MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b1cd63d9c6a41a541136481eb72887dba8b6c33d4f2f134a88c9b64ee0b11f91. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b1cd63d9c6a41a541136481eb72887dba8b6c33d4f2f134a88c9b64ee0b11f91
SHA3-384 hash: cffa6bb5454474baa0349b9f4a8c6b5e5a6169c6aa53e92e58039cd954e985e63658f719dce53650403ddff176cb67fa
SHA1 hash: 07023e2d7ac9158a57110d064c61b144e77080a4
MD5 hash: bfa8920f140c867e85fcbf9023c92d08
humanhash: vegan-potato-tango-iowa
File name:BL copy order nr. 1054-21.pdf.gz
Download: download sample
Signature Formbook
File size:670'348 bytes
First seen:2021-01-19 07:20:00 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:l5VDoNLdrwd+/RCQjOON3gyQ3zLCVT31BG/fwRy5qBw/ziholqjSOS3ol:TVDO1G+HrN3gyky31B6wRWbiVS3Q
TLSH 0BE423268AF6289C7131953B0CEC1F523DB3B9BE654498EE971DE9D4E840FB4782BC11
Reporter abuse_ch
Tags:FormBook gz


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: smtp.enel.com
Sending IP: 77.48.43.64
From: Israel Carvalho <Israel.carvalho.indra@enel.com>
Subject: BL-MW981054-20
Attachment: BL copy order nr. 1054-21.pdf.gz (contains "BL copy order nr. 1054-21.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
96
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Swotter
Status:
Malicious
First seen:
2021-01-19 07:20:20 UTC
AV detection:
14 of 46 (30.43%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

gz b1cd63d9c6a41a541136481eb72887dba8b6c33d4f2f134a88c9b64ee0b11f91

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments