MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c8d2a9c48f6790892d085cac4622f0642b4aa666c5b8d837a31063b226d31714. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c8d2a9c48f6790892d085cac4622f0642b4aa666c5b8d837a31063b226d31714
SHA3-384 hash: 1b1db073aa3d97ff3b49001be5822d647ed1925cf3956991124f2f4366af6f4c486b70680a6596d9f182e5e5058972fa
SHA1 hash: a58890039491e2c5b1d0911fc0fe9deb0e2feabd
MD5 hash: 6100e4bd41ce13ce3ed4fca310453372
humanhash: massachusetts-charlie-diet-mountain
File name:P.I..rar
Download: download sample
Signature Formbook
File size:781'045 bytes
First seen:2020-11-05 08:54:29 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:sq3DMIuW8+WPOaWefjx448qUcU8Zkq8/6Nwuo+Se3MB0WYB366zMQwFmbIZcIaP0:VTMYTWWmfED8ZjDwF+SfB/SCFmbMSP/s
TLSH B5F4332D65760F8060A389F70B68794115F99F203AC09DAA02CF4F55B46BDA273FDB2D
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: elaguizy.com
Sending IP: 103.125.191.170
From: EL AGUIZY<irini@elaguizy.com>
Subject: RE: P/ INVOICE Draft TT And Documents of Balance Payment
Attachment: P.I..rar (contains "P.I..exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-11-05 04:33:21 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar c8d2a9c48f6790892d085cac4622f0642b4aa666c5b8d837a31063b226d31714

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments