MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 452388d551942d9adb419cf5ad3e833a73e29794beaa11f737468b63ea2cb307. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 452388d551942d9adb419cf5ad3e833a73e29794beaa11f737468b63ea2cb307
SHA3-384 hash: 8e7141d206a26c25a482ba3545502934b08a3f2e23d4b14bc3bbfb7fa1d1e13be3236cf5e30eb5cef93b872dacedeb2e
SHA1 hash: 407bf45e50befadd27cab90a6c6e814725fbd9e2
MD5 hash: 86ee04895d3384f34f46caace9f2ad75
humanhash: floor-tango-hydrogen-venus
File name:CATALOGUE RMK TRADING LTD_PDF.iso
Download: download sample
Signature MassLogger
File size:937'984 bytes
First seen:2020-07-03 06:39:35 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:dTrBzc5aTA8urjgJh7OaxoZwTgmXIaXyfEm/cF8/ia44/ZFYzfIBRG3xHWw+CVHB:nzc59UJLxo6Tgm49sm0W/iaX9BG2wl
TLSH BE1512312741FF48D6658AB4752305022E7B79A71221F61E3C8D62EC5BE3B88DF9A7C1
Reporter abuse_ch
Tags:iso MassLogger


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: vm6534.seewebcloud.it
Sending IP: 213.171.165.67
From: RMK TRADING LTD <c.eomirou@rmk.es>
Subject: ORDER 03072020_07
Attachment: CATALOGUE RMK TRADING LTD_PDF.iso (contains "CATALOGUE RMK TRADING LTD_PDF.exe")

MassLogger SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Skeeyah
Status:
Malicious
First seen:
2020-07-03 06:41:03 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

iso 452388d551942d9adb419cf5ad3e833a73e29794beaa11f737468b63ea2cb307

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments