MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f5b0cf927242b9bc3d6d1cdedb8417d1fac95e15bfc3c9fb9dec80a9bc8741c6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: f5b0cf927242b9bc3d6d1cdedb8417d1fac95e15bfc3c9fb9dec80a9bc8741c6
SHA3-384 hash: da78b9b5c6da38dce954354bd9d8448019426d44d6de44f6c763a00a7b99dabc74d5fc3e1ec46ccce4390f356f8317c8
SHA1 hash: 48b23d830931dced658b961928e29d28986c0e64
MD5 hash: a1b8cae3e9016bdb3486c79a7eb06f47
humanhash: crazy-asparagus-early-two
File name:Order-960411730-pdf.img
Download: download sample
Signature Formbook
File size:1'245'184 bytes
First seen:2022-02-17 07:29:37 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:mw+5Mt5NfRbT0ngAp7zWevAtYRAsOoiwKwghVIFIldXR+J3KrrZjd:26PCgAp7zWePRIjwKDrGMXQJ3KrrX
TLSH T1E345128DF7D9D8ABC629163156757B2EF3FA77042B12930B730E1F2B870A4C295105AA
Reporter cocaman
Tags:FormBook img


Avatar
cocaman
Malicious email (T1566.001)
From: ""Dejan Nikolic" <info@zzconsulting.de>" (likely spoofed)
Received: "from proxy1-1.romtelecom.net (proxy1-1.romtelecom.net [86.35.15.60]) "
Date: "Thu, 17 Feb 2022 02:21:44 +0100"
Subject: "RE: Order PO EM96026295194 "
Attachment: "Order-960411730-pdf.img"

Intelligence


File Origin
# of uploads :
1
# of downloads :
242
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
control.exe overlay packed shell32.dll
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Nsisx
Status:
Malicious
First seen:
2022-02-17 07:30:16 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
10 of 43 (23.26%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

img f5b0cf927242b9bc3d6d1cdedb8417d1fac95e15bfc3c9fb9dec80a9bc8741c6

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments