MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 489a6d6cb5d3553e1c70395ddb23ded672c3e840cc7188eec9a6e6a03688348b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 489a6d6cb5d3553e1c70395ddb23ded672c3e840cc7188eec9a6e6a03688348b
SHA3-384 hash: 9ac96458603e655b3f3ac08df5c08dba306a15578f06665ccdbdcee19a1bce621d0a5d1cb10d19203a8daafe0816320c
SHA1 hash: 4a1b4cd4a136222d5a95a4e064da2ba8efe39e99
MD5 hash: 0b256ba5e9374140bea9331f9eb69034
humanhash: thirteen-wisconsin-seven-cola
File name:balance, EUR 73, 000,.r00
Download: download sample
Signature Formbook
File size:449'190 bytes
First seen:2020-11-03 06:18:18 UTC
Last seen:2020-11-03 10:38:41 UTC
File type: r00
MIME type:application/x-rar
ssdeep 12288:5RzEyZAU+pSP26/iZy7NqXiigTkhVcsDrQ+JxJ/fhLXE:rgyZhYSpMy7NQiDYhbFJxJ/9E
TLSH 46A423C1A54E12976774C4D17EC93485D2F8BD6F3532222F2AB9E6C3446DAF2C08CA97
Reporter cocaman
Tags:FormBook r00


Avatar
cocaman
Malicious email (T1566.001)
From: "revonda@calendarcompany.com"
Received: "from calendarcompany.com (unknown [103.153.78.33]) "
Date: "2 Nov 2020 16:09:22 -0800"
Subject: "RE: Balance Confirmation of EUR 73, 000,"
Attachment: "balance, EUR 73, 000,.r00"

Intelligence


File Origin
# of uploads :
6
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-11-03 00:37:12 UTC
File Type:
Binary (Archive)
Extracted files:
13
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

r00 489a6d6cb5d3553e1c70395ddb23ded672c3e840cc7188eec9a6e6a03688348b

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments