MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cbf684af2e0932a420af62f14a406b6b20d7e6f44789af35821b983a6cbdb857. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cbf684af2e0932a420af62f14a406b6b20d7e6f44789af35821b983a6cbdb857
SHA3-384 hash: f6dbd8363d535e3fa3ab9b434ddc1115942ce97dbeb4ef5af64887efc7a815e585a4ff7e02a380f7a3dc86005f573171
SHA1 hash: e9feaa6f09620121e04e7cb139ade88da51293e9
MD5 hash: bfe108890be4b8a8dfe865df43af33e4
humanhash: oregon-black-pluto-angel
File name:Shipping Document PLBL Draft.img
Download: download sample
Signature Formbook
File size:1'083'392 bytes
First seen:2021-01-18 09:04:35 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:s4GbT/r+XtczZckakZR5zrNXbJG9Kq7xPqOlDt:sjTSczZKSNLJG9KkPBlR
TLSH 2D35AD202080A43DF11A4D316AA5CFB219AA7C727F55784B6FE43E767F339C1A66431E
Reporter abuse_ch
Tags:DHL FormBook img


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: hj0.302.zrami.ml
Sending IP: 188.166.216.99
From: DHL Express <support@dhl.com>
Subject: Consignment Notification: You Have A Package With Us
Attachment: Shipping Document PLBL Draft.img (contains "Shipping Document PL&BL Draft.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
124
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Symmi
Status:
Malicious
First seen:
2021-01-18 09:05:19 UTC
AV detection:
12 of 43 (27.91%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

img cbf684af2e0932a420af62f14a406b6b20d7e6f44789af35821b983a6cbdb857

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments