MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c1f42cb0a72682228d22ff1a35418f5acc381e46331bad4275ed77489f8a2388. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 4
| SHA256 hash: | c1f42cb0a72682228d22ff1a35418f5acc381e46331bad4275ed77489f8a2388 |
|---|---|
| SHA3-384 hash: | ec167f4a0d7a0c2ce43471165fb0e40d43fd00c2fd9be89fa0ce48b6f748179a66f52aff68dfa167c2e6a70a23686107 |
| SHA1 hash: | 9482c61fca5babeaa56030543abd2bc50b43ba63 |
| MD5 hash: | dfafbe26b3efd52ca739c90c51be75e2 |
| humanhash: | mexico-venus-johnny-bluebird |
| File name: | SWIFT COPY_PDF.gz |
| Download: | download sample |
| Signature | Formbook |
| File size: | 591'199 bytes |
| First seen: | 2021-04-04 14:58:14 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/x-rar |
| ssdeep | 12288:KfEnQ1Ie98vHkF51fztW3v6wXmNmzvFMeCBZmWC+5:KjT9UHkF51xW/6wXmNyGpC+5 |
| TLSH | F9C423916EA9FE085205D973C940C08BAEF252CED66C59FE81DDC641068CF27E6EA4DC |
| Reporter | |
| Tags: | FormBook gz SWIFT |
cocaman
Malicious email (T1566.001)From: "Chiara MEI <chiara.mei@geodis.com>" (likely spoofed)
Received: "from geodis.com (unknown [185.222.57.227]) "
Date: "2 Apr 2021 08:03:27 -0700"
Subject: "=?UTF-8?B?UmU6UmU6IFJlOiBIQVNMQzAzMjAwNzAxNDg1IDguM0NISVRUQUdPTkcgMVgyMEdQLy8gRnVuZCBUcmFuc2ZlciAtIERlYml0Ly8g5oiq5Y2V5L+h5oGv?="
Attachment: "SWIFT COPY_PDF.gz"
Intelligence
File Origin
# of uploads :
1
# of downloads :
250
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Gathering data
Threat name:
Win32.Spyware.Noon
Status:
Malicious
First seen:
2021-04-02 12:15:02 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
17 of 29 (58.62%)
Threat level:
2/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Dropping
Formbook
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.