MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ab243bf4171b89fd4ba2c6324788e84975591354774cd23f5377a48e1d6ac51. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0ab243bf4171b89fd4ba2c6324788e84975591354774cd23f5377a48e1d6ac51
SHA3-384 hash: b64840119fe4210bd7359831008ec35d21a02ec1c7afb36d6fd1aec26ebeae61027824edf30347256d38a7eace2f5b16
SHA1 hash: 1466abf37f99511374809324970effbbe44193d4
MD5 hash: 66abe9eca06d7020489165f7c83c8c2a
humanhash: georgia-lemon-robin-edward
File name:Purchase order nr.0119-21.pdf.gz
Download: download sample
Signature Formbook
File size:662'010 bytes
First seen:2021-01-19 07:30:01 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:Sb76ajhvfDCdnkkU3FQ2Borc5hc5fqSfYs45Oexvz26og+A4:SbGodenJUHBowhc5XYs1exbAgb4
TLSH 7FE4238B4E72C048785DF7304F13D62179FB80E209C91AC887A7E917259E3946DBAE76
Reporter abuse_ch
Tags:FormBook gz


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: smtp.nexconn.com.br
Sending IP: 77.48.43.64
From: Israel Carvalho <sales3@nexconn.com.br>
Subject: Purchase order nr. 1054-21
Attachment: Purchase order nr.0119-21.pdf.gz (contains "Purchase order nr.0119-21.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
146
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-19 07:30:26 UTC
AV detection:
11 of 46 (23.91%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

gz 0ab243bf4171b89fd4ba2c6324788e84975591354774cd23f5377a48e1d6ac51

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments