MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0c7f1191eeeccc3fc61d4484e3fc4d76ad10971103c767e68199a14c23509ba0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 0c7f1191eeeccc3fc61d4484e3fc4d76ad10971103c767e68199a14c23509ba0
SHA3-384 hash: a9ee6542d4dc2146ead2d4ea64618f88a360842cd27b12bfa9115263204d5a96e25ae82b867316d83eb36d549c149cbf
SHA1 hash: 16e1e2af1764d8cd00ae8720a3c6405edf4eb285
MD5 hash: 157cc5787b4c8df36786324a6af8ec76
humanhash: alanine-enemy-low-rugby
File name:e-dekont.html.img
Download: download sample
Signature AZORult
File size:1'245'184 bytes
First seen:2021-01-06 16:08:08 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:m6sQ321i3DxvkrhDdyquS7xY+Ap2x9PPBq:m6sy25Iqh7x7AIx9PJq
TLSH 4345AD13B7884BA1C4AC76B702A1EB022745F5DA33108F5A374F9729A3972C32D6D7B5
Reporter abuse_ch
Tags:AZORult geo img TUR ZiraatBank


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: trv14.armahostdns.com
Sending IP: 78.135.79.16
From: ZİRAAT BANKASI <ziraatbank@ileti.ziraatbank.com.tr>
Subject: DEKONT
Attachment: e-dekont.html.img (contains "e-dekont.html.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
281
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Woreflint
Status:
Malicious
First seen:
2021-01-06 16:09:04 UTC
AV detection:
13 of 29 (44.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AZORult

img 0c7f1191eeeccc3fc61d4484e3fc4d76ad10971103c767e68199a14c23509ba0

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments