MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1626cec50a32f38f60295b8455ceb3ac7ff0dcac5bda6593e9685039ac54fbfc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 1626cec50a32f38f60295b8455ceb3ac7ff0dcac5bda6593e9685039ac54fbfc
SHA3-384 hash: ea8f75f27bfa4c29214ee43fc7e210b7233cb19abe9ad904ebd7bbd1760dac0eb6ddc581d1223daa86cbcd3d7df6a8de
SHA1 hash: d8923bd2becc8dc2eae9bbf1114c4f67a9342240
MD5 hash: 8b4d10da155a97ed0f529846e48160d7
humanhash: magazine-batman-mexico-blossom
File name:H4A2-423-EM152-010.TIF_xls.ace
Download: download sample
Signature Formbook
File size:461'929 bytes
First seen:2020-11-07 10:06:07 UTC
Last seen:Never
File type: ace
MIME type:application/x-rar
ssdeep 12288:Jnho0d0MeO/WatEgGVPZGtGV6dJlkuIchvWSvtAgmsN:pd0AtOxGjCIhuYn/N
TLSH 79A423EBA9388598B430C374CC5DF3FE38669D8505B482EF23B724551621C996E077EB
Reporter abuse_ch
Tags:ace FormBook geo KOR


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: mail-smail-vm50.hanmail.net
Sending IP: 203.133.180.238
From: 권성록 <dy5648@daum.net>
Subject: 견적문의 드립니다.(권성록 입니다.)
Attachment: H4A2-423-EM152-010.TIF_xls.ace (contains "H4A2-423-EM152-010.TIF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-11-05 09:10:47 UTC
AV detection:
24 of 48 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

ace 1626cec50a32f38f60295b8455ceb3ac7ff0dcac5bda6593e9685039ac54fbfc

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments