MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3a56dc8f555f5089342a75860f3cf5196c9ce7c3b9ccf99542f89d5d9085f928. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3a56dc8f555f5089342a75860f3cf5196c9ce7c3b9ccf99542f89d5d9085f928
SHA3-384 hash: 90a4c3b05d37bd2245bcd426cef7f3305a04ad98316bc5c1f7f768ea89feb8fce512f04a5018764bf521b914732e4595
SHA1 hash: 278b5c52b89ca572c4b7f64b417d9372b59cf017
MD5 hash: b48f898ee5b851e5825d0400a7a5f764
humanhash: vermont-delta-sodium-sad
File name:RFQ.gz
Download: download sample
Signature MassLogger
File size:945'668 bytes
First seen:2020-06-09 05:48:38 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 24576:sNo9zJSB/bDD/geFc0CqgiR/c0N2qw8elnZb/dLiC:9wB/bDDgeFc0Hgc/LN2qwN5j
TLSH 7915333E389CF6CDDB99BEF7909E35C2D47AD17B6088AC487CD016A82A2657DDC40C09
Reporter abuse_ch
Tags:gz MassLogger


Avatar
abuse_ch
Malspam distributing MassLogger:

From: hr@mehargroup.in
Subject: RFQ
Attachment: RFQ.gz (contains "RFQ.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Masslogger
Status:
Malicious
First seen:
2020-06-09 05:50:06 UTC
AV detection:
14 of 27 (51.85%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

gz 3a56dc8f555f5089342a75860f3cf5196c9ce7c3b9ccf99542f89d5d9085f928

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments