MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b488476fd73f2f4fe982761e9c784db0d57e67e84a791a45c0a9dd3210482b9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b488476fd73f2f4fe982761e9c784db0d57e67e84a791a45c0a9dd3210482b9b
SHA3-384 hash: 5c5aac42ed0a8949a7047c7ad864cd2fe65cf86077225d4f3350c00c23d1238e15605055e62987ad9cea078e195ba6e2
SHA1 hash: 053f9b1b8bc6cf5fe62a78f1aa48af08a9c5a77b
MD5 hash: 6a81b911adaf8093da184076fc6ffb2a
humanhash: nineteen-bravo-fix-jupiter
File name:New Order-PO-018650.zip
Download: download sample
Signature Formbook
File size:688'257 bytes
First seen:2021-03-24 06:18:53 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:V5zLCA0ZtyMngd33aj6pCZbxKGsijU07uUSFH8ydSjFGdAWyA0uu:sryMgdix1sijRuUdb4DmX
TLSH 16E4336114134EEB2BCF1C7FF71DA2A15D8ACE741B760AFAE60F06855AFCC1E6442948
Reporter cocaman
Tags:FormBook zip


Avatar
cocaman
Malicious email (T1566.001)
From: "Ahmed.Ramez <purchases@ec1.evergrown.com>" (likely spoofed)
Received: "from ec1.evergrown.com (unknown [217.146.88.165]) "
Date: "24 Mar 2021 05:11:37 +0100"
Subject: "NEW ORDER |||||| GFB-AM-024-03-2021"
Attachment: "New Order-PO-018650.zip"

Intelligence


File Origin
# of uploads :
1
# of downloads :
101
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Woreflint
Status:
Malicious
First seen:
2021-03-24 06:19:09 UTC
File Type:
Binary (Archive)
Extracted files:
37
AV detection:
7 of 48 (14.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip b488476fd73f2f4fe982761e9c784db0d57e67e84a791a45c0a9dd3210482b9b

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
Formbook

Comments