MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 148690d2f19bee2b41423d1e2d00e4c1e672640a73cd975c7aac20731091735a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 148690d2f19bee2b41423d1e2d00e4c1e672640a73cd975c7aac20731091735a
SHA3-384 hash: 8493b153b9008d43f2e6243aec474f55f3d15ef6c8e6f3171e848b63c6889bcb08e19033d5850cc2871af0f61a19c3a2
SHA1 hash: e2d28617bdd8505fcbb44989d683ab7179cba52c
MD5 hash: 802ba2e7f890bc1412ed513f558d18ae
humanhash: magazine-cola-mobile-crazy
File name:ATTACHED QUOTATION.IMG
Download: download sample
Signature Formbook
File size:1'245'184 bytes
First seen:2020-10-19 13:20:30 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:UiqQoqGn39lWnEPA2QAinFEYw+aPUg9U:fqQoH3unilixH0v
TLSH 1D45D021B6C1C4B4E4A51A7308699E450B6EFB730B385C53FBDC99CD97B0BC0953AB1A
Reporter abuse_ch
Tags:FormBook img


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: rdns0.hyterm.xyz
Sending IP: 134.209.44.46
From: Husain Shabbir<office@hyterm.xyz>
Subject: HASHTRON INTERNATIONAL TRADING RFQ DEC.Q4.
Attachment: ATTACHED QUOTATION.IMG (contains "PROFORMA C20201009.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

img 148690d2f19bee2b41423d1e2d00e4c1e672640a73cd975c7aac20731091735a

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments