MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8537dc2194884b6ec88e9bc44963b4b1dc34b28505fd20330f5ed137e63cafe6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8537dc2194884b6ec88e9bc44963b4b1dc34b28505fd20330f5ed137e63cafe6
SHA3-384 hash: f9c59cac4ff286d56a4621d30aa7d2210b79e4930b427b419675b8d3d054e6a67f7e0d90a5490b0d3e17b72fdf0b1d12
SHA1 hash: 8c3c3af0cbfc1e6e3c0d6c10229a817103d75069
MD5 hash: 40237d6a3c84f02516bda17f8b957322
humanhash: lamp-early-don-ceiling
File name:sample.rar
Download: download sample
Signature Formbook
File size:446'897 bytes
First seen:2020-09-14 19:02:25 UTC
Last seen:2020-09-14 21:02:19 UTC
File type: rar
MIME type:application/x-rar
ssdeep 6144:zxDkckbuLHbc3ybjGvGjE7LBZGXAztMt2HYo5FbZk22BtKj5LognzL9NJ2o:zqckbC7uye6hA6YHYadZXwwVognzLAo
TLSH 0D9423C2CBDAD489967783CBF0BF4C1DA453DA1A700735F8853D427202D85F285FA69A
Reporter GovCERT_CH
Tags:FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
138
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Agensla
Status:
Malicious
First seen:
2020-09-14 13:58:51 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar 8537dc2194884b6ec88e9bc44963b4b1dc34b28505fd20330f5ed137e63cafe6

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments