MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca44d4aadf6c7f4120ab51143b5d05a46737ad470cf593c372901ca0f0ee2b2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ca44d4aadf6c7f4120ab51143b5d05a46737ad470cf593c372901ca0f0ee2b2f
SHA3-384 hash: 196b213ad0c290753c8a31b10e0a15918458b96a3c7f1a62bfc84c6a4c82e680ce55c268c51ea9af20eb8bb56e30f1ac
SHA1 hash: 934bb6a6460644ccf60766b6b048b54ff735be90
MD5 hash: fd2402999d516ef1ae4037db15d7f75a
humanhash: louisiana-arkansas-beer-fillet
File name:PG2005005.rar
Download: download sample
Signature FormBook
File size:362'837 bytes
First seen:2020-05-21 09:04:32 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:sORBGltXbK8GU3bjSsCj9jEwow3w/fV9F7z40oMte2nl1G8WhqVEz44xxKx:dglpbKBU3bjZCj5E1w3sF7ErMt7V02
TLSH 3674239544D7E75938F14160CA9C1F9722F458A3B89A43E63339C3BFF271B6A97A80C1
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: 3sapparel.co
Sending IP: 111.90.140.230
From: Ahmad Al-Qasim <al-qasim@colorntouch.co>
Subject: RE: RE: 0322/PO/GEN/IV/2020
Attachment: PG2005005.rar (contains "PG2005005.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-21 05:41:59 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
15 of 48 (31.25%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar ca44d4aadf6c7f4120ab51143b5d05a46737ad470cf593c372901ca0f0ee2b2f

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments