MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 79a8a0785e9d0f2da6728711ae2fff11237f34cef45dc85365b9c4044e9d7036. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 79a8a0785e9d0f2da6728711ae2fff11237f34cef45dc85365b9c4044e9d7036
SHA3-384 hash: f4ba00ceedfeee531f3e8785ebe6878928470fdd99ee738cb8b673e3cdc344e499e74d6cada596c2d555b989baf375e0
SHA1 hash: 1f58577c00d8d975058bb8bc0c35f3983532f274
MD5 hash: c64d786cbc4032a0b7809951944162b1
humanhash: uranus-crazy-mountain-michigan
File name:Payment advice.zip
Download: download sample
Signature Formbook
File size:385'784 bytes
First seen:2020-10-21 09:50:34 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:c6kcDvQbtI9YMGBo2hNHgvCljtZSS5AyrpuAJS8XFQLQjUhGMOn5qx+HPb:vkWQbk2XzdpXOLNhAuqD
TLSH F8842345BC62E19ECFFA6019D12588594D6DF167EB76C8B0F8459362DC9CF283CE8C22
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: jupiter.flywan.net
Sending IP: 179.50.4.12
From: support <support@qbasica.com>
Subject: FW: Payment Advice 21.10.2020
Attachment: Payment advice.zip (contains "Payment advice.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-21 04:14:22 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 79a8a0785e9d0f2da6728711ae2fff11237f34cef45dc85365b9c4044e9d7036

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments