MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0e234ba687dd6bc123e8e3da1412f7e8bba502fca6559accd526ec19ee779019. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 0e234ba687dd6bc123e8e3da1412f7e8bba502fca6559accd526ec19ee779019
SHA3-384 hash: f8a66a112274e4734fa6fe3772d26d015b57640bccf95aa35c06376d51b1a3996394265d0b46fffbfaa946f257a7e272
SHA1 hash: 67004dc00eb0a14d3534724a6cd21285a32bf29e
MD5 hash: 55c161c75eebba86b2dddb702f7e170f
humanhash: december-venus-finch-black
File name:PAYSLIP.zip
Download: download sample
Signature FormBook
File size:444'142 bytes
First seen:2020-08-14 08:54:21 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:HSl+YWixiBOfnZIegBgO6hHtYo2JsCIymZ37s:yl4BcFYgO6hHE4yu7s
TLSH AB9423657C16E4765D0EAF20C1E35A2B972FE95069D8BAB1502FC7F4C920B460CEE8DC
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

From: Jian Zheng <server@hinet.net>
Subject: Please confirm payment
Attachment: PAYSLIP.zip (contains "PAYSLIP.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-14 08:56:06 UTC
AV detection:
15 of 48 (31.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 0e234ba687dd6bc123e8e3da1412f7e8bba502fca6559accd526ec19ee779019

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments