MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1a4809d9659b8a22d5d49392e0fde83c9eec86edcfe5900a7ffd78524c0b3b8f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 1a4809d9659b8a22d5d49392e0fde83c9eec86edcfe5900a7ffd78524c0b3b8f
SHA3-384 hash: 8e4232eb8e4a489207acb25eedda9aa70e877ff2bee6607ddb0e3497466345af75b0e7a79e75b9c892237e021a7a5ebd
SHA1 hash: f9b6b6353dd977d64cbe70d70be0e8e2de4e25f2
MD5 hash: 36a462af7f1045560fe42ecae544586f
humanhash: steak-sixteen-oven-hawaii
File name:Remittance copy.rar
Download: download sample
Signature FormBook
File size:347'501 bytes
First seen:2020-08-18 13:12:47 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:/3frXgn+n+S3NaBh4UKwat1i1/Z3dtS+JHKx1HBjJj5SJe4+cF0lqgsrm78M+g9:/frXgm+Dvoi1/vtxe9FXygsrF30
TLSH 567423218D887CE556BEB391BB39C8FB16184DE16B7EAB07389F914E5E4850C83C1CB5
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: mail.environment.go.ke
Sending IP: 41.89.1.174
From: ADMIN <cas@environment.go.ke>
Subject: Balance Payment_Y/ref Invoice No. 309320_ EK
Attachment: Remittance copy.rar (contains "Remittance copy.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-18 13:14:09 UTC
AV detection:
15 of 48 (31.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar 1a4809d9659b8a22d5d49392e0fde83c9eec86edcfe5900a7ffd78524c0b3b8f

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments