MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9a91d081021367b019ff9ab4a6b45e90f48d8d60fccbcd853224edb020e66074. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 9a91d081021367b019ff9ab4a6b45e90f48d8d60fccbcd853224edb020e66074
SHA3-384 hash: e432b55f8f9e17a97b56a1ab1316414b2eb137f87c25ab14cf04e14a0481948068776126100db18e2f25f60ae595f473
SHA1 hash: 298a114dc4a73968501f41be680016491bcf3b2a
MD5 hash: ceef868ff28caf323ac63b6846ac2cd5
humanhash: nineteen-berlin-venus-network
File name:MV STARSHIP.pdf.arj
Download: download sample
Signature FormBook
File size:892'685 bytes
First seen:2020-05-28 05:08:43 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 24576:7BDTlP2hD0UKtbznrgqPSlYmqX32MO/iQIQ:t9epxKt3nyqX32MEd
TLSH 4D153354D21077E9377135BEE7092A0562389848303C92F42EDD69F2D25C79FEE069AF
Reporter jarumlus
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Aitinject
Status:
Malicious
First seen:
2020-05-28 05:36:41 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
28 of 48 (58.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

arj 9a91d081021367b019ff9ab4a6b45e90f48d8d60fccbcd853224edb020e66074

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments