MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 55e112824b2b5ab36c8bee4b5653f0a08403e1daf0e32211e5436fd5545a6bda. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 55e112824b2b5ab36c8bee4b5653f0a08403e1daf0e32211e5436fd5545a6bda
SHA3-384 hash: 5ebc4268da11b6ab23023281359f5a5b5b6ba15b5ee18a5470611a92fcae099f3149c9ba105b66039cc24009708d3b4c
SHA1 hash: 9ccd7fda14d379608d215dfbb56ba76d4249abe9
MD5 hash: 26042ee1d98ebd0a692b5fd798e800b9
humanhash: pasta-blossom-nineteen-oklahoma
File name:TR_008 Purchase Order.iso
Download: download sample
Signature Formbook
File size:847'872 bytes
First seen:2020-10-09 06:10:16 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:nqOkbtgxFka6c9ntitV/0NvLF2n33HfBZXfeJj9CFpaSe3iLgu1VUk5u6PEOQWdf:ntxOjc9nItVsVF23LeUp+3ijck5
TLSH 46059DAC325075EFC95BC876CEA82C64EA117477531BD203A06B16AD9E0DA9BCF141F3
Reporter abuse_ch
Tags:FormBook iso


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: host.kroser.com.uy
Sending IP: 162.211.86.3
From: Hangzhou Zhejiang Co., Ltd. <sales@technorexco.com>
Subject: RFQ # Q20182401 // ORDER_N ° 10014 // New_Suppliers_Ord er / [OCT-DEC]
Attachment: TR_008 Purchase Order.iso (contains "TR_008 Purchase Order.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-09 01:39:23 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

iso 55e112824b2b5ab36c8bee4b5653f0a08403e1daf0e32211e5436fd5545a6bda

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments