MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 724a585829d9c3fbcae767e43097a6d789073b5f32c0203db562a6560cfde5bd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 4
| SHA256 hash: | 724a585829d9c3fbcae767e43097a6d789073b5f32c0203db562a6560cfde5bd |
|---|---|
| SHA3-384 hash: | 8de7d372283818dc93f835219f9c4c62e43788f20772e0dcfcd97738b9051895688f27bbede8c820aaf24bf89ad56932 |
| SHA1 hash: | c858aef64d5bbe74b40e96571df3424599b33276 |
| MD5 hash: | 8d27151f80468b74c84eb42ba9fb137c |
| humanhash: | virginia-leopard-angel-missouri |
| File name: | invoice08312020 2.zip |
| Download: | download sample |
| Signature | Formbook |
| File size: | 681'228 bytes |
| First seen: | 2020-09-01 04:49:49 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:PqVNfPWYKfaTV3A/9fX9AFN+VOJcN+uVISlsyL4JLcub8AP:PqVNm/aa/9ftAb+EJI+kayL4JLTYe |
| TLSH | 64E4235610D5C43C34A9271A71DDA7992BBBE4AE6FE0D030084ED1B3165DCB4FEA5B38 |
| Reporter | |
| Tags: | FormBook zip |
abuse_ch
Malspam distributing unidentified malware:HELO: alnassar.com.sa
Sending IP: 162.244.93.110
From: Omnimetric Technologies Pte Ltd <sales@omnimetric.com.sg>
Reply-To: sales@omnimetric.com.sg
Subject: invoice#08312020
Attachment: invoice08312020 2.zip (contains "invoice#08312020 (2).exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
157
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-31 03:32:18 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Kryptik
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.