MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bfca3b18fad4683186f3dae57d724a8ef34539dddcf0f8eec13d23eeff81ff43. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bfca3b18fad4683186f3dae57d724a8ef34539dddcf0f8eec13d23eeff81ff43
SHA3-384 hash: c72c2c491a183da4784b617fdcad1ff56bd7337ab067bb0385b6c2c25cb147118b28e92082cc319217e53b790e2d7ce9
SHA1 hash: 1be1bae27580157e2a24b5896944c6349982e4d0
MD5 hash: f9f6501f282073d2213b8d15f508bf33
humanhash: carolina-maine-item-whiskey
File name:New Inquiry.pdf.gz
Download: download sample
Signature FormBook
File size:240'451 bytes
First seen:2020-07-02 06:50:15 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:HfOD8edpO8hxD5puI1Pw6sH8OWwsf2TOvtGmbb35A:/OBbhxDlmAvtGAz5A
TLSH 723413C089FF69CE935F81A25B11AD6BE926B74552B27EA0C168B2F30342FC670C5F51
Reporter abuse_ch
Tags:FormBook gz


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: 313.jiangzhoulmt.casa
Sending IP: 161.35.30.80
From: inom@uzermak.com
Subject: Innovative Investors Inquiry
Attachment: New Inquiry.pdf.gz (contains "New Inquiry.pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-02 06:52:06 UTC
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

gz bfca3b18fad4683186f3dae57d724a8ef34539dddcf0f8eec13d23eeff81ff43

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments