MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e9653a518a660f088185df48ef783058bb6902c295d6dbdef795b2da7267e7aa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 4
| SHA256 hash: | e9653a518a660f088185df48ef783058bb6902c295d6dbdef795b2da7267e7aa |
|---|---|
| SHA3-384 hash: | 17afbfeb710e39485c736a09f3e40cd0f49a8e2c830c759a20fe79ec912679acdece47064b7fce744ffe4d404b0d6cbb |
| SHA1 hash: | f0122b040f438bba00d85f057c6c74a7ff9d1720 |
| MD5 hash: | 9ede621c2a06d647c36c19967ef967a4 |
| humanhash: | aspen-juliet-glucose-gee |
| File name: | SWIFT USD 354,883.00.zip |
| Download: | download sample |
| Signature | Formbook |
| File size: | 343'203 bytes |
| First seen: | 2020-12-26 06:25:42 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:QN9BN87PCr20at7WnzZ+E12iinl2K7IjYmyHGEdfKj5YKEZ9BbupyLIzSOUf:Qj2220aMUCn1/ynu+KyBaEE+Oc |
| TLSH | 207423172006178E5BA6AF9378EA5CCC2A0F3FAE5535E20674C2BCDE5BDE9C2181D50C |
| Reporter | |
| Tags: | zip |
cocaman
Malicious email (T1566.001)From: "Jenny Jiang<Jenny.Jiang@bmo.com>" (likely spoofed)
Received: "from bmo.com (unknown [79.110.52.80]) "
Date: "25 Dec 2020 02:39:29 -0800"
Subject: "FWD: SWIFT USD 354,883.00"
Attachment: "SWIFT USD 354,883.00.zip"
Intelligence
File Origin
# of uploads :
1
# of downloads :
410
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Ymacco
Status:
Malicious
First seen:
2020-12-26 06:26:07 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
17 of 46 (36.96%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Noon
Score:
0.80
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.