MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 53bd75e6b7540d1a58ac9facb9e0bab2dd9782dfb53e0b667c5551d964da820c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 53bd75e6b7540d1a58ac9facb9e0bab2dd9782dfb53e0b667c5551d964da820c
SHA3-384 hash: ccee7ac4656dd4f055254ce3db96ce97d92883370e5503e180a4b6463875b9dcd27bef887c2d4df6c18b52dd19e9cc5e
SHA1 hash: 637c0c09dbe8b217c29e1b040b1b01fd3eb3c8f9
MD5 hash: 48f9e09f5b9c1336ff7425c0cba06c82
humanhash: michigan-music-washington-monkey
File name:QUOTE 5.rar
Download: download sample
Signature FormBook
File size:275'171 bytes
First seen:2020-05-20 07:45:53 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 3072:ZnIcbArLqe3Hibth8XB7pa+nczzNbBijYbYnEipXe0feE70vDimZcraATpCYJXMw:gfnibth83aeQ2EUmr5+tgs
TLSH 27442380E8AC705FF7BEAF4ECD0E6315621FB6B468D2245DE7C70DCE509EA926508B04
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: qualitech-solutions.cam
Sending IP: 111.90.140.145
From: Cathy Dennis <cathydennis@qualitech-solutions.cam>
Subject: RE: CONFIRM QUOTATION
Attachment: QUOTE 5.rar (contains "QUOTE #5.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-05-20 08:36:43 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
15 of 31 (48.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

rar 53bd75e6b7540d1a58ac9facb9e0bab2dd9782dfb53e0b667c5551d964da820c

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments