MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c93faf6a754c533da34ff8307bf0e1fae9ee8bb94c2ac27e896749ab5bbe9ed0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 5
| SHA256 hash: | c93faf6a754c533da34ff8307bf0e1fae9ee8bb94c2ac27e896749ab5bbe9ed0 |
|---|---|
| SHA3-384 hash: | afd381a00c8c82126d13de6d73bee945758ee2c565ea44fc5733efbf3a6ac784bdd65b98c8c748482ec6c659e09182df |
| SHA1 hash: | 01aebdf9a8be3795a7c3fbf771c59d0f638d320f |
| MD5 hash: | c727f3a77322e039d34d87c12feaaab3 |
| humanhash: | indigo-purple-violet-oregon |
| File name: | VCS58GQMhuCYghCpdf.z |
| Download: | download sample |
| Signature | Formbook |
| File size: | 595'843 bytes |
| First seen: | 2021-01-19 13:04:57 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:6+LIE7WjjHjUqInxlh1bS2Je1ErZ6yUIFcpanKZOZdpz+eBRquo6g1o:6KF7WjLwqI11m2g1Er0Hi6anGOZdp+ez |
| TLSH | 23C433170C971C829CDCC78FE57FD7501C8B782CA59EC59ED347F228639106A6672C9A |
| Reporter | |
| Tags: | Yahoo z |
abuse_ch
Malspam distributing unidentified malware:HELO: sonic301-20.consmr.mail.sg3.yahoo.com
Sending IP: 106.10.242.83
From: Maizac Enterprise <maizacenterprise@yahoo.com>
Subject: Fw: Request Invoice PO 10154
Attachment: VCS58GQMhuCYghCpdf.z (contains "VCS58GQMhuCYghC.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
144
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-01-19 13:05:12 UTC
AV detection:
1 of 46 (2.17%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.55
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.