MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 82cf5c8cb06827577f944cea37a03fbc8a1c16d67c5f3907ef731c28a2d0ebf8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 82cf5c8cb06827577f944cea37a03fbc8a1c16d67c5f3907ef731c28a2d0ebf8
SHA3-384 hash: a2943e396ddbd3f04ae7613b449801694e5eca92ffba4c1494975046f4d04ccb15fa200fbb001145e34a4f03dd70cebb
SHA1 hash: ac08be753de327a840fd6fcbd358f2fd086c02ae
MD5 hash: be0fda8ae721321f3c4494a072d2c911
humanhash: double-happy-football-sixteen
File name:DN031679936.pdf.xz
Download: download sample
Signature FormBook
File size:760'310 bytes
First seen:2020-06-11 05:50:09 UTC
Last seen:Never
File type: xz
MIME type:application/x-rar
ssdeep 12288:fCzLrMquSkRcrUYZH/02h5YEFJj7TqciOftgwyCLa8PVuN6+1eOhVxlKTo+cNjFM:6z39P1c2hVWpOftuQAeOhKo+czv/zQ
TLSH 42F423CE0DD747E599EF4C14A9D309782FF418A56E663A10CA460F9F1A72BBE5C0C816
Reporter abuse_ch
Tags:FormBook xz


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: maleo.empatdns.com
Sending IP: 103.6.55.224
From: SUSAN / JCONSOL <susan@jconsol.co.kr>
Subject: Outstanding statement 01-06-2020
Attachment: DN031679936.pdf.xz (contains "DN#031679936_pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-11 05:51:06 UTC
AV detection:
17 of 48 (35.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

xz 82cf5c8cb06827577f944cea37a03fbc8a1c16d67c5f3907ef731c28a2d0ebf8

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments