MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0e234ba687dd6bc123e8e3da1412f7e8bba502fca6559accd526ec19ee779019. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
FormBook
Vendor detections: 4
| SHA256 hash: | 0e234ba687dd6bc123e8e3da1412f7e8bba502fca6559accd526ec19ee779019 |
|---|---|
| SHA3-384 hash: | f8a66a112274e4734fa6fe3772d26d015b57640bccf95aa35c06376d51b1a3996394265d0b46fffbfaa946f257a7e272 |
| SHA1 hash: | 67004dc00eb0a14d3534724a6cd21285a32bf29e |
| MD5 hash: | 55c161c75eebba86b2dddb702f7e170f |
| humanhash: | december-venus-finch-black |
| File name: | PAYSLIP.zip |
| Download: | download sample |
| Signature | FormBook |
| File size: | 444'142 bytes |
| First seen: | 2020-08-14 08:54:21 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:HSl+YWixiBOfnZIegBgO6hHtYo2JsCIymZ37s:yl4BcFYgO6hHE4yu7s |
| TLSH | AB9423657C16E4765D0EAF20C1E35A2B972FE95069D8BAB1502FC7F4C920B460CEE8DC |
| Reporter | |
| Tags: | FormBook zip |
abuse_ch
Malspam distributing FormBook:From: Jian Zheng <server@hinet.net>
Subject: Please confirm payment
Attachment: PAYSLIP.zip (contains "PAYSLIP.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-14 08:56:06 UTC
AV detection:
15 of 48 (31.25%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Kryptik
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
FormBook
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.