MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cb2f844ee0bb5f94d9d7c80798d39a4a551f39c4d52d76e3965d8c10ef5e5285. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: cb2f844ee0bb5f94d9d7c80798d39a4a551f39c4d52d76e3965d8c10ef5e5285
SHA3-384 hash: 07fc6b8750f198ed142cae232049954d4ae462eef77f5ad9c96ac437550f9e05e6a90c4d2b23911a85a008d960a852e0
SHA1 hash: 986d23975efccd5cdfec162fb41918ee7e5638fa
MD5 hash: 4c4c029c37255c4de58e4ee6182c5204
humanhash: sad-harry-ten-delaware
File name:Factura de clients_0010002345.rar
Download: download sample
Signature Formbook
File size:452'450 bytes
First seen:2020-10-16 10:23:20 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:KhHwhvB0mly9qCFWroWtoLvdGF8j3CAyJWx:oH6Dly0CFWroA6GaaWx
TLSH B8A42347126889AFB197817848DAC33FECCADC95B9F81CAE7C8A35950A54D1FC9CE530
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: anacastillo.pw
Sending IP: 138.68.104.87
From: Administracion <info@anacastillo.pw>
Reply-To: duldi@duldi.com
Subject: Factura de Clients
Attachment: Factura de clients_0010002345.rar (contains "Factura de clients_0010002345.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-10-15 17:35:58 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip cb2f844ee0bb5f94d9d7c80798d39a4a551f39c4d52d76e3965d8c10ef5e5285

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments