MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81296b9f87ea7b7b4dbc65cdd487b4fcd1934c7763e257fff14fc3312cad0b07. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 81296b9f87ea7b7b4dbc65cdd487b4fcd1934c7763e257fff14fc3312cad0b07
SHA3-384 hash: 4c7eb64a13a6d2226f23356c441176d8f0e5e5dbaa420595bd98607e0e83402f7d7fa1ad986d18f6fbf4aa8863540039
SHA1 hash: fd0eca123731d12e8fc13496a65f6a668253f338
MD5 hash: 693a144a1b0d2ed30f63367cb4542c36
humanhash: delaware-fanta-friend-september
File name:PO.zip
Download: download sample
Signature Formbook
File size:929'585 bytes
First seen:2020-11-20 07:38:45 UTC
Last seen:2020-11-27 09:58:42 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:2+WlQ+du1ufP/yAv5YFOXFe23W5rhEj4vtM3pc7ILshIj4pPy26/iAP3a8I:lWlDdCuKKlKtEjnGczkPCHa8I
TLSH B715331FB375DE8469A5775C6B90EF4BAEF397A0EA46E291C2DB86C1281F105118C0F3
Reporter abuse_ch
Tags:zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: gmail.com
Sending IP: 156.96.62.91
From: Entang Hoerudin (Pur-Polymer) <sales@gmail.com>
Reply-To: fortunatodaniel.johndeere@gmail.com
Subject: Re: Fwd: Fwd: Fwd: Fwd: RFQ # 23692 ANRITSU PROBE/ po # 29288
Attachment: PO.zip (contains "PO.exe")

Intelligence


File Origin
# of uploads :
23
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.OutBreak
Status:
Malicious
First seen:
2020-11-19 23:51:57 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 81296b9f87ea7b7b4dbc65cdd487b4fcd1934c7763e257fff14fc3312cad0b07

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments