MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d64506f2b10920a8b985abec5d9b7666a1bb9825fc082d377705c5aa035ef5f1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d64506f2b10920a8b985abec5d9b7666a1bb9825fc082d377705c5aa035ef5f1
SHA3-384 hash: eeb9ea517bf28abff8b61c38414700c9036792bae7e6f9f411578a4e91fca147222717e91a815fe787fbab2be56535d8
SHA1 hash: a5affc1065acd571aa68f38a35fff14301e9c29e
MD5 hash: 829e64a343002e170329e0c3f4a0b910
humanhash: grey-pasta-floor-fillet
File name:Factura FE2000716273.zip
Download: download sample
Signature FormBook
File size:547'363 bytes
First seen:2020-07-13 11:12:49 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:h9JOq3fGW0S74Tq+oeecg3TNk6AXaNhW6wlZw5Fkmnn9e8W9YW:h9J1v30FXuAXaNsTXqHnn9NWX
TLSH 3CC423D83A8F08CC515B5850CF51A1EF6A5E093EA47F48E83A59C2B019621F7E7339E6
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: fnadk-25.srv.cat
Sending IP: 46.16.62.251
From: Administracion <info@fedizseguros.com>
Reply-To: info@fedizseguros.com
Subject: CONSULTA TRANSFERENCIA FRA. Nº 6273 y Fr. Nº 6274.
Attachment: Factura FE2000716273.zip (contains "Facturas.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
93
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-13 11:14:08 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip d64506f2b10920a8b985abec5d9b7666a1bb9825fc082d377705c5aa035ef5f1

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments