General

  • Target

    Ziraat Bankasi Swift Mesaji.exe

  • Size

    853KB

  • MD5

    57dbc2be60ede5140738c720a629781c

  • SHA1

    b348e314c3f9be312725b23a0fecf491404caf66

  • SHA256

    c7a6d57fc3d397c2b303477d8e1d4fea64fec51f46b0ddfad97a11527771702c

  • SHA512

    8932c191f72eb089d346848164c36104e6114e39cdeed19d1e67a7546ce68f01d8fdadec2c6f9ce5a80915e5781631fd37018f9e57c3a1d54d677f2e9c6ae006

  • SSDEEP

    24576:N3mYVFbTdL3LgGStF2C/GVOoD5jQZj7/MJhmO:N3mYV9x3SH2C/EOEm7lO

Score
3/10

Malware Config

Signatures

  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • Ziraat Bankasi Swift Mesaji.exe
    .exe windows:4 windows x86 arch:x86

    6e7f9a29f2c85394521a08b9f31f6275


    Code Sign

    Headers

    Imports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:4 windows x86 arch:x86

    fc0224e99e736751432961db63a41b76


    Headers

    Imports

    Exports

    Sections

  • Meningsforskellens/Soullessness16.sek
  • Meningsforskellens/flunkies.spi
  • Nicaean/Gangbrdderne86.doc
  • Nicaean/Malingering.har
  • Unabstemiously.Cep
  • polygonies.afs
  • sanktionere.txt