MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9c54aeda4bad3cf6da4b4cc451fd97b85f2fcf3fd0d4537cbb31c29e0a639bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b9c54aeda4bad3cf6da4b4cc451fd97b85f2fcf3fd0d4537cbb31c29e0a639bc
SHA3-384 hash: 7dfada0c2feaeac98729c869523837bfca2cb4f9c35a2432ed7ce102197b35f291ab6258bd1b3d0b8825f966ca3610e2
SHA1 hash: 38d6fe5e0f632de811c271e6a94350bf61ff4106
MD5 hash: 615c08c292c0cee2f56073b6b6adcb0e
humanhash: tango-floor-wyoming-missouri
File name:solicitud de presupuesto.zip
Download: download sample
Signature Formbook
File size:494'017 bytes
First seen:2020-10-22 06:17:21 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:TEZy5brLKFWos1GWtMOin7XJDdHJE1e3gpFW:okVuFC1GWiZXExpFW
TLSH 0CB423ECB271B79399941FEB3C191606262465D7AF9B4C070C7CB78B62CC55B412FB88
Reporter abuse_ch
Tags:ESP FormBook geo zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: server.freespirittours.net
Sending IP: 216.144.241.158
From: "HERNANDEZ, ALEJANDRO" <epugnant@groupe-rdt.com>
Subject: Re: Re: solicitud de presupuesto
Attachment: solicitud de presupuesto.zip (contains "solicitud de presupuesto.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2020-10-21 17:26:59 UTC
AV detection:
9 of 48 (18.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip b9c54aeda4bad3cf6da4b4cc451fd97b85f2fcf3fd0d4537cbb31c29e0a639bc

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments