MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 afa64e8c95683206e3954c9ab341920dfdc73d8f04ccf7c4775b7142560ca04c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: afa64e8c95683206e3954c9ab341920dfdc73d8f04ccf7c4775b7142560ca04c
SHA3-384 hash: 066147508d44e85c07b58c625490ffe7c48b80170d44d3286a510673dd8f47948fb8a50584d5bd0dd4bfa7c7456f0a96
SHA1 hash: f82f18609e82034bafb2b2dca6e5b7e7ccbfb07f
MD5 hash: f7c8a659dd4cba6efd734d0fbb8f4740
humanhash: alanine-sodium-kitten-oven
File name:PO456789.rar
Download: download sample
Signature Formbook
File size:441'718 bytes
First seen:2020-06-04 06:21:40 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:XN7hp/ME1BXpURph6dB/TgqLyNRAERYvfrhw4:9lpUE1BXpURph2B7fLHERorhF
TLSH E9942302115011FC3A0EE77CBC1B057C07F26AF8EF86199E2E47B8E526670A76AF7125
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: de189-2.webuphosting.com
Sending IP: 167.86.86.214
From: sales02@inelecsytem.com
Subject: Order from Ningbo Merchandise Co
Attachment: PO456789.rar (contains "FJ3o2SCI2GTBBa1.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-06-04 06:37:51 UTC
AV detection:
15 of 48 (31.25%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar afa64e8c95683206e3954c9ab341920dfdc73d8f04ccf7c4775b7142560ca04c

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments