MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 20a4934e72fc856522d1b5babd3014bf2435cfb0dd6795cf11902d387ba925eb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 20a4934e72fc856522d1b5babd3014bf2435cfb0dd6795cf11902d387ba925eb
SHA3-384 hash: e3e736dcd57823019b8eb96f6e61a4667f67ff44bfc709f7ca31989cef51f1ee5ec8c63829a203cb68e72dc9abae5a76
SHA1 hash: 68d1452d281ff65e546c0f3f763175f895733bbe
MD5 hash: 3a13102d2198e2998213e638d7ae2bba
humanhash: earth-ten-missouri-mexico
File name:Order List.img
Download: download sample
Signature Formbook
File size:622'592 bytes
First seen:2020-08-28 06:43:35 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:LaXr1Q+xJ3EkSUlWCK+wnlqtDUpOZWfq/dEvkIlspYGIx/QZNL:YJ0fCK+GcFU+f/dEvkcspYGj
TLSH 12D41206768CCD5AC4AD417B29A0E8110BB9FFA14224DE0A2CDE25E84BB63D5D7136F7
Reporter abuse_ch
Tags:FormBook img


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: march.alignhosting.com
Sending IP: 67.205.123.150
From: Сергей Ермак <staniv.tatyana@omega.page>
Reply-To: aladdinq2011@gmail.com
Subject: Inquiry for Mobis and auto parts
Attachment: Order List.img (contains "Order List.scr")

Intelligence


File Origin
# of uploads :
1
# of downloads :
112
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-28 03:06:29 UTC
AV detection:
3 of 48 (6.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

img 20a4934e72fc856522d1b5babd3014bf2435cfb0dd6795cf11902d387ba925eb

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments