MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 78fe3ed0e50009101124d757b0ff13967a5eda787ddad427276779c4d343ce2c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 78fe3ed0e50009101124d757b0ff13967a5eda787ddad427276779c4d343ce2c
SHA3-384 hash: 12127e56721dc2c4d729ec536c1199ffdac44a9a314f1d5ea734a6c939de4fa3c564f98b866fbdc109a35c77d7c68563
SHA1 hash: d4d26ffd70753a9d81877a70477edfc13f2bfb18
MD5 hash: 2a2278ac00e3b5729826f9f828a0b9ac
humanhash: mountain-magazine-spring-mobile
File name:Materials.iso
Download: download sample
Signature Formbook
File size:428'032 bytes
First seen:2021-01-15 15:53:45 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:YNFf3hZqh0Lsgc+pkdWR65XtacANmctQesWVN:YNFfxZqCLsgnpkBXtac0m+QeHN
TLSH 1094F603A92C89B2EF38A33D40050CD995F51C9C16D9B11A67BCBD3DDA7D4225D2FA2E
Reporter abuse_ch
Tags:FormBook iso


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: mail.litos.net
Sending IP: 86.109.108.50
From: mattias.jonsson@blsindustries.se
Subject: Order For Materials - BLS Industries Sweden
Attachment: Materials.iso (contains "Materials.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
186
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-01-15 11:22:29 UTC
AV detection:
9 of 44 (20.45%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

iso 78fe3ed0e50009101124d757b0ff13967a5eda787ddad427276779c4d343ce2c

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments