MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e40091536b294e6fb16b1b18fe45069dc3b4ebb69f90f5b8b6d3e66e45540a6e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 5
| SHA256 hash: | e40091536b294e6fb16b1b18fe45069dc3b4ebb69f90f5b8b6d3e66e45540a6e |
|---|---|
| SHA3-384 hash: | 7ade94c3cfdeee2f080aedfeb0aea61031c8b6626f6222050cc4ad672c2376336292d5375fa4bb56b1dafb4404064572 |
| SHA1 hash: | 5dd41937d5302428dcec9713a906cf8e78625121 |
| MD5 hash: | 87132cff92e29a85cfe60970a62190c4 |
| humanhash: | finch-wolfram-item-neptune |
| File name: | Quotation.gz |
| Download: | download sample |
| Signature | Formbook |
| File size: | 215'719 bytes |
| First seen: | 2021-04-08 06:52:55 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/x-rar |
| ssdeep | 6144:BXRDOKX6D0xXr1CmukJg6gxzZkeht0pZXs5H/XIY:BXJnqir1Cmu5XHkef0pZXof4Y |
| TLSH | 64242312EF152895AB308A142CA0C5E4BDDBACAB44D3AE59F47F05DE53D829C3C26CD7 |
| Reporter | |
| Tags: | gz |
abuse_ch
Malspam distributing unidentified malware:HELO: mail.saresoft.net
Sending IP: 82.223.102.124
From: Barbara Liu / 刘莉 <liuli.hgxs@sinopec.com>
Subject: REQUEST FOR QUOTATION
Attachment: Quotation.gz (contains "Quotation.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.PUA.Wacapew
Status:
Malicious
First seen:
2021-04-08 04:40:02 UTC
AV detection:
14 of 48 (29.17%)
Threat level:
1/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.67
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.