MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 514f2505a743ed05cba704023ead027e7fe85e1dd057689bf66eb029f0672c99. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 514f2505a743ed05cba704023ead027e7fe85e1dd057689bf66eb029f0672c99
SHA3-384 hash: 2b3a75820fe6460d952335a1e15334f4bebfcbc7e1a9937f2ffa3f4dfc30c49b0f89a8ab6ccdaf5243df98bab744499d
SHA1 hash: 07ddc431c9c2204419391c4e7f0427d87fd49a8a
MD5 hash: 5ef6a9070c3b603d6a9d914799441525
humanhash: delta-maryland-nuts-cat
File name:novi poredak.zip
Download: download sample
Signature Formbook
File size:517'214 bytes
First seen:2020-10-12 07:31:58 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:5vxPqtye2QrCEldPjRoPWQmkBQDjkZ9KbZ5kQjhaUtZV1EM+/9cfl:P4yarCED7RoOQp6DjknKlTjXtZ0d/90
TLSH 69B4231ADD798E0AE63F40FA00566BF36DF00E5538B09736E4AAE1C71634E5F81246DB
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

From: Vitomir Slišković <info@makino.eu>
Subject: Re: Re: Zahtjev za ponudu
Attachment: novi poredak.zip (contains "novi poredak.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
93
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2020-10-12 07:33:08 UTC
AV detection:
2 of 48 (4.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 514f2505a743ed05cba704023ead027e7fe85e1dd057689bf66eb029f0672c99

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments