MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1e74c1eeb3cc1017ad88de0588d82b31fa5b0de826f4555a77bfbd9f1265dd8f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 1e74c1eeb3cc1017ad88de0588d82b31fa5b0de826f4555a77bfbd9f1265dd8f
SHA3-384 hash: a5c6baab9cecc6a09909e21661b40f8a3e5972aa5a2b82f605f2d7fed075df52f6594856c56bff3b72106369cac4b9cb
SHA1 hash: 39f2051d20c1d8463e47da0ecbc9987c7c358128
MD5 hash: b11c74fe738b935d1d90ad905c5ac046
humanhash: eleven-purple-network-south
File name:Anekgroup Order.zip
Download: download sample
Signature FormBook
File size:460'561 bytes
First seen:2020-08-17 18:54:40 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:UiCL15Um7OsQoKukUCateQipw+sUBMsbmDDxqmNPguh6:Ud5U2OsQVukXQiphs/sbmRqmOuh6
TLSH E4A42321FC7C21FC6D8EDE46B7984BA753D0A11E9562143B8F389D2D2A97B04BC72612
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: mail.pickelhost.com
Sending IP: 156.96.59.30
From: Anek Group <naqib@anekgroup.com>
Subject: Delivery Notification
Attachment: Anekgroup Order.zip (contains "Anekgroup Order.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-17 18:56:07 UTC
AV detection:
14 of 48 (29.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 1e74c1eeb3cc1017ad88de0588d82b31fa5b0de826f4555a77bfbd9f1265dd8f

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments