MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d8e0769ada04d3face55959134a7eee5e55ef10f65eedeae65d9218e4371ace4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d8e0769ada04d3face55959134a7eee5e55ef10f65eedeae65d9218e4371ace4
SHA3-384 hash: b0806ee070d593dc197f10738847ed73d3e59f6668c69d8a56a29acda56e78319b6b32fe9e5a88faa264cdc071c518ec
SHA1 hash: 61d5bd761f346d04d94e653e51898f1c588d7c4b
MD5 hash: 6e5c8107462ffed31886a7f9491722af
humanhash: cat-april-sad-jersey
File name:PO328632.zip
Download: download sample
Signature Formbook
File size:456'447 bytes
First seen:2020-06-28 09:13:43 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:qrnlQl/YiYCl//rxQVQhxvEA70XF641Devw9j/xzv9XJ:qrlQlDzp/rSmfEACFH1DeYF1
TLSH E1A433CFCBC7E1DD385F797E9111F9404C98C49A85027CA9623AB168953FAB411EA8FC
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: regular1.263xmail.com
Sending IP: 211.150.70.200
From: Leona <admin@yingshitech.com>
Subject: Re:new order
Attachment: PO328632.zip (contains "PO328632.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-28 09:15:06 UTC
AV detection:
35 of 48 (72.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip d8e0769ada04d3face55959134a7eee5e55ef10f65eedeae65d9218e4371ace4

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments