MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 197b5cc95bf78ab4f7d7894d0937ec17e48b4a131e7e90a11ae2ef6c7eebaa4b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
MassLogger
Vendor detections: 3
| SHA256 hash: | 197b5cc95bf78ab4f7d7894d0937ec17e48b4a131e7e90a11ae2ef6c7eebaa4b |
|---|---|
| SHA3-384 hash: | 20045f7b7820f78afef7e73e90f39546536d58d044a884eb6d041e680f78994699e89694a8eff6ddf6b93035cb9b12ed |
| SHA1 hash: | d560fa95e949e94c301f14d5c514be07433501cf |
| MD5 hash: | 0a85e2d521d3bffed425b9d5c29a42af |
| humanhash: | ink-carolina-island-avocado |
| File name: | Halkbank_Ekstre_20200814_075809_247482.pdf.r00 |
| Download: | download sample |
| Signature | MassLogger |
| File size: | 806'187 bytes |
| First seen: | 2020-08-14 12:18:39 UTC |
| Last seen: | Never |
| File type: | r00 |
| MIME type: | application/x-rar |
| ssdeep | 12288:xLhtuOklZTzK4Tydns+HmwW1/xlQdHnDcfv+RPO79IN2yNDEUxcX+/3LPd9Xy0i:HwOklZDTydnrmFJMDtRPYIMyNvY+znyJ |
| TLSH | 56053324B80ADB8DF52861E6C4796236FD3D5626DFAFBDD940BC54431CEE02620BCB85 |
| Reporter | |
| Tags: | geo Halkbank MassLogger r00 TUR |
abuse_ch
Malspam distributing unidentified malware:HELO: halkbank.com.tr
Sending IP: 156.96.47.16
From: HALKBANK.E-EKSTRE@halkbank.com.tr
Subject: T.HALK BANKASI A.Ş. 08.14.2020 Hesap Ekstresi
Attachment: Halkbank_Ekstre_20200814_075809_247482.pdf.r00 (contains "Halkbank_Ekstre_20200814_075809_247482.pdf.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-08-14 12:20:08 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.