MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 11e76c8d99d00f5899b833f4bdb6d61b1eb4cce920a27e67252813185134c61d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 11e76c8d99d00f5899b833f4bdb6d61b1eb4cce920a27e67252813185134c61d
SHA3-384 hash: 97fce426eb81119b16fb705610a659207504c5a502e7aa68c93151166944fc61380e308bc8ba2820165ac7c7d549c98d
SHA1 hash: 165afb979100a7ae93625ba0be8ce949ded946b5
MD5 hash: 4c977cf1f78b8973142ff110d53f7279
humanhash: arkansas-cardinal-berlin-red
File name:Payment swift copy.zip
Download: download sample
Signature Formbook
File size:602'580 bytes
First seen:2021-01-11 08:52:31 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:f77oFCIXwHhUz62SflR4AiQNimRcO6JfCydLZTCyC0a/l/bW/z+Y4VMh2G1hAwsM:q3AHhwqlRYyiKcOWT0l6/U8xsWN
TLSH EFD423809440200868B0B7487FDB6966D5287EB38724C5B3C6F3798AE1FFE46959D1FB
Reporter abuse_ch
Tags:FormBook HSBC zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: server.biompun.tk
Sending IP: 185.104.112.228
From: HSBC Advising Service <advising1_services@mail.hsbcnet.hsbc.com>
Reply-To: HSBC Advising Service <no-reply@mail.hsbcnet.hsbc.com>
Subject: Notification of Fund Transfer via HSBC Bank
Attachment: Payment swift copy.zip (contains "Payment swift copy.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Emali
Status:
Malicious
First seen:
2021-01-11 04:53:24 UTC
AV detection:
3 of 46 (6.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 11e76c8d99d00f5899b833f4bdb6d61b1eb4cce920a27e67252813185134c61d

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments