MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 33581dc85054ce94427c974e3fc3131655ed0dc297949126e8ecbef1a90ce5ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 33581dc85054ce94427c974e3fc3131655ed0dc297949126e8ecbef1a90ce5ba
SHA3-384 hash: 42c95a19940c54b674119afb6887bd7c2e7a258f923a7440079ea8f04c2abc59a9468c80b859c1cd6fee924ca3771c76
SHA1 hash: 10339a22eb952e956451aea7f453f54d03d66beb
MD5 hash: e9d88bb417c91d2d75bcbf4c24d9f1d0
humanhash: timing-california-seventeen-pluto
File name:Airline invoice details.xz
Download: download sample
Signature MassLogger
File size:877'691 bytes
First seen:2020-08-08 08:20:05 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:CyjeBYXJt6wzSgzZgnIXoExndN964ztapkqmUGxBb:CY6sJAwnNTYERdfHpt
TLSH DF15339E306BC5928485F1024B641F49D663307ED2D69B43F0E2B6986E364B42BEC6FD
Reporter abuse_ch
Tags:DHL MassLogger xz


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: m.hostcho.com
Sending IP: 138.201.145.72
From: Anastacia Petrov <rimantas@brigantina.lt>
Subject: DHL Customer Information Form
Attachment: Airline invoice details.xz (contains "Airline invoice details.bat")

MassLogger SMTP exfil server:
mail.sbrenind.com:26

Intelligence


File Origin
# of uploads :
1
# of downloads :
94
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-08 08:21:07 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 33581dc85054ce94427c974e3fc3131655ed0dc297949126e8ecbef1a90ce5ba

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments