MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d1cbc44ad223a23c6f6e07ca5e1af74bf4f5fc64e1aafc518b5f4959c80b780. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4d1cbc44ad223a23c6f6e07ca5e1af74bf4f5fc64e1aafc518b5f4959c80b780
SHA3-384 hash: 2c6d58af810af311d83592aa4752b798a90b7a93eb3f58f4bfef26da47a6bf9769177873ac8bd729419def96d999afea
SHA1 hash: 26f39dcdc72c27cc2e37a9fba5d7a387341e9106
MD5 hash: b9489018282e61d5571a2d842cc365b2
humanhash: enemy-diet-grey-uniform
File name:Quote22.zip
Download: download sample
Signature FormBook
File size:438'547 bytes
First seen:2020-08-06 07:58:51 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:rlSEoOjM2hLOgQD6KtDSuSv04Azvb8TEmrH96:ggXhBQ5tDfN4SvbqzrH96
TLSH E194238DBC062A577D640322AC3DA502684FF071FB6EB5674DDA454C829BBCD78326D3
Reporter abuse_ch
Tags:Endurance FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: 162-241-204-248.unifiedlayer.com
Sending IP: 162.241.204.248
From: Daniel Chen < server@hinet.net>
Subject: Immediate quote required
Attachment: Quote22.zip (contains "Quote22.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-06 08:00:07 UTC
AV detection:
20 of 28 (71.43%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 4d1cbc44ad223a23c6f6e07ca5e1af74bf4f5fc64e1aafc518b5f4959c80b780

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments