MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 87c1398cf6d6779c59d8f370e3aaf3f13763948ddc220663c4125dfaa423eb71. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 87c1398cf6d6779c59d8f370e3aaf3f13763948ddc220663c4125dfaa423eb71
SHA3-384 hash: 45e96c0885009c3e87e85468bcd8dbecadd75b639bc54ddeca4a69166919ced24d1c645c92262b2c2ccd9267642ed04d
SHA1 hash: 3903e0c439be4dc0cdef7f28e6eae75e497f46c4
MD5 hash: 5c1814bd3f9e5744d34f44e9362eb572
humanhash: east-floor-summer-juliet
File name:Fh_10024811.img
Download: download sample
Signature Formbook
File size:1'769'472 bytes
First seen:2020-10-27 08:48:05 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:Q9OwDuJKaOZWQbaTVGKgJjAmYmQlAARGt0KpEq:Q9jaOVkGKgJwmQlzG
TLSH 9485B49D3250B2EFC857C972CAA81C64EBA0787B931BC613A05711EDAA1D997CF150F3
Reporter abuse_ch
Tags:FormBook img


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: bjcs01.serverproof.net
Sending IP: 180.76.192.144
From: buyingfh@fhtextile.com
Subject: Re:Order 10024811
Attachment: Fh_10024811.img (contains "Quotation.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

img 87c1398cf6d6779c59d8f370e3aaf3f13763948ddc220663c4125dfaa423eb71

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments