MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 66c0315c9cbcc1513e67548563e7ba370b4554d9a28574d7fcf925b063ce2985. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 66c0315c9cbcc1513e67548563e7ba370b4554d9a28574d7fcf925b063ce2985
SHA3-384 hash: 37ef814a51c45ad73e28bdff6cff23fd1a903e4bcf7a4fc1d5518585edf924ee04ae3cfd8b52b26bbffb96276856ae6d
SHA1 hash: cfc57ed606c71153a157d12d8e169bea5cb697f8
MD5 hash: b9bf9270a4a8c1be69b540f7b7aecf4a
humanhash: lithium-maine-five-monkey
File name:DHL Express Shipment Confirmation.zip
Download: download sample
Signature FormBook
File size:309'845 bytes
First seen:2020-07-15 05:42:31 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:mmkxktKH2Pib1Uz39rgB+fgemmvNzblan0w9xliz6x/:mzH22UT9G+vBbnwtiq/
TLSH 546423BACD0838215F51E45F89CA4BABBBCF47E6899F332D52BA40CB573D4D44660C1A
Reporter jarumlus
Tags:FormBook

Intelligence


File Origin
# of uploads :
1
# of downloads :
97
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-13 14:24:20 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip 66c0315c9cbcc1513e67548563e7ba370b4554d9a28574d7fcf925b063ce2985

(this sample)

  
Dropped by
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments