MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 abbe59fc43a3a976f88ab726c8aadff90382fd64a687c44dd4aea892b1c5377b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: abbe59fc43a3a976f88ab726c8aadff90382fd64a687c44dd4aea892b1c5377b
SHA3-384 hash: e1d98ca0dfdcfa3d6b402846b5ac2471769864c962dd0c6bf58faf77ee606bf427db50ed26ba31bb771c1e797fda000e
SHA1 hash: 675be3b1d4cbc54838fa8968ea7b33309a33c28b
MD5 hash: 0873ee858fa6bc2e2702768caab1994f
humanhash: mobile-oregon-pizza-leopard
File name:Revise Order.zip
Download: download sample
Signature Formbook
File size:561'231 bytes
First seen:2021-01-12 18:00:10 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:Vzgbo5qBmLI8lpCmtiB0j7ujrD4SvJK927wGRPnNW8lGicI+x:Vz4zIPTCmtDmjv9vM920GRfgMc/
TLSH 37C423F542CCEED4F572D23787C394622F9126EA1A0EC9EA2DFBE40D445F206465B887
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: delivery.mailspamprotection.com
Sending IP: 146.66.121.82
From: Alisa Fred <oip@employability.info>
Reply-To: alisafred2020@hotmail.com
Subject: Revise Order sheet
Attachment: Revise Order.zip (contains "Revise Order.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
119
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.DelShad
Status:
Malicious
First seen:
2021-01-12 18:01:04 UTC
AV detection:
10 of 45 (22.22%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip abbe59fc43a3a976f88ab726c8aadff90382fd64a687c44dd4aea892b1c5377b

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments