MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 84dfc373c93e726bc0b146e246e878c7688bcd927081d3a3dc9c484151e633e8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 84dfc373c93e726bc0b146e246e878c7688bcd927081d3a3dc9c484151e633e8
SHA3-384 hash: 423f20da329de45e53c11ad76de3cc067e9dd05aa3c615b2d603ebe7eac2f4e1633e1c7cba389a9ac226aee43bd76f91
SHA1 hash: c25ae09f643a00c77b809741a40b01d358e84af2
MD5 hash: 2dc9b51718b4c5a21cc9e6be45bccc57
humanhash: angel-shade-eleven-charlie
File name:BL, Invoice Copies, and Full Set of Shipping Documents.rar
Download: download sample
Signature FormBook
File size:617'404 bytes
First seen:2020-07-07 08:34:26 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:XhHBhKNtYPcpR3POT169EOiFcSkkUhHBhKNtYPcpR3POT169EOiFcSkkg:XhHbitoY92TcqOiFj+hHbitoY92TcqOd
TLSH B0D423270C37C8AD7456BCF5F206F1E6528B69B8C1B14182B0B9BB1583B74F7AC92E45
Reporter abuse_ch
Tags:DHL FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: 162-241-215-47.unifiedlayer.com
Sending IP: 162.241.215.47
From: DHL Express - customer service <felixmuller.dhl@mail.com>
Subject: [DHL Express] New Shipment Notification: AWB: 7915934622 - BL, Invoice Copies, and Checklist.
Attachment: BL, Invoice Copies, and Full Set of Shipping Documents.rar (contains "Checklist, Shipping Docs.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-07-07 08:36:06 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar 84dfc373c93e726bc0b146e246e878c7688bcd927081d3a3dc9c484151e633e8

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments