MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 654d76821228c87040fbe0a9805d5e67d8dd0528561876b6090d3fb32786b6ad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 654d76821228c87040fbe0a9805d5e67d8dd0528561876b6090d3fb32786b6ad
SHA3-384 hash: eb87322ed5f8fc12affa16e1d1389a5abbdfd8b892e65ec28015c133f4e3a38a3cc110d2c717ee378906b8a8c262d54d
SHA1 hash: c11655ca3679c2f0f06297e972f16a82e29fcf5d
MD5 hash: b74014ee03dc8afb8a97051f66ed0e04
humanhash: hot-black-oranges-delta
File name:5630098XX.rar
Download: download sample
Signature Formbook
File size:1'036'521 bytes
First seen:2021-01-19 13:00:41 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:FOfUwjhD0FkDuD5sjxHTdzT/doqOB8VHw:YMRFkeAdTVdfOB8O
TLSH 6E25331224A7900851EC4E0D3D2B9B6258235D10BF65F316BBE7EF9986E8B52F7250CF
Reporter abuse_ch
Tags:FormBook rar Yahoo


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: sonic304-20.consmr.mail.sg3.yahoo.com
Sending IP: 106.10.242.210
From: sale panle <s_panle@yahoo.com>
Subject: : Fwd: Wire Transfer Payment
Attachment: 5630098XX.rar (contains "dGWioTejLEz0eVM.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
140
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-01-19 13:01:13 UTC
AV detection:
15 of 46 (32.61%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar 654d76821228c87040fbe0a9805d5e67d8dd0528561876b6090d3fb32786b6ad

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments