MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ebae04bbd7d8e6b8f6589a8e95ccd3190ac971e4208f87e3df48b138ab4a434c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ebae04bbd7d8e6b8f6589a8e95ccd3190ac971e4208f87e3df48b138ab4a434c
SHA3-384 hash: 745b60be859114345224fa97e53df8c026056059b83fd6c850e66f14aa71d43f388cf40fe095677e8a69765914847ce9
SHA1 hash: 9e5c6b9490d2674e372ed53d2aef496f962ba069
MD5 hash: a127cf300ffdc98e9aac3d76f5f01765
humanhash: papa-cold-nitrogen-virginia
File name:NEW ORDER_pdf.rar
Download: download sample
Signature Formbook
File size:516'251 bytes
First seen:2021-01-14 06:54:05 UTC
Last seen:2021-01-14 20:40:51 UTC
File type: rar
MIME type:application/x-rar
ssdeep 12288:i9N9Dbg62Ux7M43sOa0wYl+QttSG0tsufEGNxa4nM6tX0xvtyA:q93h2UpM4qw33Av0myxvtr
TLSH 1FB42390ED9F750CE69E9FD93B8B46D40470E82BB376F9870DF09820B214D029DF5669
Reporter abuse_ch
Tags:FormBook rar


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: mail.panjunan.com
Sending IP: 103.31.224.54
From: Yu-Chen Marine Service & Eng. Co., Ltd <apoteker@panjunan.com>
Reply-To: e8120376@ms41.hinet.net <e8120376@ms41.hinet.net>
Subject: ***URGENT***NEW ORDER
Attachment: NEW ORDER_pdf.rar (contains "NEW ORDER_pdf.exe")

Intelligence


File Origin
# of uploads :
3
# of downloads :
97
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-01-14 06:55:06 UTC
AV detection:
17 of 45 (37.78%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar ebae04bbd7d8e6b8f6589a8e95ccd3190ac971e4208f87e3df48b138ab4a434c

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments