MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e40091536b294e6fb16b1b18fe45069dc3b4ebb69f90f5b8b6d3e66e45540a6e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: e40091536b294e6fb16b1b18fe45069dc3b4ebb69f90f5b8b6d3e66e45540a6e
SHA3-384 hash: 7ade94c3cfdeee2f080aedfeb0aea61031c8b6626f6222050cc4ad672c2376336292d5375fa4bb56b1dafb4404064572
SHA1 hash: 5dd41937d5302428dcec9713a906cf8e78625121
MD5 hash: 87132cff92e29a85cfe60970a62190c4
humanhash: finch-wolfram-item-neptune
File name:Quotation.gz
Download: download sample
Signature Formbook
File size:215'719 bytes
First seen:2021-04-08 06:52:55 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:BXRDOKX6D0xXr1CmukJg6gxzZkeht0pZXs5H/XIY:BXJnqir1Cmu5XHkef0pZXof4Y
TLSH 64242312EF152895AB308A142CA0C5E4BDDBACAB44D3AE59F47F05DE53D829C3C26CD7
Reporter abuse_ch
Tags:gz


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: mail.saresoft.net
Sending IP: 82.223.102.124
From: Barbara Liu / 刘莉 <liuli.hgxs@sinopec.com>
Subject: REQUEST FOR QUOTATION
Attachment: Quotation.gz (contains "Quotation.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.PUA.Wacapew
Status:
Malicious
First seen:
2021-04-08 04:40:02 UTC
AV detection:
14 of 48 (29.17%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

gz e40091536b294e6fb16b1b18fe45069dc3b4ebb69f90f5b8b6d3e66e45540a6e

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments