MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 46a21ddfe48ea334fe15523aef0341134837de93d48aced84d3fa492853a94f1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 4
| SHA256 hash: | 46a21ddfe48ea334fe15523aef0341134837de93d48aced84d3fa492853a94f1 |
|---|---|
| SHA3-384 hash: | ed45709b0ab837d55fe820f8afbab48c136d647109a912be589b51008a26d26e10746269c8e64aa7b3bdc3b9d54dd4ab |
| SHA1 hash: | a82800203482fbfa4f697886fa0cef32a2767a64 |
| MD5 hash: | aa22a957f6e706bee6a964d87ebb0785 |
| humanhash: | tennessee-eleven-lion-north |
| File name: | Invoice_20210115122010.iso |
| Download: | download sample |
| Signature | Formbook |
| File size: | 907'264 bytes |
| First seen: | 2021-01-15 15:56:32 UTC |
| Last seen: | Never |
| File type: | iso |
| MIME type: | application/x-iso9660-image |
| ssdeep | 3072:VIVOeHH9wjnRZFUWlwQlNzXWV9SlO8p+fekPL7oi0qNbdL4JaKGZVni4Ee5wnh2:VQOEHmjnRIWlwmzXWDSEZLVhZ451e8 |
| TLSH | 6515DF97B27017E4F540D938F3615BAA3C23AE166C80011FAF6CB569BA7E740612FD8D |
| Reporter | |
| Tags: | DHL FormBook iso |
abuse_ch
Malspam distributing Formbook:From: DHL Express INC <support@dhl.com>
Subject: Consignment Notification: You Have A Package With Us
Attachment: Invoice_20210115122010.iso (contains "Invoice_20210115122010.scr")
Intelligence
File Origin
# of uploads :
1
# of downloads :
235
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Zmutzy
Status:
Malicious
First seen:
2021-01-15 10:28:49 UTC
AV detection:
7 of 46 (15.22%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Formbook
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.