MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8794751b785527783dc8206639012b0e891ddffb18f3ab906829a5b25cfaefcb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8794751b785527783dc8206639012b0e891ddffb18f3ab906829a5b25cfaefcb
SHA3-384 hash: bc9f679ba21d5c2d70f3633fa1f98e682b692e56e0addcfef0d6051a83d4ff0a7cc3e9e866836c6c2ec284c920511e18
SHA1 hash: 4f8f926eae112727907786bea2b2d66af9ab888e
MD5 hash: 5dec658ae9ef8d76228232ff00241a07
humanhash: avocado-pennsylvania-hydrogen-steak
File name:Demand_List.pdf ....
Download: download sample
Signature FormBook
File size:35'009 bytes
First seen:2020-08-12 14:36:01 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:uwEuqXKpsLYTdbQvfIK+ht/FosMzKj1MQYDOJKtCG9kzD:TEbDwdbQ4K+rMzKj1Mv6KtP9kzD
TLSH BBF2E14360E870E464F6A68B149F8F94DCD28DB1D6B7D5B03CBD2D343722516B2E2243
Reporter abuse_ch
Tags:FormBook Hostwinds


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: hwsrv-760084.hostwindsdns.com
Sending IP: 104.168.145.121
From: Md.Mohsin Chowdhury<info@hemoclan.com>
Reply-To: Md.Mohsin Chowdhury<dhczengs@gmail.com>
Subject: RE: Order List
Attachment: Demand_List.pdf .... (contains "Demand_List.pdf ...............................exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Graftor
Status:
Malicious
First seen:
2020-08-12 14:37:06 UTC
AV detection:
7 of 48 (14.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar 8794751b785527783dc8206639012b0e891ddffb18f3ab906829a5b25cfaefcb

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments