MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca73dbdd5e448a5dd2c4cad8224ef9923467b946ceec0e7d7393c5baba070d00. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: ca73dbdd5e448a5dd2c4cad8224ef9923467b946ceec0e7d7393c5baba070d00
SHA3-384 hash: b37c9deefc50105b61bc546e2b80348942c44a7fe1f5ed0839f2d3dee215db25cff9949f639ee141c0d2e16e4df76256
SHA1 hash: 43ab95a861059bd4b0960bbc79ef212650661a51
MD5 hash: 955aa447603ce05e22dbd420ae8b7e4a
humanhash: king-alaska-yellow-dakota
File name:CCF0382890.zip
Download: download sample
Signature Formbook
File size:220'062 bytes
First seen:2021-02-25 14:19:38 UTC
Last seen:2021-02-26 17:40:38 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:ZpwwgWGEhq4OlaoX9lWMXoi2bjKfXB4nG:b5g1laW0MX5EjKZcG
TLSH 0E2412A9E7E375F70B91384796313C9E1090732274B5C5FBDAB5CE08AD622562AC0B1E
Reporter GovCERT_CH
Tags:FormBook

Intelligence


File Origin
# of uploads :
4
# of downloads :
149
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Spyware.Artemis
Status:
Malicious
First seen:
2021-02-24 22:23:34 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip ca73dbdd5e448a5dd2c4cad8224ef9923467b946ceec0e7d7393c5baba070d00

(this sample)

  
Dropped by
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments