MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aaadb8e27ffc99333e3d23e527051d6dd9acf3df1231463f4e25860edcc13bfb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: aaadb8e27ffc99333e3d23e527051d6dd9acf3df1231463f4e25860edcc13bfb
SHA3-384 hash: 400ea203cd43017077db5d3ea26732dea780f8ee3fcb3542f18fbb605d3081855dbfeaf7d5e1c489de320444d7c84864
SHA1 hash: 141de697e378c44f0ff7974372d817d0a329193d
MD5 hash: c0e23791ab7c6cacdb0e12de1936ef34
humanhash: lactose-nebraska-alaska-emma
File name:Inquiry pdf.z
Download: download sample
Signature Formbook
File size:431'664 bytes
First seen:2021-02-06 15:54:05 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:2bkqLXZyt+qUos3ucYU6x559Gwi4YQ8qJr9h196+fj519w:2QFQqUos1/09ur8hL6Uxw
TLSH 999423B3103B861660EFFD40189812B6286B4AE28313FACF554F7725358CBF756C9A79
Reporter fabjer
Tags:z

Intelligence


File Origin
# of uploads :
1
# of downloads :
181
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Swotter
Status:
Malicious
First seen:
2021-02-05 20:23:37 UTC
AV detection:
27 of 47 (57.45%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

z aaadb8e27ffc99333e3d23e527051d6dd9acf3df1231463f4e25860edcc13bfb

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments