MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eca5a46b96f446d1180e0c1d007fa6877643a1ef88f8a95ab64dce9bc94f6206. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: eca5a46b96f446d1180e0c1d007fa6877643a1ef88f8a95ab64dce9bc94f6206
SHA3-384 hash: 55b3d8eff1bd520ee700d6ced1de47b11f158143aaa887da2fb8d6ce2aef72257aa0022398fb9abe3e60ce5830ed8920
SHA1 hash: 67f77b79cbdff12aeba332346b9d4182e28e3841
MD5 hash: 427efd38d55faf552a418815a86c74cb
humanhash: kitten-happy-wisconsin-four
File name:대동테크윈 견적 요청.rar
Download: download sample
Signature Formbook
File size:232'345 bytes
First seen:2021-04-12 06:15:13 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:dMsG6/1YV1EMjatAkwFv6oNRoWpqeq1Jc4FDfYu:dMsG6/m1EuaO7v6oNyWpqDNQu
TLSH 7B3422F93FA25B2276C62D2065EC4DC3B3B84BE9F1059B4D8EA331391D7A1D91217A07
Reporter abuse_ch
Tags:geo KOR rar


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: mail-vip48.idc.redeunifique.com.br
Sending IP: 177.200.201.48
From: Soojeong Choi <soo@daedong114.co.kr>
Reply-To: dd@daedong114.co.kr
Subject: 대동테크윈 견적 요청
Attachment: 대동테크윈 견적 요청.rar (contains "대동테크윈 견적 요청.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
118
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Spyware.Noon
Status:
Malicious
First seen:
2021-04-12 06:15:19 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar eca5a46b96f446d1180e0c1d007fa6877643a1ef88f8a95ab64dce9bc94f6206

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments