MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bd255e714e52cf21202645362573cedb2285c67f6e6e16b59e14c07c0b1ac189. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bd255e714e52cf21202645362573cedb2285c67f6e6e16b59e14c07c0b1ac189
SHA3-384 hash: ebee3203e0b0fc4fe0e55a5e89e5b61b25e4b46d77561504575e987715e79c1d3622cb0ffbf0833faf4d73af287b341d
SHA1 hash: 442d49effddd88a03ac231581a201cd69efeb823
MD5 hash: 70bafbd18ba87ca0706362782b903f63
humanhash: finch-early-rugby-kansas
File name:2020.07.06.rar
Download: download sample
Signature FormBook
File size:341'284 bytes
First seen:2020-07-06 08:15:25 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:25uxbr809qf0wOM0lcaMHPrglHfDyXufzUS/IBCMavsIz0IOadN4Ek:9P/s9ZZrPrglr9xIkMavsQBW
TLSH 5B7423547DF0142C96E38EDD259F3370B19A34FA8DEC171C967326E8C36EA851CE6059
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: ns1.aparatologiadeestetica.com
Sending IP: 91.142.208.185
From: antika exim<antika.exim@gmail.com>
Subject: Re:INQUIRY-Transfer
Attachment: 2020.07.06.rar (contains "2020.07.06.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-07-06 08:17:07 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar bd255e714e52cf21202645362573cedb2285c67f6e6e16b59e14c07c0b1ac189

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments