MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8f9d2241f1054c785b3af71a82641c6c9abe571bc537c245d1bfe82f5e85cbe3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 8f9d2241f1054c785b3af71a82641c6c9abe571bc537c245d1bfe82f5e85cbe3
SHA3-384 hash: 99513cf89247a4d592acbbb8ebe261235a3688bbe770f5acd11e36bfc24f8964e91d089d7fd2a98cdee2197649777dc9
SHA1 hash: ae034ac7e218d083a3a00a6b7e982e3b574f2e9b
MD5 hash: 74d790d2238388c81e4798100c3bbe07
humanhash: pluto-bravo-butter-harry
File name:February Order.zip
Download: download sample
Signature Formbook
File size:549'646 bytes
First seen:2021-01-18 08:29:30 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:f7/6822kxXoW6aLI76k6KC2XiSssnqkV6xDEfbHL1u:f7O2dW6a8IULu4Dr1u
TLSH FFC423C4FB34F66671DE2F1E6B1CA7ADAC1B12E5C4FB058441925E3CA21C945A2D32F8
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: cbdjo.cam
Sending IP: 111.90.159.32
From: =??Q?Petros_Malaktos=C2=A0?= <krystianrednose@interia.pl>
Reply-To: mzahar04@protonmail.com
Subject: FW: February Order
Attachment: February Order.zip (contains "February Order.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
112
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-18 04:07:27 UTC
AV detection:
8 of 46 (17.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 8f9d2241f1054c785b3af71a82641c6c9abe571bc537c245d1bfe82f5e85cbe3

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments