MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 197b5cc95bf78ab4f7d7894d0937ec17e48b4a131e7e90a11ae2ef6c7eebaa4b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 197b5cc95bf78ab4f7d7894d0937ec17e48b4a131e7e90a11ae2ef6c7eebaa4b
SHA3-384 hash: 20045f7b7820f78afef7e73e90f39546536d58d044a884eb6d041e680f78994699e89694a8eff6ddf6b93035cb9b12ed
SHA1 hash: d560fa95e949e94c301f14d5c514be07433501cf
MD5 hash: 0a85e2d521d3bffed425b9d5c29a42af
humanhash: ink-carolina-island-avocado
File name:Halkbank_Ekstre_20200814_075809_247482.pdf.r00
Download: download sample
Signature MassLogger
File size:806'187 bytes
First seen:2020-08-14 12:18:39 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 12288:xLhtuOklZTzK4Tydns+HmwW1/xlQdHnDcfv+RPO79IN2yNDEUxcX+/3LPd9Xy0i:HwOklZDTydnrmFJMDtRPYIMyNvY+znyJ
TLSH 56053324B80ADB8DF52861E6C4796236FD3D5626DFAFBDD940BC54431CEE02620BCB85
Reporter abuse_ch
Tags:geo Halkbank MassLogger r00 TUR


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: halkbank.com.tr
Sending IP: 156.96.47.16
From: HALKBANK.E-EKSTRE@halkbank.com.tr
Subject: T.HALK BANKASI A.Ş. 08.14.2020 Hesap Ekstresi
Attachment: Halkbank_Ekstre_20200814_075809_247482.pdf.r00 (contains "Halkbank_Ekstre_20200814_075809_247482.pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-08-14 12:20:08 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

r00 197b5cc95bf78ab4f7d7894d0937ec17e48b4a131e7e90a11ae2ef6c7eebaa4b

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments