MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9664c1d1ad01ca49f8cbad4d2551013683fd2e267b16351068bd9c750a4dcb78. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 9664c1d1ad01ca49f8cbad4d2551013683fd2e267b16351068bd9c750a4dcb78
SHA3-384 hash: abb5e5717ec3a714e6219354a6940594bac11a3726dc1c9a0f1a86b211f04452ec6f6b946f449fb46a77c9998e5afd48
SHA1 hash: 719dd5b6af3c1fa1a01fab87ee9d5bcf8f806422
MD5 hash: 867f5ff212f0698e76cab9f9152731f9
humanhash: sodium-mockingbird-emma-six
File name:Ref. PDF IGAPO17493.r07
Download: download sample
Signature Formbook
File size:736'914 bytes
First seen:2021-04-08 15:44:38 UTC
Last seen:Never
File type: r07
MIME type:application/x-rar
ssdeep 12288:WImZHXgpkzaPbQokKV+BB5otsFufmjr0ZIJncZ2arhmUi3rh6Jyt/k:WImZHXgpk2Pb3k/BB5oi8mjrXJin9mHG
TLSH 07F423EA2583B0C2C3D93F2B5CBE4B2D3F4D765680B45C528C74525E50EABEEE46948C
Reporter abuse_ch
Tags:FormBook r07


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: experticsmail.expertics.com.mx
Sending IP: 187.217.245.25
From: Ideal Glass & Aluminium Works Sdn. Bhd.<emma.linderothh@dhl.com>
Reply-To: Ideal Glass & Aluminium Works Sdn. Bhd.<rolandskin@mail.ru>
Subject: Purchase Order (Ref. IGA/PO/17493)
Attachment: Ref. PDF IGAPO17493.r07 (contains "Ref. PDF IGAPO17493.Scr")

Intelligence


File Origin
# of uploads :
1
# of downloads :
189
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-04-08 15:45:12 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

r07 9664c1d1ad01ca49f8cbad4d2551013683fd2e267b16351068bd9c750a4dcb78

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments