MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 abbe59fc43a3a976f88ab726c8aadff90382fd64a687c44dd4aea892b1c5377b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 4
| SHA256 hash: | abbe59fc43a3a976f88ab726c8aadff90382fd64a687c44dd4aea892b1c5377b |
|---|---|
| SHA3-384 hash: | e1d98ca0dfdcfa3d6b402846b5ac2471769864c962dd0c6bf58faf77ee606bf427db50ed26ba31bb771c1e797fda000e |
| SHA1 hash: | 675be3b1d4cbc54838fa8968ea7b33309a33c28b |
| MD5 hash: | 0873ee858fa6bc2e2702768caab1994f |
| humanhash: | mobile-oregon-pizza-leopard |
| File name: | Revise Order.zip |
| Download: | download sample |
| Signature | Formbook |
| File size: | 561'231 bytes |
| First seen: | 2021-01-12 18:00:10 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:Vzgbo5qBmLI8lpCmtiB0j7ujrD4SvJK927wGRPnNW8lGicI+x:Vz4zIPTCmtDmjv9vM920GRfgMc/ |
| TLSH | 37C423F542CCEED4F572D23787C394622F9126EA1A0EC9EA2DFBE40D445F206465B887 |
| Reporter | |
| Tags: | FormBook zip |
abuse_ch
Malspam distributing Formbook:HELO: delivery.mailspamprotection.com
Sending IP: 146.66.121.82
From: Alisa Fred <oip@employability.info>
Reply-To: alisafred2020@hotmail.com
Subject: Revise Order sheet
Attachment: Revise Order.zip (contains "Revise Order.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
119
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
Win32.Trojan.DelShad
Status:
Malicious
First seen:
2021-01-12 18:01:04 UTC
AV detection:
10 of 45 (22.22%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
0.85
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Formbook
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.