MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 46a21ddfe48ea334fe15523aef0341134837de93d48aced84d3fa492853a94f1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 46a21ddfe48ea334fe15523aef0341134837de93d48aced84d3fa492853a94f1
SHA3-384 hash: ed45709b0ab837d55fe820f8afbab48c136d647109a912be589b51008a26d26e10746269c8e64aa7b3bdc3b9d54dd4ab
SHA1 hash: a82800203482fbfa4f697886fa0cef32a2767a64
MD5 hash: aa22a957f6e706bee6a964d87ebb0785
humanhash: tennessee-eleven-lion-north
File name:Invoice_20210115122010.iso
Download: download sample
Signature Formbook
File size:907'264 bytes
First seen:2021-01-15 15:56:32 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 3072:VIVOeHH9wjnRZFUWlwQlNzXWV9SlO8p+fekPL7oi0qNbdL4JaKGZVni4Ee5wnh2:VQOEHmjnRIWlwmzXWDSEZLVhZ451e8
TLSH 6515DF97B27017E4F540D938F3615BAA3C23AE166C80011FAF6CB569BA7E740612FD8D
Reporter abuse_ch
Tags:DHL FormBook iso


Avatar
abuse_ch
Malspam distributing Formbook:

From: DHL Express INC <support@dhl.com>
Subject: Consignment Notification: You Have A Package With Us
Attachment: Invoice_20210115122010.iso (contains "Invoice_20210115122010.scr")

Intelligence


File Origin
# of uploads :
1
# of downloads :
235
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Zmutzy
Status:
Malicious
First seen:
2021-01-15 10:28:49 UTC
AV detection:
7 of 46 (15.22%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

iso 46a21ddfe48ea334fe15523aef0341134837de93d48aced84d3fa492853a94f1

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments