MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d0b886db39ab25fa4bada1ba69eed8a5091ed8b8eab0ca2091dbe2aef94a8ea8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d0b886db39ab25fa4bada1ba69eed8a5091ed8b8eab0ca2091dbe2aef94a8ea8
SHA3-384 hash: 51bd9471ae168dcfee1e7311b614a6e80a5e219b2af6e48d2ef1b7ac5a392f0a054f4048d6097343d361e0a752e48301
SHA1 hash: fea40ba14dd5da277451a1773db37b5f89e9058c
MD5 hash: 95e4f8f165d3ec3fbe275e94133c170a
humanhash: leopard-april-sink-moon
File name:INV_00976HK.rar
Download: download sample
Signature FormBook
File size:279'257 bytes
First seen:2020-06-17 06:12:25 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:VBQK0beCpqxC9SdlqSItUvxVS4VR5M6j29qhiTz9ygpabXcSmTlg9D7m5:VB50bN0PISItUvxHRS6jYWSJEZ+GFw
TLSH 465423E97116010B95DAEAD703992F17E4B90CFBF86CD109673ED762334A1AC087ED68
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: disey.com.mx
Sending IP: 184.154.61.154
From: MML Law Firm <ventas@srr.com.mx>
Subject: COURT SUE M1
Attachment: INV_00976HK.rar (contains "INV_00976HK.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-17 06:14:07 UTC
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar d0b886db39ab25fa4bada1ba69eed8a5091ed8b8eab0ca2091dbe2aef94a8ea8

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments