MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 73c6b5d079631f5333cf83d080e70cb3b69262d7994596be9dc3deb28b7ae507. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 73c6b5d079631f5333cf83d080e70cb3b69262d7994596be9dc3deb28b7ae507
SHA3-384 hash: 0aa478aa3172d09e68b87a1ef826986c1aff37d04affd9048c8bbb4f20e85284528a9f3ebce340820ba23db685654d7d
SHA1 hash: 8ce80828dd89d660cec251aaf90097344f688d2d
MD5 hash: 512be8787c7bdcd7ac3f6119faf789b5
humanhash: massachusetts-lemon-ink-carolina
File name:Scan2272020 pdf.iMG
Download: download sample
Signature FormBook
File size:933'888 bytes
First seen:2020-07-22 08:51:39 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:XQ/ena6F83r+bPrsdB0L0gazjJsJNulttShwmAl+fE02y6ax3prABZ+b:KaaFabDs7btHlttqwmFfE03Fpc3+b
TLSH BC159E66F1934833C562DA3C8C5BB678583AB9111A2976467BF80F8C9F3E64338352D7
Reporter abuse_ch
Tags:FormBook img


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: server.example.com
Sending IP: 103.133.110.22
From: Stocks-Tandel's <stocks@tandels.com> <admin@motonina.ml>
Subject: MISTAKE ON DUE PAYMENT DATE
Attachment: Scan2272020 pdf.iMG (contains "Scan2272020 pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-22 08:53:06 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

img 73c6b5d079631f5333cf83d080e70cb3b69262d7994596be9dc3deb28b7ae507

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments