MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fbc74bac868ddd18b7b8214f0a8d07458012a51b7659eda32ec19faa001e4534. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fbc74bac868ddd18b7b8214f0a8d07458012a51b7659eda32ec19faa001e4534
SHA3-384 hash: 17f4d2044070731e84974a75020f6e7802b7b5fec298fa1139b7d1ed99f2b7a6036004912022084cbd3a055555c9e376
SHA1 hash: 04b920635e4d378ac52b938003e3bbec6b2d80ed
MD5 hash: 4da15fe2907aeaa0f350b49a1bf0a067
humanhash: beryllium-one-fourteen-quebec
File name:payment.zip
Download: download sample
Signature FormBook
File size:398'577 bytes
First seen:2020-05-06 17:10:23 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:VN8mENuueiEE07zEue4vg6KMHqp0bPich5YLIa:xWCfYfiHraL9
TLSH 528423623243AC744D9730826548E03F7868AF6EFD9225526B05DCCD612D0FA6FF1F99
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: mail.armaniousgroup.com
Sending IP: 196.219.214.52
From: Iffat Marashy <peter.remon@evapharma.com>
Subject: Fwd:payment from bank
Attachment: payment.zip (contains "payment")

FormBook payload URL:
https://paste.ee/r/Wy6V2

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Scrami
Status:
Malicious
First seen:
2020-05-06 17:52:57 UTC
File Type:
Binary (Archive)
Extracted files:
17
AV detection:
23 of 48 (47.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip fbc74bac868ddd18b7b8214f0a8d07458012a51b7659eda32ec19faa001e4534

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments