MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 16b88923e093887264a89d98d151c5c50ae1d4813923a279ebd6c78c6e02c9d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 16b88923e093887264a89d98d151c5c50ae1d4813923a279ebd6c78c6e02c9d7
SHA3-384 hash: 9f2d603ac48869900a1e34d49cb1180da42e32b36d6a105f8b4d28dd530e57cca92ae624a92f946ce39e0b5eb07b2ea1
SHA1 hash: 35b91bb453a4abaa7580e873c539803a9430d8e5
MD5 hash: b5245ab83632dfd2259905c2a66410b6
humanhash: mississippi-floor-magazine-alpha
File name:Reversed order 68906.zip
Download: download sample
Signature FormBook
File size:231'856 bytes
First seen:2020-07-15 06:11:45 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:fiSkuDy8+V6fOATuw/6lXb2B2h2H5bdXhoYqC6hO2:fiC46fONwUC2y5pz8p
TLSH 0834234741FC5D0D77303B2E6D7875DEB3B0886AA4B3227CEB1D3634265A5986A23E42
Reporter jarumlus
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
98
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-15 02:08:00 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 16b88923e093887264a89d98d151c5c50ae1d4813923a279ebd6c78c6e02c9d7

(this sample)

  
Dropped by
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments