MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 21df33a5dd5ab7048c0be0db146ccbe0b16c6f5b2a06c000e4286f22bb3eb521. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 21df33a5dd5ab7048c0be0db146ccbe0b16c6f5b2a06c000e4286f22bb3eb521
SHA3-384 hash: a8cb7ad135a5c3823be3b0e277e3780dfaea75789de03fd59d87ce9a633bc55c522f3f438a8a4e6006d672523f0edbf9
SHA1 hash: 2902d756b7fe76bf04ff4490a48e9ab0a5a48578
MD5 hash: 496554c41b6e580daa5f72d428c8eb6c
humanhash: helium-violet-angel-mockingbird
File name:PO SPL 4223020POIX_XLS.arj
Download: download sample
Signature Formbook
File size:478'165 bytes
First seen:2020-10-27 12:14:25 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:qf25xISvVpbfswRbK+HeMmnrvzG7Pz8bEn8GFD:wCVR0w9HexLCv8nGFD
TLSH D1A42398B68EB7AF1F1C9A43378BBCE7563E9AB12047678CC70F95CE0D1417605066E8
Reporter abuse_ch
Tags:arj FormBook


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: super.cdtsrv.com
Sending IP: 50.115.18.159
From: Puji Astuti <sales-puji_a@muliajayamandiri.com>
Subject: RE: SALES CONTRACT FE2010138015 CB-608 88MT - Nov shipment
Attachment: PO SPL 4223020POIX_XLS.arj (contains "nnaRAsmVjCPEdRk.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Backdoor.Androm
Status:
Malicious
First seen:
2020-10-27 02:10:59 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 21df33a5dd5ab7048c0be0db146ccbe0b16c6f5b2a06c000e4286f22bb3eb521

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments