MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ea8c01b863af915ad3b0e804b6cd1726e34cf5c74dc3060975caa64e9a7c6c16. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ea8c01b863af915ad3b0e804b6cd1726e34cf5c74dc3060975caa64e9a7c6c16
SHA3-384 hash: 2327235c77f41c6d6b600bce6cff0acf245a08e776b10c5bbc7f101facc229d2208a5db4db21f07cddd62a94b9e69a49
SHA1 hash: 0670d78722394c91484e5fec5f401880dc6a79fc
MD5 hash: 05749b1813eaf96025c6ec5884dcde1e
humanhash: table-sierra-burger-snake
File name:Shipping Documents Invoice Packing List PDF.r09
Download: download sample
Signature FormBook
File size:241'567 bytes
First seen:2020-07-02 06:55:12 UTC
Last seen:Never
File type: r09
MIME type:application/x-rar
ssdeep 3072:s/UeMuIRPAXg0Yv7/uQU/XDjQSlLHqfIMa0QC26Xu11goLeiERE1rvslS31KnHvh:wxM3P5xYXfZqE0N26s7LrEmrEjAtszsQ
TLSH 6D342263F190B51C66E2FEAD1921D77CD43A8B1432C854D48DAD88EEED21944CDE2BD3
Reporter abuse_ch
Tags:FormBook r09


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: checkpt.com
Sending IP: 103.125.191.31
From: Jasim Uddin <Jasim.Uddin@checkpt.com>
Subject: New Shipment (docs)
Attachment: Shipping Documents Invoice Packing List PDF.r09 (contains "Shipping Documents (Invoice & Packing List) PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
96
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Swotter
Status:
Malicious
First seen:
2020-07-02 06:57:03 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

r09 ea8c01b863af915ad3b0e804b6cd1726e34cf5c74dc3060975caa64e9a7c6c16

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments