MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a0d901c8b9b67190044d81bfe56f8df6d175f46a9279de7d2207cd2c212a1af. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 7a0d901c8b9b67190044d81bfe56f8df6d175f46a9279de7d2207cd2c212a1af
SHA3-384 hash: 6a1ff95c89db19e31e323aa5abb1aad47f4c154f76e2520bd17dac6936229b5ba72980aa50dde25754f003c09f590c51
SHA1 hash: a102768f24ded1416c42f12ea54bdc8def8c795d
MD5 hash: ca6db9f0415fa20dc1f9f065027c2ff0
humanhash: muppet-arizona-nebraska-mango
File name:INV-COPY5673245367.pdf.zip
Download: download sample
Signature FormBook
File size:302'924 bytes
First seen:2020-06-25 09:34:51 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:oAf7aGAkvYyu8dHJoVpiCP8qQW+hwMm+QubIt8jcf4/Uebx:rfWGAk9uCpqpiUdemwbItKpsIx
TLSH 4554235EB2051EACE438D067B7829A5763D2007448707F29793393CEF4BDAA17E06B5B
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: communityworldservice.asia
Sending IP: 173.208.220.242
From: Kim Wang <kim.wang@bodemax.com>
Subject: Investment Copy
Attachment: INV-COPY5673245367.pdf.zip (contains "INV-COPY##5673245367.pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 7a0d901c8b9b67190044d81bfe56f8df6d175f46a9279de7d2207cd2c212a1af

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments