MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 afefbb688be3f8afd802d9a9388c45b1623a0a4f32f92879234a0a193b2fc4f1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: afefbb688be3f8afd802d9a9388c45b1623a0a4f32f92879234a0a193b2fc4f1
SHA3-384 hash: aeffba07aa4c1649dac5a79374cd148ea4f249a2a82f716c60aa4efff3e5fb0f7130a26720f278cfb5b057a6844f0431
SHA1 hash: 54d6df563788b5df5f6775e3a97e2b0996d32045
MD5 hash: 9c61b085006fdac06ce891d3962a0250
humanhash: paris-vegan-may-hawaii
File name:PO8479349743085.zip
Download: download sample
Signature Formbook
File size:207'561 bytes
First seen:2020-10-18 17:15:22 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:Rw5sFWBhg+CvqPnS7uBIGzl/7zadaUPF83o8SvyldEFMbzqB4wdDFA:U3X8YnSLGh/H47PF8wyldEFuzqC5
TLSH C41413022AE84F0BDA053B5469FB10868EEE73056EA0AD2CD7F51055A93B8D1353F7BD
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: regular1.263xmail.com
Sending IP: 211.150.70.199
From: huang <sales1@cnboh.com>
Subject: urgent quote
Attachment: PO8479349743085.zip (contains "PO8479349743085.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
117
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip afefbb688be3f8afd802d9a9388c45b1623a0a4f32f92879234a0a193b2fc4f1

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments