MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9e9829ad6570ba7f19654421a74172b2e1c8950092f910f7cee26f47970011cc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 9e9829ad6570ba7f19654421a74172b2e1c8950092f910f7cee26f47970011cc
SHA3-384 hash: cfb7232e2c6479728570d8e8c42225e5eec453e1e90ea4237cfd1166b98bc26d002f290e0607444e3f9bf898e2a0261f
SHA1 hash: 677fdce77f816fa35e73c057bbcf7ab1f0e20994
MD5 hash: 9ef155fc7dc3fc903c46e89b301d9d21
humanhash: gee-enemy-december-foxtrot
File name:MEDUAE670644.ARJ
Download: download sample
Signature Formbook
File size:528'862 bytes
First seen:2022-03-21 07:52:58 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 12288:3iUDi/+B8ywtRBU0tjDWeODeiMcAsTcxlPwCkL/GOdJcmtr:yUYfRBU0tjDJOyiMcAs4Pw5/GOdJfr
TLSH T1E3B4238D5ED58E16B9477C84F9D921B870075A3ED6B28EBBC47EFAB64F480830263C15
Reporter cocaman
Tags:arj FormBook


Avatar
cocaman
Malicious email (T1566.001)
From: ""Dharmendra Kumar Thakur (Delhi-Corp)" <dharmendra.thakur@greenlam.com>" (likely spoofed)
Received: "from greenlam.com (unknown [185.222.58.240]) "
Date: "21 Mar 2022 08:51:53 +0100"
Subject: "Re: SHIPMENT STATUS B/L NO: MEDUAE670644 MELBOURNE TO MALAN PUR (M.P) EPT/21-22/591"
Attachment: "MEDUAE670644.ARJ"

Intelligence


File Origin
# of uploads :
1
# of downloads :
139
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
control.exe obfuscated packed replace.exe update.exe
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.Tnega
Status:
Malicious
First seen:
2022-03-21 03:25:03 UTC
File Type:
Binary (Archive)
Extracted files:
22
AV detection:
20 of 27 (74.07%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

arj 9e9829ad6570ba7f19654421a74172b2e1c8950092f910f7cee26f47970011cc

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
Formbook

Comments