MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 489a6d6cb5d3553e1c70395ddb23ded672c3e840cc7188eec9a6e6a03688348b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 3
| SHA256 hash: | 489a6d6cb5d3553e1c70395ddb23ded672c3e840cc7188eec9a6e6a03688348b |
|---|---|
| SHA3-384 hash: | 9ac96458603e655b3f3ac08df5c08dba306a15578f06665ccdbdcee19a1bce621d0a5d1cb10d19203a8daafe0816320c |
| SHA1 hash: | 4a1b4cd4a136222d5a95a4e064da2ba8efe39e99 |
| MD5 hash: | 0b256ba5e9374140bea9331f9eb69034 |
| humanhash: | thirteen-wisconsin-seven-cola |
| File name: | balance, EUR 73, 000,.r00 |
| Download: | download sample |
| Signature | Formbook |
| File size: | 449'190 bytes |
| First seen: | 2020-11-03 06:18:18 UTC |
| Last seen: | 2020-11-03 10:38:41 UTC |
| File type: | r00 |
| MIME type: | application/x-rar |
| ssdeep | 12288:5RzEyZAU+pSP26/iZy7NqXiigTkhVcsDrQ+JxJ/fhLXE:rgyZhYSpMy7NQiDYhbFJxJ/9E |
| TLSH | 46A423C1A54E12976774C4D17EC93485D2F8BD6F3532222F2AB9E6C3446DAF2C08CA97 |
| Reporter | |
| Tags: | FormBook r00 |
cocaman
Malicious email (T1566.001)From: "revonda@calendarcompany.com"
Received: "from calendarcompany.com (unknown [103.153.78.33]) "
Date: "2 Nov 2020 16:09:22 -0800"
Subject: "RE: Balance Confirmation of EUR 73, 000,"
Attachment: "balance, EUR 73, 000,.r00"
Intelligence
File Origin
# of uploads :
6
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-11-03 00:37:12 UTC
File Type:
Binary (Archive)
Extracted files:
13
AV detection:
18 of 29 (62.07%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.