AF9E04E5D8C6BCF2AFF6492B517523E4895E748292CEC3C3
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: cathay-food.co
Sending IP: 111.90.140.123
From: Caterina <caterina@cathay-food.co>
Subject: Conti Srl (Order 1NNQ)
Attachment: Conti Srl PO352ELJ3524.rar (contains "Conti Srl (PO352ELJ3524).exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-04-29 16:27:18 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
16 of 31 (51.61%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar 6f825a42b2676b0b7d5aae79bdcc3791fdd0372bca413b887c356ac97eece501

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments