MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 24adb6ee45614d8945b89b01ce542a9a6451d42d29460e2a1b16d4a254f2cc00. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 24adb6ee45614d8945b89b01ce542a9a6451d42d29460e2a1b16d4a254f2cc00
SHA3-384 hash: e1ba6a3d1d749d65282ebbc8d577636fef194e1f772bffb773ea4413564a3d24fb35d2cd2deb1b453719f9511a123763
SHA1 hash: bd6c11e8382dea37b8148457e02b04223dde970d
MD5 hash: b67d5629b84d81e872c691d5f3f316dd
humanhash: delaware-fourteen-may-bakerloo
File name:INV.2020.06.005997.DOCX.img
Download: download sample
Signature AsyncRAT
File size:1'245'184 bytes
First seen:2020-07-13 05:24:01 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 3072:kR4y2uibi4a+5gbeDTukRjl0BcU8u657OL6zE6iJykmHDM57/aMxTX:Py2uR+OeuDii+zcykr5me
TLSH 3845DFD9B6DD0337FF4A4AB97D593302C2B2816A1152F38A3A8DF7649F973C54A012D2
Reporter cocaman
Tags:AsyncRAT img


Avatar
cocaman
Malicious email
From: GLASSDRIVE ASKIM <post@io-bilglass.no>
Received: from submit.uniweb.no (submit.uniweb.no [91.207.158.117])
Date: Mon, 13 Jul 2020 01:51:56 +0200
Subject: Payment declined
Attachment: INV.2020.06.005997.DOCX.img

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-07-12 23:31:16 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AsyncRAT

img 24adb6ee45614d8945b89b01ce542a9a6451d42d29460e2a1b16d4a254f2cc00

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AsyncRAT

Comments