MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 21b2c97f10dc75b063ac9e53c473749c498ebf37bfa82b5d63dcedafbc50e071. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 21b2c97f10dc75b063ac9e53c473749c498ebf37bfa82b5d63dcedafbc50e071
SHA3-384 hash: c18219f1e832b2a8ab688587f0bcde8fff2c975bdaa4c4153576050024ec2fa1df2e83ed12fac11b29b6803e348dd791
SHA1 hash: 3cc9a7efbb6fa0498d1a980320397aebd5bece3f
MD5 hash: d9f09e4335672eabbe9f93e9506fe7a2
humanhash: connecticut-high-cup-magnesium
File name:PO646756575646.zip
Download: download sample
Signature Formbook
File size:246'539 bytes
First seen:2020-10-27 10:15:53 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:8eW0p5C/I1wt5iWVNLSjjhv9VWdVx3A14bzwE3Qv+RzUXoxy:FW0p5Ut5ieS3hHWdVdA00WQCUYg
TLSH C13423D337174A894FC9C840A3B6E72603BA1C5389B0EBBDA7947A7BC17E0786975107
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: lucky1.263xmail.com
Sending IP: 211.157.147.135
From: 杨玲 <sales2@teweiband.com>
Subject: PO#646756575646
Attachment: PO646756575646.zip (contains "PO#646756575646.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
103
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 21b2c97f10dc75b063ac9e53c473749c498ebf37bfa82b5d63dcedafbc50e071

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments