MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5162e5537eaf72f20d9868894a797331e2e01f1460eadb7f12a6a66a1c96d179. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5162e5537eaf72f20d9868894a797331e2e01f1460eadb7f12a6a66a1c96d179
SHA3-384 hash: c297ddd332f4503865a07b7370c018892fb87d8d1f7819bb5aaac253e6102a5ebb42c3d47fbd1b7473569323a8457506
SHA1 hash: b997443b793e3e8fc1f00a650c1710fbbe70b9b5
MD5 hash: 740770f1fec614517dd0dd7c42bad8de
humanhash: steak-angel-coffee-harry
File name:payment invoice.img
Download: download sample
Signature FormBook
File size:356'352 bytes
First seen:2020-07-07 06:26:37 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:CxaIT3YMasZRaCxz1dpTNzqpvDsjnrCGSzhjElOtQWcKng/GS:jIrYMtd5MKnSzBElOWWPg/3
TLSH 1E740185B3A44316D87E03B9A8A2C1B403797E524635DB6E6DCD2CCF7B273248A41F5B
Reporter abuse_ch
Tags:FormBook img


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: mail0.506.simonleehung.casa
Sending IP: 46.101.184.147
From: Shabeer M. T <shabeermt@lamco.ae>
Subject: Re: Payment Assistance Due To Covid-19 Pandemic
Attachment: payment invoice.img (contains "payment invoice.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-07 03:09:17 UTC
AV detection:
10 of 27 (37.04%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

img 5162e5537eaf72f20d9868894a797331e2e01f1460eadb7f12a6a66a1c96d179

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments