MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aeb7bd2fc40a3cd8a62a8e8e8dc9db921ba4e81257126a9a43b340bb1964a94f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: aeb7bd2fc40a3cd8a62a8e8e8dc9db921ba4e81257126a9a43b340bb1964a94f
SHA3-384 hash: e8de935c20764d64deec2b64aef29dbf099c31e55ea4b7d099c36ff93d47a536386a2b634e70c394de37fdde42c1be47
SHA1 hash: 6ee7802b610a9682215ba0bc4258e9d1523a1a02
MD5 hash: 75e0760524cdc1540f62b1749add1ef5
humanhash: october-maine-virginia-mockingbird
File name:PO-Hiks726357289.z
Download: download sample
Signature FormBook
File size:186'124 bytes
First seen:2020-06-15 05:39:52 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 3072:7/R/6kkYCxKy2NkxHR7nriWjH5yT2NabdORcgnA80ViBF6VrEUAaY:7/R/6kkY6t9xU2NaeT2gz
TLSH 2604239B60F64443716DBE9A3B0386671EDBF0DC6A9087B01A9415CFCB7E74AF086781
Reporter abuse_ch
Tags:FormBook z


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: yangtwang.pw
Sending IP: 142.11.195.30
From: Lanre Hai <orders@hiksvisions.com>
Subject: Hiksvision Trial PO
Attachment: PO-Hiks726357289.z (contains "PO-Hiks726357289.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Casdet
Status:
Malicious
First seen:
2020-06-15 05:41:07 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

z aeb7bd2fc40a3cd8a62a8e8e8dc9db921ba4e81257126a9a43b340bb1964a94f

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments