MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d0d8d8eb59807b54198aa881e835099cfa7abf9a1f8f28751862264931741f04. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d0d8d8eb59807b54198aa881e835099cfa7abf9a1f8f28751862264931741f04
SHA3-384 hash: 18ded82b73bb77f8d01fee63908a607910e43773340c2cc6e0eaf7e6474141a81b226a2834f60a0601996f3ac5e93371
SHA1 hash: d29c15774473cef1a21abcb7d4886702bdf89ae9
MD5 hash: 3a20237e5ee90c6cf326477daee17bd8
humanhash: sodium-west-item-football
File name:SALINAN SWIFT PRA-PEMBAYARAN UNTUK PEMASANGAN.iso
Download: download sample
Signature Formbook
File size:348'160 bytes
First seen:2021-04-07 05:53:47 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 3072:QeYBCwqDxkJCfwr+eY+lDhuodEqV0IKfk2YzlcJ2w+F1OBoL/vmd9uKu+9mnszac:QDIwNhuQEqVXHrzlckw+BH2uKu1sO
TLSH 7F74E0166282D0DAC585C1740D24EAADE66BED2008735EA73F8C7F6F6B7BA0B450C357
Reporter abuse_ch
Tags:FormBook iso


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: vps.bur-ibserte.com
Sending IP: 185.121.120.26
From: PRE-PAYMENT SWIFT COPY FOR INSTALLMENT <sales6@joyiqi.com>
Subject: SALINAN SWIFT PRA-PEMBAYARAN UNTUK PEMASANGAN
Attachment: SALINAN SWIFT PRA-PEMBAYARAN UNTUK PEMASANGAN.iso (contains "SALINAN SWIFT PRA-PEMBAYARAN UNTUK PEMASANGAN.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
107
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Spynoon
Status:
Malicious
First seen:
2021-04-07 00:58:49 UTC
AV detection:
14 of 48 (29.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

iso d0d8d8eb59807b54198aa881e835099cfa7abf9a1f8f28751862264931741f04

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments