MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 34793c1f5717a9a3b892ae1b694c9c0750eaafe83cce73cdc57148eb730bef9f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 34793c1f5717a9a3b892ae1b694c9c0750eaafe83cce73cdc57148eb730bef9f
SHA3-384 hash: 09e8eb774054804b482a2d5c4adf20e682139932dba9a2089b9948afeb593521b04f585edc7835b230cb397f63fcad53
SHA1 hash: 0a07d91f7cc62b769f5f3911ac85353884e88a18
MD5 hash: 4039288790bfd9f2c3991b0ee4d777e8
humanhash: ceiling-carolina-pluto-carbon
File name:New_PO17-08-20TNQ1.zip
Download: download sample
Signature Formbook
File size:326'327 bytes
First seen:2020-11-26 06:44:48 UTC
Last seen:2020-11-27 08:23:35 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:KDpPOlMVUjfso2zBx3SC++usB9bTt+7kz5YAGGIjPBKTgRtDH:KDdaMe0Lb3tbuAxIjptz
TLSH 3B6423C3625C2FD5A72558F277BC06D52736A2DA90849E7E279ACF4FD13082C89C13B5
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: ncsline.com
Sending IP: 193.56.28.122
From: Margret Sarwar <accounting-spo@ncsline.com>
Subject: New_PO #17-08-20TNQ1
Attachment: New_PO17-08-20TNQ1.zip (contains "anthon.exe")

Intelligence


File Origin
# of uploads :
4
# of downloads :
144
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-11-26 00:54:24 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 34793c1f5717a9a3b892ae1b694c9c0750eaafe83cce73cdc57148eb730bef9f

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments