MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8608fe85cb9b720bfe35b5bfbbdd7c8cf43456bdd57caef008d8ad7a54e5e59a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8608fe85cb9b720bfe35b5bfbbdd7c8cf43456bdd57caef008d8ad7a54e5e59a
SHA3-384 hash: bcd114f0b5f21ca4bf70276d7a642cf68f6147b338b1230ed9da4527f8b61b5c54e203549a48203cc28e3733b7792051
SHA1 hash: f51a603d5f160614f5e21c2189598637994f7b73
MD5 hash: 465743c8c987bd68cc1e64086656e85c
humanhash: tennis-grey-tennis-sixteen
File name:Invoice.img
Download: download sample
Signature FormBook
File size:1'507'328 bytes
First seen:2020-05-04 18:16:13 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:z9FU/dwXoTlOCmfgDASt4B/uybSUcUuDG569xg8ULwaaioBUsE9:zMdwXglqfgDASCB/PbQeYt3diEE9
TLSH 43659E85B14888DFE97B1DB3A83BAA3024567EED90E0811E365F771945F334201AFE5E
Reporter abuse_ch
Tags:FormBook img Outlook


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: EUR01-DB5-obe.outbound.protection.outlook.com
Sending IP: 40.92.64.42
From: import manager <mohammedazeem003@outlook.com>
Subject: 改变顺序
Attachment: Invoice.img (contains "Order.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Grp
Status:
Malicious
First seen:
2020-05-04 12:41:28 UTC
File Type:
Binary (Archive)
AV detection:
16 of 31 (51.61%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

img 8608fe85cb9b720bfe35b5bfbbdd7c8cf43456bdd57caef008d8ad7a54e5e59a

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments