MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 923c62e079e90e0394c8d5295a839bb43fc17bff1cc67d963d3abf32c93e4f11. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 923c62e079e90e0394c8d5295a839bb43fc17bff1cc67d963d3abf32c93e4f11
SHA3-384 hash: f535ec82f7d2b61699b4e3dac0f619c833960aec7388c78a63c8130e8e8e36fe17db28c5109793a17fb597d740295e59
SHA1 hash: 9b2f1f51e8231c80d264bf3723ff81e15c8bec6e
MD5 hash: 8e436430a3aa8b5572c77801598a7a22
humanhash: pluto-green-football-cat
File name:8e436430a3aa8b5572c77801598a7a22.exe
Download: download sample
Signature Formbook
File size:334'214 bytes
First seen:2021-02-18 07:21:55 UTC
Last seen:2021-02-18 08:39:23 UTC
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 3072:hN/Cwaxsa7lSW+Fyi2x+ZFSWyoIuVvyhLWdbm1BiRLlSXdciuHYwzLr6Cp37TZBI:hMTgVvyhLW5mjmAtcfpv6uLTZB+oymU
TLSH 2B64076223D57B44D47E5B748020790083F3F5AEE779C64E3DD820DA6B32BC1A6A7792
Reporter abuse_ch
Tags:exe FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
100
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
56 / 100
Signature
.NET source code contains potential unpacker
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-18 07:22:07 UTC
AV detection:
10 of 47 (21.28%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
923c62e079e90e0394c8d5295a839bb43fc17bff1cc67d963d3abf32c93e4f11
MD5 hash:
8e436430a3aa8b5572c77801598a7a22
SHA1 hash:
9b2f1f51e8231c80d264bf3723ff81e15c8bec6e
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Formbook

Executable exe 923c62e079e90e0394c8d5295a839bb43fc17bff1cc67d963d3abf32c93e4f11

(this sample)

  
Delivery method
Distributed via web download

Comments