MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 d3dc5a8efbc7f86b130da983adfd31107a97cacf016214d6f0da55c54a29fb0a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 4
| SHA256 hash: | d3dc5a8efbc7f86b130da983adfd31107a97cacf016214d6f0da55c54a29fb0a |
|---|---|
| SHA3-384 hash: | 86d9f51939f73b8f6fab3af1a62b5a685f541f05c843708a8d090593cb3140badd8eb8eac15267dc11ee321cef7606fc |
| SHA1 hash: | c1c28f158f91071b0f59706e07b0fd538d436cea |
| MD5 hash: | ee696600587d1b03feb472c1dd2b355b |
| humanhash: | lactose-finch-floor-cola |
| File name: | AWBInvoice INA10197.zip |
| Download: | download sample |
| Signature | Formbook |
| File size: | 668'671 bytes |
| First seen: | 2020-12-28 07:56:55 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:yGRETL5ZFxAuSY/RN57n3Khx8Bfztwo17SBAs6AXsj8RKowB4:yHvliYJn4x8Bhr72Z6UrRK+ |
| TLSH | 4BE423314DAEE50BB30346269C85079EE62BF59B7466AE3E1941D8C68FD124AC2F70C3 |
| Reporter | |
| Tags: | DHL FormBook zip |
abuse_ch
Malspam distributing Formbook:HELO: dhl.com
Sending IP: 79.110.52.80
From: finansaltalepler@dhl.com
Subject: Your latest DHL invoice : SAWR000148651
Attachment: AWBInvoice INA10197.zip (contains "AWBInvoice INA10197.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
204
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-12-28 07:57:08 UTC
AV detection:
7 of 48 (14.58%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Formbook
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Formbook
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.