MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 af85cccb50e0d1132ec9a3c079adfb1d3acdc29fad58fbfa912adaecc94c9bea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: af85cccb50e0d1132ec9a3c079adfb1d3acdc29fad58fbfa912adaecc94c9bea
SHA3-384 hash: fb7b84bfbdaedac685e9a641b8c103a85fd37f1fae3d9f180a2e502bae12f4bc9d987dc9d6cce0cbfdde679c7587eed4
SHA1 hash: 0a01033940586e513ddea26860bbbefbf3d9e6a6
MD5 hash: 2929f40c60de23e98dc0b7b9f481e4f2
humanhash: hotel-queen-hot-lima
File name:9NH90853.rar
Download: download sample
Signature Formbook
File size:450'939 bytes
First seen:2021-01-18 08:25:29 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:6redAbrlZYOLjDF/H7Ce/Lx8CJZehBu/u3IMkpU6jMHaDMq:6ydmJiOLPF/ua8aorHRkpUv6DMq
TLSH 5CA423FC8EB78E908CB5A96A66F731C562A4DCD0E9884BF4C5FC107534CC76A214866F
Reporter abuse_ch
Tags:rar Yahoo


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: sonic315-15.consmr.mail.bf2.yahoo.com
Sending IP: 74.6.134.125
From: Frank Tom <franktom64@yahoo.com>
Subject: : Fwd: Wire Transfer Payment
Attachment: 9NH90853.rar (contains "9tyZf93qRdNHfVw.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
105
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-18 08:26:10 UTC
AV detection:
7 of 45 (15.56%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar af85cccb50e0d1132ec9a3c079adfb1d3acdc29fad58fbfa912adaecc94c9bea

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments