MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fd0bac5b0b78c5735498fc0a4fdda83a073f2e2f1413065a630c6a9e6864677d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fd0bac5b0b78c5735498fc0a4fdda83a073f2e2f1413065a630c6a9e6864677d
SHA3-384 hash: c80b87d733484f1b17e56b7c6fef0414cd1b0df129ae6be93c725d0b9a1e0cccad997cdd3f1ce5deaf36c7bf58d4a407
SHA1 hash: 2b6f6b1cb2777de70d00e5347cb90326f542f8dc
MD5 hash: 5e2c9856667b195d58fd409591aae80c
humanhash: shade-edward-illinois-mississippi
File name:cv.iso
Download: download sample
Signature Formbook
File size:458'752 bytes
First seen:2020-07-22 09:58:24 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:KZkjbSthXTPuwvPUm2GhNAr/lvlfL99fRPRIisx58gKz6qPHVYBhJPWN:KKjbStdvPUm2iNSF9u4g66q/OP
TLSH 8EA4BF10E7B80AD9D76907B9E0615414ABB6651A63EAE70E3B9DF0DC1B33B408713F27
Reporter abuse_ch
Tags:FormBook iso


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: server1.swisspac.es
Sending IP: 119.18.63.233
From: Arshad Bhai <assafmak@gmail.com>
Subject: CV
Attachment: cv.iso (contains "cv.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Swotter
Status:
Malicious
First seen:
2020-07-22 10:00:08 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

iso fd0bac5b0b78c5735498fc0a4fdda83a073f2e2f1413065a630c6a9e6864677d

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments