MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 40fff2709ece475da3b7142fad661df228cd6c3c516880da4546fc656f060931. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 40fff2709ece475da3b7142fad661df228cd6c3c516880da4546fc656f060931
SHA3-384 hash: 76fa5dab43bdb357d23377d169b8a851244dc33bde5f608b4ce6a837104ec0c0d2e397acb620916e2fb938d23be28f35
SHA1 hash: ddb2c951a19ad1f16b27a7afff546ef2b036f687
MD5 hash: 36b6f10e78303304def20720ba89cf06
humanhash: lemon-asparagus-summer-snake
File name:Remittance Scan DOC-2029293PI207-048.txt.gz
Download: download sample
Signature Formbook
File size:700'832 bytes
First seen:2020-10-21 08:59:50 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:EDbYkiFZdUCAuRmPW6zxoQLxWD/0AU1JmI43Rp0/8bP5I6jAGWJvwhsboriDwD:nLFZuqRmu8k7g8bP5I6jAdvwhsbeiDwD
TLSH 76E433471A442588BEE663C49D5CAF03169AA7D8F4786147C700EB4F6ABDD3C6C8F1B8
Reporter abuse_ch
Tags:FormBook gz


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: geodis.com
Sending IP: 83.149.106.6
From: Nemanja Mijatovic <nemanja.mijatovic@geodis.com>
Subject: RE: Transfer Remittance (PI207-048)
Attachment: Remittance Scan DOC-2029293PI207-048.txt.gz (contains "Remittance Scan DOC-2029293#PI207-048.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-21 05:12:35 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

gz 40fff2709ece475da3b7142fad661df228cd6c3c516880da4546fc656f060931

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments