MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c2d6e5914eb812ee96b4996392e03707376d069c96573104cf5b64e6b1ef7f69. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 4
| SHA256 hash: | c2d6e5914eb812ee96b4996392e03707376d069c96573104cf5b64e6b1ef7f69 |
|---|---|
| SHA3-384 hash: | 5fa58658c4e6ba9791277d12ce3518dc05fdf513120fca54d04a0924fce9eae16cd8c08f3bc353300abeea5f53f7e2b8 |
| SHA1 hash: | 611f0de314e7a0535f827b43a030889a8a05a5f7 |
| MD5 hash: | 8537bd6ea074695ff2b95d7b2e38ab63 |
| humanhash: | jig-nevada-don-hot |
| File name: | PO_2536478233.pdf.img |
| Download: | download sample |
| Signature | Formbook |
| File size: | 1'572'864 bytes |
| First seen: | 2021-03-16 10:23:05 UTC |
| Last seen: | Never |
| File type: | img |
| MIME type: | application/x-iso9660-image |
| ssdeep | 24576:I+9VKqcBR6ajPaQBmQKqWlzyuQxzquJDQ:IcVKqO6yyQefXNuJDQ |
| TLSH | 5675F0212688FE51F0BDDB7C046115C017F7AC06EE26FACA7F9933D91A72681467A633 |
| Reporter | |
| Tags: | FormBook img |
abuse_ch
Malspam distributing unidentified malware:HELO: tenda.cn
Sending IP: 58.250.161.62
From: marketing@tenda.cn <marketing@tenda.cn>
Subject: PR/PEE/RFQ0001140/2021
Attachment: PO_2536478233.pdf.img (contains "Quotation_2536478234.pdf.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
119
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-03-16 03:51:06 UTC
AV detection:
20 of 47 (42.55%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.45
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.