MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc475778d5805e14f9e10162c0dbf361dc079710c2872bb4cef78f66a616f122. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dc475778d5805e14f9e10162c0dbf361dc079710c2872bb4cef78f66a616f122
SHA3-384 hash: ce8cf3809c18151963cafbce0876808e3546da4ab8dabd3c24dca0514bcbb82e0988734df508815ecd3aedd4cd367ba7
SHA1 hash: bf49baa38573d5f8c12b7054d733231a3c9d9868
MD5 hash: 6c9124e31556983da0b5489ce2a25b48
humanhash: papa-west-massachusetts-princess
File name:Halkbank_Ekstre_20200521_082357_541079 4.r00
Download: download sample
Signature MassLogger
File size:951'175 bytes
First seen:2020-10-23 09:31:58 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 24576:wn98WsYHdE058BImSKwBrmMztUB/FJGy5AU3JXtMbI:w209E0+BImSzBrNtUVFJZAwXj
TLSH 21153310218B0B6DB60BAF9B997F8A842DC52F8547ED15F037F0E485F754826E2B18BD
Reporter abuse_ch
Tags:geo Halkbank MassLogger r00 TUR


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: oksygen.com.tr
Sending IP: 37.49.225.101
From: HALKBANK.E-EKSTRE-halkbank.com.tr <muhasebe@oksygen.com.tr>
Subject: T.HALK BANKASI A.S. 01.01.2019 - 22.10.2020 Hesap Ekstresi
Attachment: Halkbank_Ekstre_20200521_082357_541079 4.r00 (contains "Halkbank_Ekstre_20200521_082357_541079.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
105
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-10-23 08:54:32 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

r00 dc475778d5805e14f9e10162c0dbf361dc079710c2872bb4cef78f66a616f122

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments