MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 397ba9cec424917d80168f055586a562da66a6d36653517e4922656120e9f453. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 397ba9cec424917d80168f055586a562da66a6d36653517e4922656120e9f453
SHA3-384 hash: 2d75095adf1a37e71708f90a3bc65e2b1e0063e3a5d969216f0caf106fe5e3557bae490c59143a00b5b741fa25f6e4bf
SHA1 hash: 580570b6f55cf5adbf3a6a33023179af63ca559e
MD5 hash: f7e768a9e9a1136011838ab646ec9935
humanhash: cold-arizona-stairway-alabama
File name:invoice.rar
Download: download sample
Signature FormBook
File size:307'924 bytes
First seen:2020-07-10 07:03:42 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:7768O8GgWdX0JZfkICtjQiplc0FWnWxiX2QQkCkK1187:fhO8rFJZfDCWwFiWximQLEU
TLSH 59642385BFA48D07EEFAC35FC878F6BD0AB824055D06D4EB2D1D48385A92CCE95F2601
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: slot0.olyatise.com
Sending IP: 45.95.169.159
From: info@olyatise.com
Attachment: invoice.rar (contains "invoice.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-10 07:05:10 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar 397ba9cec424917d80168f055586a562da66a6d36653517e4922656120e9f453

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments