MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 02a2259bffb76809ebddfc7402a4c3e0c2c1b99f644ed91226620d9c2f5eb4c8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 02a2259bffb76809ebddfc7402a4c3e0c2c1b99f644ed91226620d9c2f5eb4c8
SHA3-384 hash: 2cced26318a9ecd4b3892296cf8af90cde254c1b44e21418bf4b8c5de09bd3c14a92404007d799d570c9d8cf35800813
SHA1 hash: d295b5f2b8c12dabd822c9fc9c6350ba63e3beb4
MD5 hash: 1e4619efbeeda1a9caf18f3900c48b1d
humanhash: earth-eight-shade-table
File name:PO20200060005 Alu Tube Of Jul 20 ALMET THAI.zip
Download: download sample
Signature Formbook
File size:296'491 bytes
First seen:2020-07-06 08:15:14 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:3e3RgpnFEO1ks1Wd+A0c4lS463E7UIKO6P97xvg2KdxVDtay:3e3RgrEO18d0l963y56F+/Vx/
TLSH CD5422DE1F7A112B21C22423478EEF11CE7B87629765443A896C43E637809CA7F6E45B
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: gmail.com
Sending IP: 107.173.40.221
From: Wanphen <sales@gmail.com>
Reply-To: ltbthuyposco@gmail.com
Subject: PO20200060005 Alu Tube Of Jul'20 // ALMET THAI
Attachment: PO20200060005 Alu Tube Of Jul 20 ALMET THAI.zip (contains "PO20200060005 Alu Tube Of Jul 20 ALMET THAI.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-06 08:17:05 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 02a2259bffb76809ebddfc7402a4c3e0c2c1b99f644ed91226620d9c2f5eb4c8

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments