MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 724a585829d9c3fbcae767e43097a6d789073b5f32c0203db562a6560cfde5bd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 724a585829d9c3fbcae767e43097a6d789073b5f32c0203db562a6560cfde5bd
SHA3-384 hash: 8de7d372283818dc93f835219f9c4c62e43788f20772e0dcfcd97738b9051895688f27bbede8c820aaf24bf89ad56932
SHA1 hash: c858aef64d5bbe74b40e96571df3424599b33276
MD5 hash: 8d27151f80468b74c84eb42ba9fb137c
humanhash: virginia-leopard-angel-missouri
File name:invoice08312020 2.zip
Download: download sample
Signature Formbook
File size:681'228 bytes
First seen:2020-09-01 04:49:49 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:PqVNfPWYKfaTV3A/9fX9AFN+VOJcN+uVISlsyL4JLcub8AP:PqVNm/aa/9ftAb+EJI+kayL4JLTYe
TLSH 64E4235610D5C43C34A9271A71DDA7992BBBE4AE6FE0D030084ED1B3165DCB4FEA5B38
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: alnassar.com.sa
Sending IP: 162.244.93.110
From: Omnimetric Technologies Pte Ltd <sales@omnimetric.com.sg>
Reply-To: sales@omnimetric.com.sg
Subject: invoice#08312020
Attachment: invoice08312020 2.zip (contains "invoice#08312020 (2).exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
157
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-31 03:32:18 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 724a585829d9c3fbcae767e43097a6d789073b5f32c0203db562a6560cfde5bd

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments