MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a4e64ee3585ba2c75e1e9453235265c55efb01f7d8ff1e6da79d12fdffed7e29. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: a4e64ee3585ba2c75e1e9453235265c55efb01f7d8ff1e6da79d12fdffed7e29
SHA3-384 hash: 1685b8ffafb92aa1ba2ca21e64c504827ede762b763c462e6fff92f39770909d9831e947665851962a930ba965d1b9b0
SHA1 hash: 8894c94739f9761575224e27629f50981f935399
MD5 hash: 25d8246e7d80f4b28772b8e6ee6b9188
humanhash: michigan-green-april-mockingbird
File name:DHL DETAIL.gz
Download: download sample
Signature Formbook
File size:202'236 bytes
First seen:2020-12-16 08:43:04 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:dKoNqTxD+uNA8ivRXOuCU+I07PK43IiM+8Pbh:8oNqVhAFouCPcioPbh
TLSH E3141230FD9E806D2E6BB70A3D3720C4486F08C9E56948075AD6D3685EDA6D0D7E3B74
Reporter abuse_ch
Tags:DHL FormBook gz


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: sujd0.315.dfinxo.ml
Sending IP: 138.68.17.133
From: "DHL Express" <info@315.dfinxo.ml>
Subject: DHL Delivery Notification
Attachment: DHL DETAIL.gz (contains "gunzipped")

Intelligence


File Origin
# of uploads :
1
# of downloads :
159
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2020-12-16 08:44:05 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

gz a4e64ee3585ba2c75e1e9453235265c55efb01f7d8ff1e6da79d12fdffed7e29

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments