MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 714c75a0e96af96cd086ce91994e4ffabb25a0a7db9bbada332e18170ff6489d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 714c75a0e96af96cd086ce91994e4ffabb25a0a7db9bbada332e18170ff6489d
SHA3-384 hash: 618e36244a9e3134c66ebd166ede25341dc7815558596556fef619f6ca991397f5cdde63fd6177cea8ece28a619c1d3d
SHA1 hash: 56c14fa7f3cf438e1bba6eb897b2271d71f6042e
MD5 hash: 6f042a90454a740b5f5aa28861388e4e
humanhash: zebra-johnny-river-emma
File name:PO33374784_2020-05-14_02-36.zip
Download: download sample
Signature FormBook
File size:283'324 bytes
First seen:2020-05-14 04:41:38 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:HQKbYfa17eJv3iREQd2SdFmqpFgYP3z/cqQdvHa/+1:HQKOa17eJv3GEQASdoqYYPDYp621
TLSH 7054228CF41D1A51747BCBEB838C0410FAADEF9CE531E011F7BE99946A1ED966362087
Reporter jarumlus
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-14 05:35:40 UTC
File Type:
Binary (Archive)
Extracted files:
13
AV detection:
24 of 48 (50.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 714c75a0e96af96cd086ce91994e4ffabb25a0a7db9bbada332e18170ff6489d

(this sample)

  
Dropped by
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments