MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d21375e24681a3470425ab4eba8276f415821e9e06b28567091b206cbd578361. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d21375e24681a3470425ab4eba8276f415821e9e06b28567091b206cbd578361
SHA3-384 hash: c47a165a3d9d923017f5085c419991ea6abf2fee4d96b41a352a4dca27db4c06a8a5bcd642fbe27c8379369b9d2a6ee0
SHA1 hash: 666caf6524dd0a71472f32176cd7408b3faac4e1
MD5 hash: b82e45a9c8b6702d8f2d85c9212e255b
humanhash: lake-low-failed-green
File name:TC Schedule Others for GOODS_MRCSB.rar
Download: download sample
Signature FormBook
File size:257'529 bytes
First seen:2020-05-11 08:04:44 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:M0RovgWYupGg1DLJVbbkH1QSYb0EBlb9zHqaO4AY64hMzy7JC1gn:xRoGupGg1XcHSSYbD7bAx4hMzD1gn
TLSH 08442333C71335ED2A0F538E81F7449358307813D887D2F79A71659A58E7B0A89E26E7
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: caracal.birch.relay.mailchannels.net
Sending IP: 23.83.209.30
From: mazirul.rosli@petronas.com
Subject: Fwd: FW: [TA2019] URGENT: Request for Quotation: MRCSB-T19-All-010-MNAMR-001RB
Attachment: TC Schedule Others for GOODS_MRCSB.rar (contains "T&C Schedule & Others for GOODS_MRCSB.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-11 08:36:55 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
16 of 48 (33.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar d21375e24681a3470425ab4eba8276f415821e9e06b28567091b206cbd578361

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments