MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 41b61b1b6d2e01fe382dc6fae97862e773270c6606912d343b2230647caf07c4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 3
| SHA256 hash: | 41b61b1b6d2e01fe382dc6fae97862e773270c6606912d343b2230647caf07c4 |
|---|---|
| SHA3-384 hash: | 1c95b2c61a5fc97b66e9aae18d5606cb51b8682e77aac4ce2b48ef679b0744625b137868719ae349c15c603cf6018bcf |
| SHA1 hash: | be624e187cd25de4d526e7fd2e52a450158e79ea |
| MD5 hash: | ee85d72d23c5ac0114c161e77133bd07 |
| humanhash: | football-eleven-pizza-high |
| File name: | Lista comenzii noastre.zip |
| Download: | download sample |
| Signature | Formbook |
| File size: | 1'053'848 bytes |
| First seen: | 2020-10-13 12:30:27 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 24576:PHD1q5iRrrOt2QEY0pjFY+y7JrQoMZ3EbMicTbJvykz+lSEsr:PgYtrOiRFYzjMZuLcTbJvyk3b |
| TLSH | 44253353F95FCD27BC267936FBA0417F1193E89F85517E7473384A1CB9311A212AA8C8 |
| Reporter | |
| Tags: | FormBook zip |
abuse_ch
Malspam distributing unidentified malware:HELO: server.linux92.papaki.gr
Sending IP: 195.201.61.173
From: Ioana Tataran <info@bibusmetals.ro>
Subject: Re: Re: Comandă de achiziție
Attachment: Lista comenzii noastre.zip (contains "Lista comenzii noastre.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
95
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Spyware.Noon
Status:
Malicious
First seen:
2020-10-13 12:32:08 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
2/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.