MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 302afd42a5cbeef7d6709bdd6a82f7ccb04403c06ac99af026909126733d5e90. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 302afd42a5cbeef7d6709bdd6a82f7ccb04403c06ac99af026909126733d5e90
SHA3-384 hash: 0437a0c463e5d142e37cf7efc2faede8051b71ad36688d537f111e444681ec44e7915ceae0c430844ded8ca483782b62
SHA1 hash: 80a2f1d4a305fcb5312ee742cd847be532948349
MD5 hash: 9bb0e81e2fd49906653b9b696c6c6161
humanhash: spring-diet-zebra-maine
File name:IDBI BANK JUNE 2020 Statement.CAB
Download: download sample
Signature MassLogger
File size:1'332'909 bytes
First seen:2020-06-08 08:39:56 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:0uxV1LWKktiDoqeujAxWHIgamHH3t5Nl2/Ak313z003Up0/iWjqdc1Era/6Jkc+:3VLzktisq+xWHIgz3tvwJ1jJpKWjiran
TLSH 14553354953AE069150E03E990C48D97259E62EF791C0FCDEFD8EE0E57BA80213E936F
Reporter abuse_ch
Tags:cab MassLogger


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: cloudhost-67388.au-south-1.nxcli.net
Sending IP: 103.224.90.42
From: IDBI Bank <neft@idbi.com>
Subject: IDBI BANK JUNE 2020 Account Statement
Attachment: IDBI BANK JUNE 2020 Statement.CAB (contains "IDBI BANK JUNE 2020 Statement.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-08 08:41:06 UTC
AV detection:
18 of 45 (40.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 302afd42a5cbeef7d6709bdd6a82f7ccb04403c06ac99af026909126733d5e90

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments