MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 15bd021d7edf28a4e80ab5d8541a0cf5814561d63c09c6387573450ac3685471. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 15bd021d7edf28a4e80ab5d8541a0cf5814561d63c09c6387573450ac3685471
SHA3-384 hash: 69052fbc69264764be4b3aac199d90cf250271d47047b0333f20e331b84989d732c2a6c06dc0dff796bbb83393de8c75
SHA1 hash: 17d9cf36caf3a571f1ed54538b4834e98f24f8e2
MD5 hash: 12ae9750b71de8f36550c07ca0f06f0e
humanhash: nevada-east-red-sink
File name:Revised Invoice No CU 7035.rar
Download: download sample
Signature Formbook
File size:315'762 bytes
First seen:2021-04-08 07:04:17 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:jAwxa4yLLQpYeJrQ79S9uig3tZ9xgentRN5mIdAvU85PUPpV:La4yLPeJs7tjtdlntRSIdAvU856H
TLSH E064232900AD95FEE9412FB9AB49211D3C5382AC7F3664E77C508D7E05FDD9E60B8078
Reporter abuse_ch
Tags:rar


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: ip116.ip-147-135-107.us
Sending IP: 147.135.107.116
From: <sly.etuk@vertiv.com>
Subject: Revised Invoice
Attachment: Revised Invoice No CU 7035.rar (contains "Revised Invoice No CU 7035.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
101
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar 15bd021d7edf28a4e80ab5d8541a0cf5814561d63c09c6387573450ac3685471

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments