MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c93faf6a754c533da34ff8307bf0e1fae9ee8bb94c2ac27e896749ab5bbe9ed0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: c93faf6a754c533da34ff8307bf0e1fae9ee8bb94c2ac27e896749ab5bbe9ed0
SHA3-384 hash: afd381a00c8c82126d13de6d73bee945758ee2c565ea44fc5733efbf3a6ac784bdd65b98c8c748482ec6c659e09182df
SHA1 hash: 01aebdf9a8be3795a7c3fbf771c59d0f638d320f
MD5 hash: c727f3a77322e039d34d87c12feaaab3
humanhash: indigo-purple-violet-oregon
File name:VCS58GQMhuCYghCpdf.z
Download: download sample
Signature Formbook
File size:595'843 bytes
First seen:2021-01-19 13:04:57 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:6+LIE7WjjHjUqInxlh1bS2Je1ErZ6yUIFcpanKZOZdpz+eBRquo6g1o:6KF7WjLwqI11m2g1Er0Hi6anGOZdp+ez
TLSH 23C433170C971C829CDCC78FE57FD7501C8B782CA59EC59ED347F228639106A6672C9A
Reporter abuse_ch
Tags:Yahoo z


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: sonic301-20.consmr.mail.sg3.yahoo.com
Sending IP: 106.10.242.83
From: Maizac Enterprise <maizacenterprise@yahoo.com>
Subject: Fw: Request Invoice PO 10154
Attachment: VCS58GQMhuCYghCpdf.z (contains "VCS58GQMhuCYghC.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
144
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-01-19 13:05:12 UTC
AV detection:
1 of 46 (2.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip c93faf6a754c533da34ff8307bf0e1fae9ee8bb94c2ac27e896749ab5bbe9ed0

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments