MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ab12101dc8596903186c9246dd2ed6306ee61c611a51b20ae7aa673e7824af5b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: ab12101dc8596903186c9246dd2ed6306ee61c611a51b20ae7aa673e7824af5b
SHA3-384 hash: 2147a08f4cb32108cba0506ed6c4015bffa797d8f03a0407f8332feb10bc85fe47225ae79a5eac3cf0c6d45d90e9e7b6
SHA1 hash: aebe1e71805a61fc984f98800e056a27d9391c4d
MD5 hash: 40ae5dc390d7640f1f9ab44422411ab4
humanhash: freddie-quebec-apart-romeo
File name:Agolives.zip
Download: download sample
Signature Formbook
File size:647'412 bytes
First seen:2020-10-26 14:51:23 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:T3yN9WPwijjN8N5eZXNaqWkOO3YGmNrO4zXi1hv0TKb3W52gtcd99YrvxZCn9x:zyNUPKN52D/YGmdOoi1hS7Fg9kZC9x
TLSH D6D423B3BD3D38AD762E807BE941076283A628717C6809F6734C6CB9476D7C1B0B7652
Reporter abuse_ch
Tags:ESP FormBook geo Hostwinds zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: client-108-174-203-66.hostwindsdns.com
Sending IP: 108.174.203.66
From: eduardo camacho <info@agolives.com>
Reply-To: engineering@engineer.com
Subject: Agolives / Solicitud de presupuesto
Attachment: Agolives.zip (contains "Agolives.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip ab12101dc8596903186c9246dd2ed6306ee61c611a51b20ae7aa673e7824af5b

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments