MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e8e016a2ee1c64ca21b8e272647e9c9cda49bb6e2400cff8d4b6d16b6ba1019a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e8e016a2ee1c64ca21b8e272647e9c9cda49bb6e2400cff8d4b6d16b6ba1019a
SHA3-384 hash: 8ec97bf97f6fcfa2b4e8225fe4a0f26c729645f1b075fd18e7ceb4f2cb72eaad55b8dbb4f48f08114a61710265c529c6
SHA1 hash: c883f2156705aed3e40d708efdc6b9ff96302ea7
MD5 hash: 6f541c525b8d39a9e5557b98450aeb6d
humanhash: timing-beer-golf-michigan
File name:QUOTATION.LZH
Download: download sample
Signature FormBook
File size:266'530 bytes
First seen:2020-06-17 10:10:51 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:Wk22MU0hJImZbxkSo0pe1+30ss5ReiQFxm/NakGK:WX00hJIm/kSL303MOakGK
TLSH B5442383CB4F5C78689B620ECC20A72525E2537A521A5375041BEEC66D3273F1ECEB69
Reporter abuse_ch
Tags:FormBook lzh


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: vps.tiantuct.com
Sending IP: 45.95.169.92
From: PMRG LTD<info@tiantuct.com>
Reply-To: fra_white33@yahoo.com
Subject: QUOTATION
Attachment: QUOTATION.LZH (contains "QUOTATION.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-17 10:37:28 UTC
AV detection:
23 of 48 (47.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar e8e016a2ee1c64ca21b8e272647e9c9cda49bb6e2400cff8d4b6d16b6ba1019a

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments