MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1daa69bf8214760ffc96ca16b99e4a42bf98b2777843f86afdedd98de63e57fb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1daa69bf8214760ffc96ca16b99e4a42bf98b2777843f86afdedd98de63e57fb
SHA3-384 hash: 9b3540e7332dc84bec0213dd9178729cd5c04cac04dc199fd709a2812388a132c4963aca43065a199f109866e1f4414f
SHA1 hash: 07f287d33f88852cdecb83702011c6ab3d56feaf
MD5 hash: 89c45559b4df1b5e48b10724f3e4549c
humanhash: missouri-network-football-december
File name:Pay-in-Dco.rar
Download: download sample
Signature FormBook
File size:236'984 bytes
First seen:2020-06-24 07:36:59 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:ZsYQt53jPtMtipZ104HuBQv7OwzECDBUbb7UgA:ZstjjOMpZ103+OERlG/m
TLSH C934232E75BF0D16A0AB2DC212D0E1561D3D27BC01791A38B558783ED9F8258BF1D7C8
Reporter abuse_ch
Tags:FormBook rar Yahoo


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: sonic305-19.consmr.mail.sg3.yahoo.com
Sending IP: 106.10.241.82
From: joy sales <salejoy43@yahoo.com.sg>
Subject: FW: Payment Transfer
Attachment: Pay-in-Dco.rar (contains "Pay-in-Dco.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-24 07:38:06 UTC
AV detection:
13 of 29 (44.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar 1daa69bf8214760ffc96ca16b99e4a42bf98b2777843f86afdedd98de63e57fb

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments