MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 311b79d69da0b1c4d57a5b15e5507b5be53ac3a97940d900ae0f4d37615b8e6e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 311b79d69da0b1c4d57a5b15e5507b5be53ac3a97940d900ae0f4d37615b8e6e
SHA3-384 hash: d9f241087be058c22f86db4c10eb96565d95157f1be78c9e2e8a25c9a24ff455ba45d47a1a3e2593b91ce9dc857e855f
SHA1 hash: f3c71bae9368f6968e3125411341610b77eb3ad2
MD5 hash: ab1aed09d94c6d890dc7256ec4badec8
humanhash: sodium-lactose-golf-alabama
File name:Order 2021.01.06.cab
Download: download sample
Signature Formbook
File size:591'301 bytes
First seen:2021-01-06 08:04:08 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 12288:tkXK+ji29pu8/KrqX8HRRDNr/+FMK12duXphR8VNpITuu/LD:tkZXu1rXxb8MS2cXOK1
TLSH F6C423034731A78CAB0A2679E7A9C6FCF55E1D4E0B278597FA7401F63E4A04FB604D98
Reporter abuse_ch
Tags:cab FormBook


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: mail-smail-vm48.hanmail.net
Sending IP: 203.133.180.236
From: 라이즈 <bsy8776@hanmail.net>
Subject: (긴급건) 견적 요청 드립니다.
Attachment: Order 2021.01.06.cab (contains "Order (2021.01.06).exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
167
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-01-06 08:04:15 UTC
AV detection:
7 of 46 (15.22%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

cab 311b79d69da0b1c4d57a5b15e5507b5be53ac3a97940d900ae0f4d37615b8e6e

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments