MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e9653a518a660f088185df48ef783058bb6902c295d6dbdef795b2da7267e7aa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e9653a518a660f088185df48ef783058bb6902c295d6dbdef795b2da7267e7aa
SHA3-384 hash: 17afbfeb710e39485c736a09f3e40cd0f49a8e2c830c759a20fe79ec912679acdece47064b7fce744ffe4d404b0d6cbb
SHA1 hash: f0122b040f438bba00d85f057c6c74a7ff9d1720
MD5 hash: 9ede621c2a06d647c36c19967ef967a4
humanhash: aspen-juliet-glucose-gee
File name:SWIFT USD 354,883.00.zip
Download: download sample
Signature Formbook
File size:343'203 bytes
First seen:2020-12-26 06:25:42 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:QN9BN87PCr20at7WnzZ+E12iinl2K7IjYmyHGEdfKj5YKEZ9BbupyLIzSOUf:Qj2220aMUCn1/ynu+KyBaEE+Oc
TLSH 207423172006178E5BA6AF9378EA5CCC2A0F3FAE5535E20674C2BCDE5BDE9C2181D50C
Reporter cocaman
Tags:zip


Avatar
cocaman
Malicious email (T1566.001)
From: "Jenny Jiang<Jenny.Jiang@bmo.com>" (likely spoofed)
Received: "from bmo.com (unknown [79.110.52.80]) "
Date: "25 Dec 2020 02:39:29 -0800"
Subject: "FWD: SWIFT USD 354,883.00"
Attachment: "SWIFT USD 354,883.00.zip"

Intelligence


File Origin
# of uploads :
1
# of downloads :
410
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Ymacco
Status:
Malicious
First seen:
2020-12-26 06:26:07 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
17 of 46 (36.96%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip e9653a518a660f088185df48ef783058bb6902c295d6dbdef795b2da7267e7aa

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments