MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 9664c1d1ad01ca49f8cbad4d2551013683fd2e267b16351068bd9c750a4dcb78. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 4
| SHA256 hash: | 9664c1d1ad01ca49f8cbad4d2551013683fd2e267b16351068bd9c750a4dcb78 |
|---|---|
| SHA3-384 hash: | abb5e5717ec3a714e6219354a6940594bac11a3726dc1c9a0f1a86b211f04452ec6f6b946f449fb46a77c9998e5afd48 |
| SHA1 hash: | 719dd5b6af3c1fa1a01fab87ee9d5bcf8f806422 |
| MD5 hash: | 867f5ff212f0698e76cab9f9152731f9 |
| humanhash: | sodium-mockingbird-emma-six |
| File name: | Ref. PDF IGAPO17493.r07 |
| Download: | download sample |
| Signature | Formbook |
| File size: | 736'914 bytes |
| First seen: | 2021-04-08 15:44:38 UTC |
| Last seen: | Never |
| File type: | r07 |
| MIME type: | application/x-rar |
| ssdeep | 12288:WImZHXgpkzaPbQokKV+BB5otsFufmjr0ZIJncZ2arhmUi3rh6Jyt/k:WImZHXgpk2Pb3k/BB5oi8mjrXJin9mHG |
| TLSH | 07F423EA2583B0C2C3D93F2B5CBE4B2D3F4D765680B45C528C74525E50EABEEE46948C |
| Reporter | |
| Tags: | FormBook r07 |
abuse_ch
Malspam distributing unidentified malware:HELO: experticsmail.expertics.com.mx
Sending IP: 187.217.245.25
From: Ideal Glass & Aluminium Works Sdn. Bhd.<emma.linderothh@dhl.com>
Reply-To: Ideal Glass & Aluminium Works Sdn. Bhd.<rolandskin@mail.ru>
Subject: Purchase Order (Ref. IGA/PO/17493)
Attachment: Ref. PDF IGAPO17493.r07 (contains "Ref. PDF IGAPO17493.Scr")
Intelligence
File Origin
# of uploads :
1
# of downloads :
189
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-04-08 15:45:12 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.