MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8f9f7c1b25fdc44fe44cd0ed39b10bfa66bf9ca2019edb64ddefb2a6f2813bfd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 8f9f7c1b25fdc44fe44cd0ed39b10bfa66bf9ca2019edb64ddefb2a6f2813bfd
SHA3-384 hash: 25a3875f6f989b8fea7c9263d50633f0f6354be1ffe05d9247e4a882e2894ee8aa08144c4048c98b3c9c520c3ba74b8a
SHA1 hash: 8b4fe6c10ff3a4849868032444bb10d234e007b5
MD5 hash: 79607766d46079cc215f02d99f93b1c1
humanhash: ceiling-vermont-sink-moon
File name:SOA.gz
Download: download sample
Signature Formbook
File size:435'733 bytes
First seen:2020-10-27 13:06:18 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:OtYZ+mFGX4vwMtQVf5O5VUkhzKyNG7HoUvRfwn8hEufuWG/uMBk:OWFFGIvwMwBcPh+n79fALk
TLSH 1B94232AD34B64B7BE5E9FB9CAEFA21A2ABD70D530541583B71F163315004A2924C3F7
Reporter abuse_ch
Tags:FormBook gz


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: services.mailserver.ae
Sending IP: 74.124.219.187
From: SUNLINE <yousif.alsharif@ysalc.ae>
Subject: RE: Payment Confirmation
Attachment: SOA.gz (contains "SOA.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
113
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-10-27 08:27:52 UTC
AV detection:
4 of 48 (8.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

gz 8f9f7c1b25fdc44fe44cd0ed39b10bfa66bf9ca2019edb64ddefb2a6f2813bfd

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments