MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 05b37fed91a4de9d7442349ccd379719c3b9dd9b220d28b702adfb25f05d010c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 05b37fed91a4de9d7442349ccd379719c3b9dd9b220d28b702adfb25f05d010c
SHA3-384 hash: 63ae0437777384589d031a5ead27259089739366e4efa34e9af6fa4e388fb93322cc6fa79fcb0a465ec27b6afdf05917
SHA1 hash: 01a386556ad98eff5ed212fae02f7d3cdf601113
MD5 hash: 443e88cebec0121202f20edf999ef955
humanhash: gee-vegan-mirror-speaker
File name:scan00465.pdf.zip
Download: download sample
Signature MassLogger
File size:926'242 bytes
First seen:2020-06-09 06:03:21 UTC
Last seen:2020-06-09 13:04:03 UTC
File type: zip
MIME type:application/zip
ssdeep 24576:5nJhc0MRDcAGvWWjCVmVKeU87h4oTcEYYwJAI0OIADH4uOa:5JhckNjRKEhPEFJAh3a
TLSH 39153347E9784F97447A40D2D86719A5B4CA6052AC4C69A3D5CD3FFAB2BF0783232F09
Reporter abuse_ch
Tags:MassLogger zip


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: dayacom.com.tw
Sending IP: 156.96.62.53
From: (Ms) ivy leung <sales@dayacom.com.tw>
Reply-To: (Ms) ivy leung <saIes@dayacom.com.tw>
Subject: revised product enquiry, sample request
Attachment: scan00465.pdf.zip (contains "scan00465.pdf.exe")

MassLogger SMTP exfil server:
mail.saritatravels.com:587

Intelligence


File Origin
# of uploads :
3
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-09 00:17:55 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 05b37fed91a4de9d7442349ccd379719c3b9dd9b220d28b702adfb25f05d010c

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments