MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 9e9829ad6570ba7f19654421a74172b2e1c8950092f910f7cee26f47970011cc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 5
| SHA256 hash: | 9e9829ad6570ba7f19654421a74172b2e1c8950092f910f7cee26f47970011cc |
|---|---|
| SHA3-384 hash: | cfb7232e2c6479728570d8e8c42225e5eec453e1e90ea4237cfd1166b98bc26d002f290e0607444e3f9bf898e2a0261f |
| SHA1 hash: | 677fdce77f816fa35e73c057bbcf7ab1f0e20994 |
| MD5 hash: | 9ef155fc7dc3fc903c46e89b301d9d21 |
| humanhash: | gee-enemy-december-foxtrot |
| File name: | MEDUAE670644.ARJ |
| Download: | download sample |
| Signature | Formbook |
| File size: | 528'862 bytes |
| First seen: | 2022-03-21 07:52:58 UTC |
| Last seen: | Never |
| File type: | arj |
| MIME type: | application/x-rar |
| ssdeep | 12288:3iUDi/+B8ywtRBU0tjDWeODeiMcAsTcxlPwCkL/GOdJcmtr:yUYfRBU0tjDJOyiMcAs4Pw5/GOdJfr |
| TLSH | T1E3B4238D5ED58E16B9477C84F9D921B870075A3ED6B28EBBC47EFAB64F480830263C15 |
| Reporter | |
| Tags: | arj FormBook |
cocaman
Malicious email (T1566.001)From: ""Dharmendra Kumar Thakur (Delhi-Corp)" <dharmendra.thakur@greenlam.com>" (likely spoofed)
Received: "from greenlam.com (unknown [185.222.58.240]) "
Date: "21 Mar 2022 08:51:53 +0100"
Subject: "Re: SHIPMENT STATUS B/L NO: MEDUAE670644 MELBOURNE TO MALAN PUR (M.P) EPT/21-22/591"
Attachment: "MEDUAE670644.ARJ"
Intelligence
File Origin
# of uploads :
1
# of downloads :
139
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
7.5/10
Confidence:
100%
Tags:
control.exe obfuscated packed replace.exe update.exe
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.Tnega
Status:
Malicious
First seen:
2022-03-21 03:25:03 UTC
File Type:
Binary (Archive)
Extracted files:
22
AV detection:
20 of 27 (74.07%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.35
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Dropping
Formbook
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.