MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 20a4934e72fc856522d1b5babd3014bf2435cfb0dd6795cf11902d387ba925eb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 3
| SHA256 hash: | 20a4934e72fc856522d1b5babd3014bf2435cfb0dd6795cf11902d387ba925eb |
|---|---|
| SHA3-384 hash: | e3e736dcd57823019b8eb96f6e61a4667f67ff44bfc709f7ca31989cef51f1ee5ec8c63829a203cb68e72dc9abae5a76 |
| SHA1 hash: | 68d1452d281ff65e546c0f3f763175f895733bbe |
| MD5 hash: | 3a13102d2198e2998213e638d7ae2bba |
| humanhash: | earth-ten-missouri-mexico |
| File name: | Order List.img |
| Download: | download sample |
| Signature | Formbook |
| File size: | 622'592 bytes |
| First seen: | 2020-08-28 06:43:35 UTC |
| Last seen: | Never |
| File type: | img |
| MIME type: | application/x-iso9660-image |
| ssdeep | 12288:LaXr1Q+xJ3EkSUlWCK+wnlqtDUpOZWfq/dEvkIlspYGIx/QZNL:YJ0fCK+GcFU+f/dEvkcspYGj |
| TLSH | 12D41206768CCD5AC4AD417B29A0E8110BB9FFA14224DE0A2CDE25E84BB63D5D7136F7 |
| Reporter | |
| Tags: | FormBook img |
abuse_ch
Malspam distributing unidentified malware:HELO: march.alignhosting.com
Sending IP: 67.205.123.150
From: Сергей Ермак <staniv.tatyana@omega.page>
Reply-To: aladdinq2011@gmail.com
Subject: Inquiry for Mobis and auto parts
Attachment: Order List.img (contains "Order List.scr")
Intelligence
File Origin
# of uploads :
1
# of downloads :
112
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-28 03:06:29 UTC
AV detection:
3 of 48 (6.25%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.