MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 1a4809d9659b8a22d5d49392e0fde83c9eec86edcfe5900a7ffd78524c0b3b8f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
FormBook
Vendor detections: 4
| SHA256 hash: | 1a4809d9659b8a22d5d49392e0fde83c9eec86edcfe5900a7ffd78524c0b3b8f |
|---|---|
| SHA3-384 hash: | 8e4232eb8e4a489207acb25eedda9aa70e877ff2bee6607ddb0e3497466345af75b0e7a79e75b9c892237e021a7a5ebd |
| SHA1 hash: | f9b6b6353dd977d64cbe70d70be0e8e2de4e25f2 |
| MD5 hash: | 36a462af7f1045560fe42ecae544586f |
| humanhash: | steak-sixteen-oven-hawaii |
| File name: | Remittance copy.rar |
| Download: | download sample |
| Signature | FormBook |
| File size: | 347'501 bytes |
| First seen: | 2020-08-18 13:12:47 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 6144:/3frXgn+n+S3NaBh4UKwat1i1/Z3dtS+JHKx1HBjJj5SJe4+cF0lqgsrm78M+g9:/frXgm+Dvoi1/vtxe9FXygsrF30 |
| TLSH | 567423218D887CE556BEB391BB39C8FB16184DE16B7EAB07389F914E5E4850C83C1CB5 |
| Reporter | |
| Tags: | FormBook rar |
abuse_ch
Malspam distributing FormBook:HELO: mail.environment.go.ke
Sending IP: 41.89.1.174
From: ADMIN <cas@environment.go.ke>
Subject: Balance Payment_Y/ref Invoice No. 309320_ EK
Attachment: Remittance copy.rar (contains "Remittance copy.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-18 13:14:09 UTC
AV detection:
15 of 48 (31.25%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
FormBook
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.