MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5f8114d7abbf7e21f339fe9cc666931a2cd89bc4ef68de6e4030c25800649dc0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5f8114d7abbf7e21f339fe9cc666931a2cd89bc4ef68de6e4030c25800649dc0
SHA3-384 hash: 526ed581f3acb410596a8e1f34f2461c98fd8b1cd55052aaa7695e7079b0495ddabaaad1fe80d379b185502963eabf5d
SHA1 hash: 80b84a5173c97adf94028707705aad0745bb8f31
MD5 hash: 227251d9248fc05a0d3708197a9a8782
humanhash: green-maine-nineteen-stairway
File name:Calendario dei pagamenti.zip
Download: download sample
Signature Formbook
File size:612'617 bytes
First seen:2021-01-19 10:13:26 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:l11sbhttGK+tEO4WfSB0PXGa7ACH/GFq4j1VOj3MnDBdKNPMOvt08veToL0k:6bDtV2UCPWad14Cj3Mn9CMOvtNveUX
TLSH 5FD423CD11E132AA5CCF535B7A9BF0819FC8019A0758ED8FD6AF106FA9821D2165E4BC
Reporter cocaman
Tags:FormBook zip


Avatar
cocaman
Malicious email (T1566.001)
From: "a.tireli@immgroup.it" (likely spoofed)
Received: "from mail.litos.net (unknown [86.109.108.50]) "
Date: "Tue, 19 Jan 2021 01:58:33 -0800"
Subject: "Calendario dei pagamenti"
Attachment: "Calendario dei pagamenti.zip"

Intelligence


File Origin
# of uploads :
1
# of downloads :
138
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-19 10:14:05 UTC
File Type:
Binary (Archive)
Extracted files:
22
AV detection:
6 of 46 (13.04%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 5f8114d7abbf7e21f339fe9cc666931a2cd89bc4ef68de6e4030c25800649dc0

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
Formbook

Comments