MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6e87010bddef671db2fa1cc3cba588c9d80eee5718a4cbb0d35829993f811dc4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 6e87010bddef671db2fa1cc3cba588c9d80eee5718a4cbb0d35829993f811dc4
SHA3-384 hash: 0305e34358749482d311fa8f23c9271233974c8514e1783f347e37a8e0863bb235191347e978328dabc2833c95eb4eb8
SHA1 hash: 77b8358a2ccc484ca253f472dd103748d0e24f17
MD5 hash: fe1becfee1d1f421ad2e75b884d092b9
humanhash: papa-red-oscar-helium
File name:zicni prijenos.zip
Download: download sample
Signature Formbook
File size:1'141'722 bytes
First seen:2020-10-13 14:46:59 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:A/euPERuV4SB3CQhIOj2eOmapCMi6nP+O9yTMT605dVO5RTWwF:A/euc6LBfIOjF/aLiImdaS3
TLSH 5E353322D6B4F2C3CC655A5306A026E4788B5BE52AFFF0034FA5D557EAC58C940FCA71
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: tur2.hipotenus.com
Sending IP: 213.159.30.161
From: obrtnicka-komora-zagreb@zg.t-com.hr
Subject: AW 10-13/2020:žični prijenos
Attachment: zicni prijenos.zip (contains "zicni prijenos.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Worm.Ramnit
Status:
Malicious
First seen:
2020-10-13 12:47:07 UTC
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 6e87010bddef671db2fa1cc3cba588c9d80eee5718a4cbb0d35829993f811dc4

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments