MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 ebae04bbd7d8e6b8f6589a8e95ccd3190ac971e4208f87e3df48b138ab4a434c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Formbook
Vendor detections: 3
| SHA256 hash: | ebae04bbd7d8e6b8f6589a8e95ccd3190ac971e4208f87e3df48b138ab4a434c |
|---|---|
| SHA3-384 hash: | 745b60be859114345224fa97e53df8c026056059b83fd6c850e66f14aa71d43f388cf40fe095677e8a69765914847ce9 |
| SHA1 hash: | 9e5c6b9490d2674e372ed53d2aef496f962ba069 |
| MD5 hash: | a127cf300ffdc98e9aac3d76f5f01765 |
| humanhash: | papa-cold-nitrogen-virginia |
| File name: | NEW ORDER_pdf.rar |
| Download: | download sample |
| Signature | Formbook |
| File size: | 516'251 bytes |
| First seen: | 2021-01-14 06:54:05 UTC |
| Last seen: | 2021-01-14 20:40:51 UTC |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 12288:i9N9Dbg62Ux7M43sOa0wYl+QttSG0tsufEGNxa4nM6tX0xvtyA:q93h2UpM4qw33Av0myxvtr |
| TLSH | 1FB42390ED9F750CE69E9FD93B8B46D40470E82BB376F9870DF09820B214D029DF5669 |
| Reporter | |
| Tags: | FormBook rar |
abuse_ch
Malspam distributing Formbook:HELO: mail.panjunan.com
Sending IP: 103.31.224.54
From: Yu-Chen Marine Service & Eng. Co., Ltd <apoteker@panjunan.com>
Reply-To: e8120376@ms41.hinet.net <e8120376@ms41.hinet.net>
Subject: ***URGENT***NEW ORDER
Attachment: NEW ORDER_pdf.rar (contains "NEW ORDER_pdf.exe")
Intelligence
File Origin
# of uploads :
3
# of downloads :
97
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-01-14 06:55:06 UTC
AV detection:
17 of 45 (37.78%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Formbook
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.