MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c9450a71b733b676444075423932f94082ac7d409aaee9a68adb15c507231bab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: c9450a71b733b676444075423932f94082ac7d409aaee9a68adb15c507231bab
SHA3-384 hash: bdd15d0f84742e32c7bfc2565c84756e4f707e83163755af5725bb61a4166f3b3d56137445266bf66b0b612e99a7ddf8
SHA1 hash: a8e894532671d2307a5ac80164510487c06890ed
MD5 hash: 43494d6169afd958a81595f294edf204
humanhash: princess-maine-item-beryllium
File name:SCAN_20210112_132640143,pdf.cab
Download: download sample
Signature Formbook
File size:535'120 bytes
First seen:2021-01-12 07:25:26 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 12288:fifDi9pJuznl9Nl7Ze4WaCwk2PGhBBKieqQEmzCQeCj:eYpJu7JVOdt2ehBBI7EE/
TLSH BBB4237DBF12A01EF9A072B6ADF7C483938B1099F2C4C95EB4B916414258E3481E57FE
Reporter abuse_ch
Tags:cab FormBook geo KOR


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: mail-smail-vm31.hanmail.net
Sending IP: 203.133.180.215
From: 태림종합건설 <e-taelim@hanmail.net>
Subject: 우리를_인용하십시오 (원소재 요청드립니다.)
Attachment: SCAN_20210112_132640143,pdf.cab (contains "SCAN_20210112_132640143,pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
169
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
SUSPICIOUS
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-01-12 07:26:19 UTC
AV detection:
4 of 46 (8.70%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

cab c9450a71b733b676444075423932f94082ac7d409aaee9a68adb15c507231bab

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments