MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 74d38284fdbab1055e523230c628d163500864836becd5561c5812b5e4adac06. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 74d38284fdbab1055e523230c628d163500864836becd5561c5812b5e4adac06
SHA3-384 hash: 38b201a2a8dcc9092fd74121dfa1150689a24107ea3abbc891b4f2cf9766633f29ccc066621403b57c9364c3bca5c033
SHA1 hash: 301636b4a13352592bad76dbceff9ffa014fce9a
MD5 hash: ee5e74875a3831be5c201356c77e0fde
humanhash: gee-gee-robin-ack
File name:SES20052020.rar
Download: download sample
Signature FormBook
File size:309'078 bytes
First seen:2020-05-20 06:01:52 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:bkCfaWr3X7/PKoeYzB9LotZp7ZGgi+8vhE0d2qyhEo2tV6dpJJoFO5z6:bkCfae7/PKoeYzB9CTZaAEvV6pJeO5z6
TLSH B6642396ED7D33F0F090FB49E04A8C19A5953F6E97D46222F7AB441928A5B3D0708B4F
Reporter jarumlus
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Frs
Status:
Malicious
First seen:
2020-05-20 06:35:24 UTC
File Type:
Binary (Archive)
Extracted files:
9
AV detection:
16 of 31 (51.61%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar 74d38284fdbab1055e523230c628d163500864836becd5561c5812b5e4adac06

(this sample)

  
Dropped by
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments