MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0c7f1191eeeccc3fc61d4484e3fc4d76ad10971103c767e68199a14c23509ba0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AZORult
Vendor detections: 5
| SHA256 hash: | 0c7f1191eeeccc3fc61d4484e3fc4d76ad10971103c767e68199a14c23509ba0 |
|---|---|
| SHA3-384 hash: | a9ee6542d4dc2146ead2d4ea64618f88a360842cd27b12bfa9115263204d5a96e25ae82b867316d83eb36d549c149cbf |
| SHA1 hash: | 16e1e2af1764d8cd00ae8720a3c6405edf4eb285 |
| MD5 hash: | 157cc5787b4c8df36786324a6af8ec76 |
| humanhash: | alanine-enemy-low-rugby |
| File name: | e-dekont.html.img |
| Download: | download sample |
| Signature | AZORult |
| File size: | 1'245'184 bytes |
| First seen: | 2021-01-06 16:08:08 UTC |
| Last seen: | Never |
| File type: | img |
| MIME type: | application/x-iso9660-image |
| ssdeep | 6144:m6sQ321i3DxvkrhDdyquS7xY+Ap2x9PPBq:m6sy25Iqh7x7AIx9PJq |
| TLSH | 4345AD13B7884BA1C4AC76B702A1EB022745F5DA33108F5A374F9729A3972C32D6D7B5 |
| Reporter | |
| Tags: | AZORult geo img TUR ZiraatBank |
abuse_ch
Malspam distributing unidentified malware:HELO: trv14.armahostdns.com
Sending IP: 78.135.79.16
From: ZİRAAT BANKASI <ziraatbank@ileti.ziraatbank.com.tr>
Subject: DEKONT
Attachment: e-dekont.html.img (contains "e-dekont.html.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
281
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Woreflint
Status:
Malicious
First seen:
2021-01-06 16:09:04 UTC
AV detection:
13 of 29 (44.83%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Kryptik
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.