MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7b36a6deba614caf421f5041d0dcace5ac72eb41ec9efce8102cd9aa0e4539a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b7b36a6deba614caf421f5041d0dcace5ac72eb41ec9efce8102cd9aa0e4539a
SHA3-384 hash: f226d8618d8347737770ded157f56ac1b65da4d02720e824c010beb04966cd434cfdbb6367e4da88ef14aa71b8e8e8cf
SHA1 hash: 7d217e017af3ef7cf37f76f71df7f32cc52f23e8
MD5 hash: b86091cc5af09a01707e3815f9f38429
humanhash: mockingbird-december-washington-happy
File name:payment advice002436_pdf.arj
Download: download sample
Signature Formbook
File size:664'508 bytes
First seen:2021-01-15 07:09:52 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 12288:Yw6vPLiPNZPpXiYMWdyks74cYbx9deV7/xOdI6l9y1hyZBeMcwPb1:J6GPXPpXi/Wzs74cYbx4p8nY+BttP5
TLSH 92E43338DEAE43A1339B1961571E4192C062F17E2AF8F1DD52E332DB227248C9E5562F
Reporter abuse_ch
Tags:arj FormBook


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: ts20.progressiveline.com
Sending IP: 149.56.84.229
From: Bank of Hope <tkt@heung-a.com.cn>
Reply-To: kyunghwa.park@bankofhope.com
Subject: Advice from Bank of Hope
Attachment: payment advice002436_pdf.arj (contains "payment advice002436_pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
153
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-01-15 04:18:07 UTC
AV detection:
14 of 46 (30.43%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

arj b7b36a6deba614caf421f5041d0dcace5ac72eb41ec9efce8102cd9aa0e4539a

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments