MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a6a3868c066bf6d3e03e7c13e9f7053523cdd2f2aaba44737a387762b7ca805f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: a6a3868c066bf6d3e03e7c13e9f7053523cdd2f2aaba44737a387762b7ca805f
SHA3-384 hash: 5444f2d476bf7a3b8d04b5b6b59de6322bce5b052eb19d5054e756b13ee30f9168160cc4783a17fe030c94667d223eb0
SHA1 hash: 99e64b1372b0b1e7c8102142bba561c213e7dee0
MD5 hash: ff6b0149a50d104918fa4c4770c3450a
humanhash: five-november-utah-william
File name:61vPFITGkbgCrMTpdf.z
Download: download sample
Signature Formbook
File size:426'180 bytes
First seen:2021-02-06 08:26:19 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:8p0Zt/fM6q03acZI9hlKGVG6ArB5//RhTPU:8p0Z90d0qcZI7lKVfXRJM
TLSH 5A94230C803D0584072355BEF9AF65AD11D22A82FBDF5924E4ADE087F3885FD699378E
Reporter abuse_ch
Tags:FormBook z


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: spfilter-4.mschosting.com
Sending IP: 110.4.43.244
From: gpstore@kowhock.my
Subject: COPIES
Attachment: 61vPFITGkbgCrMTpdf.z (contains "61vPFITGkbgCrMT.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
214
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Spyware.Noon
Status:
Malicious
First seen:
2021-02-06 08:27:08 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip a6a3868c066bf6d3e03e7c13e9f7053523cdd2f2aaba44737a387762b7ca805f

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments