MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4bc8a87e1e004d6f3e7406e9925f8d01592c1e95b9f62de5e8305854c0a62b48. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 4bc8a87e1e004d6f3e7406e9925f8d01592c1e95b9f62de5e8305854c0a62b48
SHA3-384 hash: ea17bf652df49d5ef661e8e5d1597f72d0bc251a35f7ba1e319b4d5a886ebe14a27319504003d66cd197a0ed8194490c
SHA1 hash: 5c1c4776f8d676661afd1ab07e65f8a7b90f0372
MD5 hash: f4059e7b7a9125ba550415fc374fed67
humanhash: jersey-two-lima-speaker
File name:G0170-PF3F-20-02602T.cab
Download: download sample
Signature Formbook
File size:601'047 bytes
First seen:2021-01-19 07:32:39 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 12288:4Qv+s0dCnxi4eG2nFRvkHNY4fu47Mn9JmGT7nVAr/Ar:1+Xd4xi4eG2F2Hy6uyMnpTrmr/e
TLSH 79D423310665788C36CBE12BF1EE0ABB91F712A38C279E4ED5C4F09DD9A4A4722DC195
Reporter abuse_ch
Tags:cab FormBook geo Hostwinds KOR


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: hwsrv-824350.hostwindsdns.com
Sending IP: 104.168.171.198
From: 보낸 사람<mehur@sramexports.in>
Reply-To: haandha.haandha@dr.com
Subject: (긴급건) 견적 요청 드립니다.
Attachment: G0170-PF3F-20-02602T.cab (contains "(G0170-PF3F-20-0260)2T.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
179
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-01-18 23:42:56 UTC
AV detection:
1 of 46 (2.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

cab 4bc8a87e1e004d6f3e7406e9925f8d01592c1e95b9f62de5e8305854c0a62b48

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments