MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2a8545d3fd1bd5a35b19a76c3e6e454623bac3893cf1bbcc8bd950ca627db1e8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 2a8545d3fd1bd5a35b19a76c3e6e454623bac3893cf1bbcc8bd950ca627db1e8
SHA3-384 hash: fbcf7c5a54f919057c39d9ac2991b10a1904ea58b509c053100515c6a34015941100486909ca3913d34b9551c29c7474
SHA1 hash: ddac989fe039d7166bc6c8657d1d559cf3f6ce2d
MD5 hash: 6fca01996fd401874ec31c38041b5099
humanhash: oven-ten-jersey-missouri
File name:TPN Letter of Demand. Client Request.PDF.gz
Download: download sample
Signature MassLogger
File size:590'810 bytes
First seen:2020-08-07 13:28:06 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:DUIM2NGEOSKclHYMt8PEGSPlzSD67e1ncCDESFtyiYl:QIM2NNOBO4M8IssCDRIiYl
TLSH 9FC4336BDFD15B18352E9B1E04DFAEC7A3224F2AD78DAAA6E3C514F015230D112C72D9
Reporter abuse_ch
Tags:gz MassLogger


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: host.qualifairs.com
Sending IP: 85.25.130.41
From: collection@tpn.co.za
Subject: [TPN] Letter of Demand
Attachment: TPN Letter of Demand. Client Request.PDF.gz (contains "TPN Letter of Demand. Client Request.PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2020-08-07 13:30:07 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

gz 2a8545d3fd1bd5a35b19a76c3e6e454623bac3893cf1bbcc8bd950ca627db1e8

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments