MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0c125aaea07b9b97fedc0e2022f3951ef3cdefda9110c3b1f4955abeeed9ac22. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 0c125aaea07b9b97fedc0e2022f3951ef3cdefda9110c3b1f4955abeeed9ac22
SHA3-384 hash: ff3b4913cdca81d514ed12ce94ee41e5adbc07e2c742c55321fe5e94a06db9c802c726a5bfe5d69b79d7c187d19404f5
SHA1 hash: fbd9b3df410bc54b031e7f36ed40c0f2e3bb0f73
MD5 hash: bc32021093147eac3742eba7f8a42532
humanhash: eleven-green-wisconsin-eighteen
File name:Request for quotation, Purchase Order no 1093121.zip
Download: download sample
Signature Formbook
File size:1'014'101 bytes
First seen:2021-01-07 14:00:10 UTC
Last seen:2021-01-07 14:01:04 UTC
File type: zip
MIME type:application/zip
ssdeep 24576:5Wu0rmnx/DTkKH6LRjlaBs6b0Jjeoqj9UO4Ho/PK:5WanxRaNjlesk0JSCFH/
TLSH 5725237BCDA82C129EE39A47913D649DA1B4DF4829F70A2D4669DE4D18C8CC5B30FCD2
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: server3.bsname.com
Sending IP: 111.91.236.19
From: Joseph Liew <joseph.liew@petronas.com>
Reply-To: Joseph Liew <josephp.liew@outlook.com>
Subject: [Petronas]: Request for quotation, Purchase Order no: 1093121
Attachment: Request for quotation, Purchase Order no 1093121.zip (contains "Petronas ITQ format.exe")

Intelligence


File Origin
# of uploads :
2
# of downloads :
250
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Noon
Status:
Malicious
First seen:
2021-01-07 14:01:05 UTC
AV detection:
11 of 46 (23.91%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 0c125aaea07b9b97fedc0e2022f3951ef3cdefda9110c3b1f4955abeeed9ac22

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments