MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 4bc8a87e1e004d6f3e7406e9925f8d01592c1e95b9f62de5e8305854c0a62b48. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 5
| SHA256 hash: | 4bc8a87e1e004d6f3e7406e9925f8d01592c1e95b9f62de5e8305854c0a62b48 |
|---|---|
| SHA3-384 hash: | ea17bf652df49d5ef661e8e5d1597f72d0bc251a35f7ba1e319b4d5a886ebe14a27319504003d66cd197a0ed8194490c |
| SHA1 hash: | 5c1c4776f8d676661afd1ab07e65f8a7b90f0372 |
| MD5 hash: | f4059e7b7a9125ba550415fc374fed67 |
| humanhash: | jersey-two-lima-speaker |
| File name: | G0170-PF3F-20-02602T.cab |
| Download: | download sample |
| Signature | Formbook |
| File size: | 601'047 bytes |
| First seen: | 2021-01-19 07:32:39 UTC |
| Last seen: | Never |
| File type: | cab |
| MIME type: | application/vnd.ms-cab-compressed |
| ssdeep | 12288:4Qv+s0dCnxi4eG2nFRvkHNY4fu47Mn9JmGT7nVAr/Ar:1+Xd4xi4eG2F2Hy6uyMnpTrmr/e |
| TLSH | 79D423310665788C36CBE12BF1EE0ABB91F712A38C279E4ED5C4F09DD9A4A4722DC195 |
| Reporter | |
| Tags: | cab FormBook geo Hostwinds KOR |
abuse_ch
Malspam distributing Formbook:HELO: hwsrv-824350.hostwindsdns.com
Sending IP: 104.168.171.198
From: 보낸 사람<mehur@sramexports.in>
Reply-To: haandha.haandha@dr.com
Subject: (긴급건) 견적 요청 드립니다.
Attachment: G0170-PF3F-20-02602T.cab (contains "(G0170-PF3F-20-0260)2T.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
179
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-01-18 23:42:56 UTC
AV detection:
1 of 46 (2.17%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Formbook
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.