MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 799160e10efd12ac4a9cc0bb98a1426a9d86ef90c64ce26708de979b490f353f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 799160e10efd12ac4a9cc0bb98a1426a9d86ef90c64ce26708de979b490f353f
SHA3-384 hash: 025a780103559255247049e9090fc11f237427126d774dfa144ef63742ad878e1faadd73a4ea76b20fbf4ae7d585ca14
SHA1 hash: 06b3088407576b8e6c91c90197e06146bca5cf36
MD5 hash: 6afad6d2fed3c379d66080b25e019306
humanhash: ceiling-romeo-johnny-music
File name:New Order Product Specifications.iso
Download: download sample
Signature Formbook
File size:550'912 bytes
First seen:2020-10-07 04:46:58 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:xSi5Za+LKfq5sLfnvKWbhpKYVNxEWOI4JOdQCw5uRlItyw9C8j1Ppvu00:xSivlLBiLXKOuY3xfzMulDetyl8O
TLSH ACC48C736D82989DCE6947B10CB541E1F67A02CE3FA3890E729E530C0F12717775A66E
Reporter abuse_ch
Tags:FormBook iso


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: fujitec.co
Sending IP: 209.11.159.147
From: Purchase Dept <mohan.j@fujitecindia.com>
Subject: Fwd: Product Enquiry/New Order
Attachment: New Order Product Specifications.iso (contains "New Order & Product Specifications.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

iso 799160e10efd12ac4a9cc0bb98a1426a9d86ef90c64ce26708de979b490f353f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments