MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dae9b428901d8df2061e5a8128667549c9939785857aff255f3c5ab11812bdc8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: dae9b428901d8df2061e5a8128667549c9939785857aff255f3c5ab11812bdc8
SHA3-384 hash: b8eb322fbfe1d9f01e7d2c8ee9c13b075868548795737e8721912a3999060aa959bd2379b485402dbd3f3646bb60088d
SHA1 hash: 643f5be2a6a2cd34f93a3a01c30d9d1c1c2feb99
MD5 hash: a510a979ced0bc601f68ceaf7903dcfa
humanhash: high-pluto-july-winter
File name:PO#PCL2003827677#Invoice.r00
Download: download sample
Signature Formbook
File size:906'117 bytes
First seen:2022-04-12 14:32:21 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 24576:MJZVnndHUsEXEfbvc4omAIvAuJRHSXdL6:sZVnnxvEUfymAIvxsF6
TLSH T1511533EE461FC87E087C0CC52EA0663562146E0A69346B279C791DF1E7DF6713A0F9E8
Reporter cocaman
Tags:DHL FormBook INVOICE r00 Shipping


Avatar
cocaman
Malicious email (T1566.001)
From: "Lucy Zhu (DHL CN), external <osha.isc18@dhl.com>" (likely spoofed)
Received: "from dhl.com (unknown [185.222.57.75]) "
Date: "12 Apr 2022 15:02:20 +0200"
Subject: "RE: JPAR363 BOOKING PO#PCL2003827677 Shipping Order Num#202037392248"
Attachment: "PO#PCL2003827677#Invoice.r00"

Intelligence


File Origin
# of uploads :
1
# of downloads :
236
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2022-04-12 11:39:20 UTC
File Type:
Binary (Archive)
Extracted files:
81
AV detection:
18 of 41 (43.90%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

r00 dae9b428901d8df2061e5a8128667549c9939785857aff255f3c5ab11812bdc8

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments