MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 9adfb6b7723f95034dbe6fde3030175a0b0dcfb1a128b8605a118db8498c567b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 3
| SHA256 hash: | 9adfb6b7723f95034dbe6fde3030175a0b0dcfb1a128b8605a118db8498c567b |
|---|---|
| SHA3-384 hash: | a1b3d2957126e5135026cbcbf83b583efc7b913d16c2da3b4f936cf06f926d339b28da3b11a90660825e49adcdf3f8e2 |
| SHA1 hash: | 1102fd9931800c425b4efcebc98f6c7351b01df3 |
| MD5 hash: | 955d1b04d453aae4705c951c939a5813 |
| humanhash: | november-avocado-cold-music |
| File name: | Q1028838.txt.gz |
| Download: | download sample |
| Signature | Formbook |
| File size: | 398'229 bytes |
| First seen: | 2020-10-14 15:19:55 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/x-rar |
| ssdeep | 12288:5MEOcYcJzyOiVIL0B/RddGDnHf8SKiBzUR06:+VBFvIL0B/Rdd0TKMsd |
| TLSH | BD8423AD194068D5E2271981FCE2F68EB00C6CDE2BA6136BFA5F5A0C362424F55C9BD1 |
| Reporter | |
| Tags: | FormBook gz |
abuse_ch
Malspam distributing unidentified malware:HELO: mail.forecastle-shipping.com
Sending IP: 202.93.27.5
From: sales support <sales.support@heintlogistics.com>
Subject: Fwd: RFQ#IM201014BID , CIP AIR SHIPMENT FM HKG-CGK
Attachment: Q1028838.txt.gz (contains "Q1028838.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Packed.Generic
Status:
Suspicious
First seen:
2020-10-14 06:23:10 UTC
AV detection:
7 of 48 (14.58%)
Threat level:
1/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.