MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 1d4857df391a573ee683a687e034cfdf2630ccd284412acc78b47213f7ec6179. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 3
| SHA256 hash: | 1d4857df391a573ee683a687e034cfdf2630ccd284412acc78b47213f7ec6179 |
|---|---|
| SHA3-384 hash: | c0f5ae02cbc60da7b57626f9c11c8b34c761a2455c3fb4110cbea0c88a59c3fd70ff852ee3df5494f5ec76ee3b1e611a |
| SHA1 hash: | fcc9d20547403b58f85c5c06262c88b7f36dab97 |
| MD5 hash: | 65a7f4955a89d7144e1351f831caf046 |
| humanhash: | nebraska-magnesium-comet-pennsylvania |
| File name: | S343160101221012616310.rar |
| Download: | download sample |
| Signature | Formbook |
| File size: | 651'269 bytes |
| First seen: | 2021-02-04 07:09:55 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 12288:7KXGc34sNjWWsgqkGWrW5E1h2c6lOrPw0jSUfMMUja3NpesDNBOIorERI:2X53/NqWsgr5W5E/2NMiUBgYNwsDNBvA |
| TLSH | 64D4230616626FB9534FAC994E609050E0ADD7A0C43ACFFC2C14CD957E72A96D839FB3 |
| Reporter | |
| Tags: | rar |
Intelligence
File Origin
# of uploads :
1
# of downloads :
94
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-04 02:56:47 UTC
AV detection:
23 of 47 (48.94%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.