MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b042e4bdfe19df2aa474fd5e2294aecc9a07d447c96466db7a7e20316d885634. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b042e4bdfe19df2aa474fd5e2294aecc9a07d447c96466db7a7e20316d885634
SHA3-384 hash: d0a0aa8a79a98816442c7d334ba8f0c85ccb43b18d93e37547aed95ffd050c5eed7300bba7bea7cb21f9967a7715dbcd
SHA1 hash: 90dc42555e12af423038ef46e5d172f1283c3163
MD5 hash: 384b0d9dfb95b569779a0d9971adedce
humanhash: river-oregon-california-montana
File name:384b0d9dfb95b569779a0d9971adedce.exe
Download: download sample
Signature FormBook
File size:358'912 bytes
First seen:2020-06-03 08:01:58 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f22635dbd118c4c2567a245ddd95bb69 (9 x FormBook)
ssdeep 6144:CQ8xGU8PImbmdIN5NsYC8GvdhemLn9YwfHbLw:rrbm+N5NlQdheuawP3
Threatray 4'968 similar samples on MalwareBazaar
TLSH BC74D041E6A2D43DF14AC77D6D6872528A78BDD29226B2C33AE43BC8DE331834535367
Reporter abuse_ch
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-06-01 22:06:00 UTC
AV detection:
25 of 31 (80.65%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

Executable exe b042e4bdfe19df2aa474fd5e2294aecc9a07d447c96466db7a7e20316d885634

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments