MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1adaa8420a2f3281e04fcc500815e5519fc3e52e8457fd36903f41b688f3501a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1adaa8420a2f3281e04fcc500815e5519fc3e52e8457fd36903f41b688f3501a
SHA3-384 hash: 7f4209324d434dc21290c24926e80b21379938116d0c233fbac63eb86c2be4dd9814b153a95abd38d1456f271d3699e9
SHA1 hash: 10b89919b72c6928911db9993cf598f03f2dc336
MD5 hash: bfc03e8f1f79c9bff2ffdcafc646a275
humanhash: romeo-nevada-mobile-jersey
File name:New Quotation.zip
Download: download sample
Signature FormBook
File size:635'782 bytes
First seen:2020-08-04 07:43:21 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:dERaWL3qljqVIxKHiKNi6WCfVpKhzbrp0lYU1B9eLZhvSJPem:qRaodMcN06WCfVpKhZUoLaIm
TLSH 59D4238CD519D9A3C49BF8BCA713DA81F72A94BA0D677359CFB905375110280A392FCE
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: cloudhost-150218.us-midwest-1.nxcli.net
Sending IP: 104.207.254.25
From: MORSTAR GENERAL TRADING <aarti.paigwal@morstar.com.in>
Subject: Morstar General Trading
Attachment: New Quotation.zip (contains "New Quotation.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-04 07:45:06 UTC
AV detection:
11 of 48 (22.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 1adaa8420a2f3281e04fcc500815e5519fc3e52e8457fd36903f41b688f3501a

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments