Source: Ziraat Bankas#U0131 Swift Mesaji2.docx.doc |
Virustotal: Detection: 9% |
Perma Link |
Source: Ziraat Bankas#U0131 Swift Mesaji2.docx.doc |
ReversingLabs: Detection: 13% |
Source: classification engine |
Classification label: mal52.evad.winDOC@0/0@0/0 |
Source: Ziraat Bankas#U0131 Swift Mesaji2.docx.doc |
OLE indicator, Word Document stream: true |
Source: Ziraat Bankas#U0131 Swift Mesaji2.docx.doc |
OLE indicator, Word Document stream: true |
Source: Ziraat Bankas#U0131 Swift Mesaji2.docx.doc |
OLE document summary: title field not present or empty |
Source: Ziraat Bankas#U0131 Swift Mesaji2.docx.doc |
OLE document summary: title field not present or empty |
Source: Ziraat Bankas#U0131 Swift Mesaji2.docx.doc |
Virustotal: Detection: 9% |
Source: Ziraat Bankas#U0131 Swift Mesaji2.docx.doc |
ReversingLabs: Detection: 13% |
Source: Ziraat Bankas#U0131 Swift Mesaji2.docx.doc |
Initial sample: OLE zip file path = word/embeddings/oleObject2.bin |
Source: Ziraat Bankas#U0131 Swift Mesaji2.docx.doc |
Initial sample: OLE zip file path = word/media/image2.emf |
Source: Ziraat Bankas#U0131 Swift Mesaji2.docx.doc |
Initial sample: OLE zip file path = word/_rels/settings.xml.rels |
Source: Ziraat Bankas#U0131 Swift Mesaji2.docx.doc |
Initial sample: OLE indicators vbamacros = False |
Source: settings.xml.rels |
Extracted files from sample: http://wheel.to/sewtek |
Source: Ziraat Bankas#U0131 Swift Mesaji2.docx.doc |
Stream path 'CONTENTS' entropy: 7.91669502048 (max. 8.0) |
Source: Ziraat Bankas#U0131 Swift Mesaji2.docx.doc |
Stream path 'CONTENTS' entropy: 7.91598386737 (max. 8.0) |