MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a4cb74b1a586d8ba87bce47b6fa775056586970f3dbe39ddd1e06a1968563a6d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments 1

SHA256 hash: a4cb74b1a586d8ba87bce47b6fa775056586970f3dbe39ddd1e06a1968563a6d
SHA3-384 hash: 6abba2fba32e001761cfe8a85529cea0f84a2649cfcfcaf2f83b82a50c5e15d2f958b4d92c34b707a1e1415e0f8d0858
SHA1 hash: b41dffa17a402d42678286b12b7c372b9a22c837
MD5 hash: 0401ba1b0e79a95e50ae03a892a3632d
humanhash: venus-burger-burger-comet
File name:Dhl Delivery Document.pdf.z
Download: download sample
Signature Formbook
File size:685'854 bytes
First seen:2024-07-04 15:34:29 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:w7YKTv8LilOAFzTDkSYvC/Giju1/uiyYm++wGW7P4iR+fRuvILKsr:XKDxO4oSY8G8uEiApwFP4TpFr
TLSH T106E42311306C0ED76894DCD593B53A981236DCE2F6788CBDC6873B54E598295BFC223E
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter malwarology
Tags:FormBook zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Dhl Delivery Document.exe
File size:0 bytes
SHA256 hash: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
MD5 hash: d41d8cd98f00b204e9800998ecf8427e
MIME type:inode/x-empty
Signature Formbook
Vendor Threat Intelligence
Gathering data
Gathering data
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip a4cb74b1a586d8ba87bce47b6fa775056586970f3dbe39ddd1e06a1968563a6d

(this sample)

91b57e4a229a929ffef77e2cf564dea624bbc50fd54372d48d8ec812753c976f

Comments



Avatar
Malwarology commented on 2024-07-04 15:37:24 UTC

Password: Express1234