MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 87e11ec7352f195bc1b4d4be2eb58bc8f20e56dab2e77ce7969bdd99ae25eb29. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 87e11ec7352f195bc1b4d4be2eb58bc8f20e56dab2e77ce7969bdd99ae25eb29
SHA3-384 hash: 291e7e6b0c136ca027869a5fde86c24e07824ee1ce404b92774c780e70ab9900a0aa63cddfecc8566db708c7469be155
SHA1 hash: 08ff53e63e96a640f976aae5f15ab55c6e1956cf
MD5 hash: b7cca09820651acd746166ee653a3929
humanhash: uniform-sink-sad-ack
File name:Copy-andamiro566.iso
Download: download sample
Signature FormBook
File size:1'245'184 bytes
First seen:2020-06-24 07:35:19 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:+GihdYseMXF9Ns+GiQzbQoA/50JgyqbekuBHe/8vrpsGJw7CXdjJn/FoI8e:TJMX3N/Im/5igyQSBw8VW7CXdjB
TLSH A145E007374CAB17C17C1AF954D26F4463BA59AAB681FACA3CCC62941BC37E649213C7
Reporter abuse_ch
Tags:FormBook iso


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: mx.andamiro.com
Sending IP: 49.247.9.203
From: 이진영 <pinkpig72@andamiro.com>
Subject: Re:
Attachment: Copy-andamiro566.iso (contains "copy #24445.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-24 07:37:04 UTC
AV detection:
13 of 29 (44.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

iso 87e11ec7352f195bc1b4d4be2eb58bc8f20e56dab2e77ce7969bdd99ae25eb29

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments