MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9740834e51cc749f6869a8b5f713116b41d9b26e244ef56a2f8a87f3ec00aef3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9740834e51cc749f6869a8b5f713116b41d9b26e244ef56a2f8a87f3ec00aef3
SHA3-384 hash: 6ec2b209f9bb04e1477539f272b045dcded6b3f00908c98fd9ec7b2ae3a91a931bee6aba541bc0bc2f93864113b07702
SHA1 hash: 2b5f8a57826fafe27703e022bd15fca537fa7982
MD5 hash: 2a66cce624f65728b510a252ad9c32b4
humanhash: juliet-mango-pluto-hydrogen
File name:NPD76122.rar
Download: download sample
Signature Formbook
File size:1'432'765 bytes
First seen:2020-12-24 09:20:49 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:DCdZzZRef3S4aFtS9UjtRpnY3UeNtFQtBEQbg0bnjjVqPFfCUISJvfapZ7x/DOc:DO57v4a+95UvsonjjyfCp0vfabx/DF
TLSH D065331F496A8990DF8DB8519B30EA0EBD0123ED9C3DD33325F1B0F6F655A48A586C78
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: pbb0000039.promail.vn
Sending IP: 103.237.151.43
From: Jane Liu<huynh.mai@mikazuki.com.vn>
Reply-To: <debora.pacini14@gmail.com>
Subject: Re: Bookings
Attachment: NPD76122.rar (contains "NPD76122.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
284
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
4
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-12-24 09:21:05 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar 9740834e51cc749f6869a8b5f713116b41d9b26e244ef56a2f8a87f3ec00aef3

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments