MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c2d6e5914eb812ee96b4996392e03707376d069c96573104cf5b64e6b1ef7f69. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c2d6e5914eb812ee96b4996392e03707376d069c96573104cf5b64e6b1ef7f69
SHA3-384 hash: 5fa58658c4e6ba9791277d12ce3518dc05fdf513120fca54d04a0924fce9eae16cd8c08f3bc353300abeea5f53f7e2b8
SHA1 hash: 611f0de314e7a0535f827b43a030889a8a05a5f7
MD5 hash: 8537bd6ea074695ff2b95d7b2e38ab63
humanhash: jig-nevada-don-hot
File name:PO_2536478233.pdf.img
Download: download sample
Signature Formbook
File size:1'572'864 bytes
First seen:2021-03-16 10:23:05 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:I+9VKqcBR6ajPaQBmQKqWlzyuQxzquJDQ:IcVKqO6yyQefXNuJDQ
TLSH 5675F0212688FE51F0BDDB7C046115C017F7AC06EE26FACA7F9933D91A72681467A633
Reporter abuse_ch
Tags:FormBook img


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: tenda.cn
Sending IP: 58.250.161.62
From: marketing@tenda.cn <marketing@tenda.cn>
Subject: PR/PEE/RFQ0001140/2021
Attachment: PO_2536478233.pdf.img (contains "Quotation_2536478234.pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
119
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-03-16 03:51:06 UTC
AV detection:
20 of 47 (42.55%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

img c2d6e5914eb812ee96b4996392e03707376d069c96573104cf5b64e6b1ef7f69

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments