MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f954bbd6366067c6c9c7380cc5765bb5dba285fecc2851e1fdc3b276806263f8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f954bbd6366067c6c9c7380cc5765bb5dba285fecc2851e1fdc3b276806263f8
SHA3-384 hash: c2f013d0fc1ed1d9f753c338f45165b2c2a7a99de84937044f79f9aa3ecb6d036a0f5e19e91c366fbc1e93896ea7d983
SHA1 hash: b58c570e36c24f36960b86847b736e4922d58b1d
MD5 hash: e1e7473137d0e0fb7b8e0b2ddb9f82ec
humanhash: earth-island-green-march
File name:Request for Quotation-BV-76435020.arj
Download: download sample
Signature FormBook
File size:376'292 bytes
First seen:2020-06-26 06:42:46 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 6144:C0xx7HDz9qNKmsqErsxZ+/y4WOq6DonYoMz9iH62MwtVdiTL1cf8P:bxpjYPsh4xZdvWsnYoIj2Mw50B
TLSH 378423E1E092FA3486CE8E479742AEAEDCE940D0EBF5DCEEA4A155D0EB280F45F11514
Reporter abuse_ch
Tags:arj FormBook


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: cosmo.securesvr.net
Sending IP: 139.99.69.157
From: Jakub Novák <jakubnovak@bvelektronik.cz>
Reply-To: Jakub Novák <mahdi_bashii45@yahoo.com>
Subject: Request for Quotation - BV elektronik
Attachment: Request for Quotation-BV-76435020.arj (contains "Request for Quotation-BV-76435020.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-26 06:44:04 UTC
AV detection:
20 of 31 (64.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

arj f954bbd6366067c6c9c7380cc5765bb5dba285fecc2851e1fdc3b276806263f8

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments