MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 a75fbdeb8922f5dd2819017b83fd10f2d13968a40f761ef939f77180a6a9d908. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 3
| SHA256 hash: | a75fbdeb8922f5dd2819017b83fd10f2d13968a40f761ef939f77180a6a9d908 |
|---|---|
| SHA3-384 hash: | 3e77ee3ac3940342f2b4f62f8da818d62a7f89d54327aab88a75bbb4cf1a79852c5adce2145c04a246383ec836cecc7b |
| SHA1 hash: | d73d8433b20ba50f3bdbfb781e797618970c1fe5 |
| MD5 hash: | f60f9d356d0432ddd34bcd2515fd560f |
| humanhash: | crazy-sweet-robert-triple |
| File name: | QUOTATION.rar |
| Download: | download sample |
| Signature | Formbook |
| File size: | 388'480 bytes |
| First seen: | 2020-10-27 12:28:12 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 6144:C1p0jMGe+zFhALIEZJ+FFGNoJQoiXN5A88E/utzKAPsbZyvgoGPtJ1ETyjaY1ypr:2p0hALISoFGYQoiMNtOvZDPtyyjOF2Yt |
| TLSH | E48423687E55A139324C5F6E0AE61ED122ED49C371A409247F76CB2B98B243CCBE3717 |
| Reporter | |
| Tags: | FormBook rar |
abuse_ch
Malspam distributing unidentified malware:From: "高静" <gj@mascube.com>
Subject: RE: Quote and price list request
Attachment: QUOTATION.rar (contains "Quotation-pdf-file.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
107
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2020-10-27 02:15:48 UTC
AV detection:
7 of 47 (14.89%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.