MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f0e49ab19ca2e330275d4269472a4186301e917ae86e66870f264a771af55d66. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f0e49ab19ca2e330275d4269472a4186301e917ae86e66870f264a771af55d66
SHA3-384 hash: 868dda5080780fb4a996a1bfb326ed9479fd3bd03e0ad23b6b7aeb691dcda47a0eb7ac0a6e487eedb7599c92d833946a
SHA1 hash: 90be36ca70e2cd7fe958cc7bdd57c0d45755ab66
MD5 hash: 81702c11e1b377c229bde8e0c1e8d651
humanhash: spring-xray-ohio-saturn
File name:BCP SWIFT RNP094546505.rar
Download: download sample
Signature Formbook
File size:620'860 bytes
First seen:2020-10-23 06:25:39 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:pk9xogUiSMW48If8tZhHrx9DLFCIiOHKaMzs1ZQK++hboz6cKJOwgG:pQagUiSwf8tZh1CIifaGsvQK++Yc
TLSH D6D4233E25EE5D49E857795F2EC1C99F430ECA89129B74AF1D423C8A6F31C3E0A27059
Reporter abuse_ch
Tags:FormBook Outlook rar


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: NAM11-CO1-obe.outbound.protection.outlook.com
Sending IP: 40.92.18.91
From: David De La Oliva Falla- Scotia Bank <davidtanis@hotmail.com>
Subject: FWD: Re: OUTWARD DEBIT**Payment Advice RNP094546505
Attachment: BCP SWIFT RNP094546505.rar (contains "BCP SWIFT RNP094546505.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Noon
Status:
Malicious
First seen:
2020-10-22 23:09:02 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar f0e49ab19ca2e330275d4269472a4186301e917ae86e66870f264a771af55d66

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments