MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0e4b5ab44742383ce8ea2299c730513ecf6162682702b53c81e9f500ab5b3821. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 0e4b5ab44742383ce8ea2299c730513ecf6162682702b53c81e9f500ab5b3821
SHA3-384 hash: 5728ecd90e01a36bd7667b1545a9ff333a4af767b239b243d5b513db18464578c6883fa818d5049966de36a45ebdb7aa
SHA1 hash: e4faf2deb99a4997ccbc7e681b7c08bbd5d5cc97
MD5 hash: 7c7efcaaad116ba2aaa84c04d7802508
humanhash: oxygen-carolina-arizona-lactose
File name:HMT-200810-02.rar
Download: download sample
Signature Formbook
File size:614'325 bytes
First seen:2020-11-05 15:37:08 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:NpvBLzOvQ/UXYJ6YMs0oF4pz6Jy840/R0yFryhTPL2oIuF9UzUZ1XTv:jFC7YJqzm70rL5FXTv
TLSH BCD42335E82C434906E5A70DB677CAEF953AC674EB7109C63A4CBC6D0602D5E2C9DC8B
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: dlveltex.co
Sending IP: 111.90.140.219
From: Mehrdad Jafari <M.Jafari@dlveltex.co>
Subject: Re: ORDER PO No.HMT-200810-02
Attachment: HMT-200810-02.rar (contains "HMT-200810-02.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-11-05 11:40:16 UTC
AV detection:
11 of 48 (22.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar 0e4b5ab44742383ce8ea2299c730513ecf6162682702b53c81e9f500ab5b3821

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments