MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 15bd021d7edf28a4e80ab5d8541a0cf5814561d63c09c6387573450ac3685471. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 4
| SHA256 hash: | 15bd021d7edf28a4e80ab5d8541a0cf5814561d63c09c6387573450ac3685471 |
|---|---|
| SHA3-384 hash: | 69052fbc69264764be4b3aac199d90cf250271d47047b0333f20e331b84989d732c2a6c06dc0dff796bbb83393de8c75 |
| SHA1 hash: | 17d9cf36caf3a571f1ed54538b4834e98f24f8e2 |
| MD5 hash: | 12ae9750b71de8f36550c07ca0f06f0e |
| humanhash: | nevada-east-red-sink |
| File name: | Revised Invoice No CU 7035.rar |
| Download: | download sample |
| Signature | Formbook |
| File size: | 315'762 bytes |
| First seen: | 2021-04-08 07:04:17 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 6144:jAwxa4yLLQpYeJrQ79S9uig3tZ9xgentRN5mIdAvU85PUPpV:La4yLPeJs7tjtdlntRSIdAvU856H |
| TLSH | E064232900AD95FEE9412FB9AB49211D3C5382AC7F3664E77C508D7E05FDD9E60B8078 |
| Reporter | |
| Tags: | rar |
abuse_ch
Malspam distributing unidentified malware:HELO: ip116.ip-147-135-107.us
Sending IP: 147.135.107.116
From: <sly.etuk@vertiv.com>
Subject: Revised Invoice
Attachment: Revised Invoice No CU 7035.rar (contains "Revised Invoice No CU 7035.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
101
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.