MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 53c05a4b75e539caed8efe3f60af055da27c014c2f8ba6f9a05981fc2e073e59. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 53c05a4b75e539caed8efe3f60af055da27c014c2f8ba6f9a05981fc2e073e59
SHA3-384 hash: dac800707511db6e4f5bdcbc1bb140995802dede33da3dcc3c2726a7de6d1d6e8c70f68be58c3c25d405fca5668614ca
SHA1 hash: 8ec3551d5bce779e1425f0b6f6bcb0195043eace
MD5 hash: 2b372a7077f8705f843f343dea500b85
humanhash: triple-double-item-skylark
File name:Pago adjust 2020-20_PDF.img
Download: download sample
Signature MassLogger
File size:1'900'544 bytes
First seen:2020-05-20 12:07:38 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:d63eJneeEt6Y9oRoLdJy5+g+72mkK1lmJ5nHg4umyCip2J5Bb2:H/YCw0+gKkKzQ9gCEp2R
TLSH C4956C2639C2C408C56885362025ADC5E7E6AB4236A6CB5FFA9F534F5F02B3E7B111CD
Reporter abuse_ch
Tags:CaixaBank ESP geo img MassLogger


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: server.lazul.com
Sending IP: 82.194.91.57
From: La Caixa <direccion@eucov.com>
Subject: RV: Confirmación de pago
Attachment: Pago adjust 2020-20_PDF.img (contains "Pago adjust 2020-20_PDF.exe")

MassLogger FTP exfil server:
ftp.sisbg.net:21

MassLogger FTP exfil user name:
ntums@sisbg.net

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-05-20 12:32:07 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
12 of 30 (40.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

img 53c05a4b75e539caed8efe3f60af055da27c014c2f8ba6f9a05981fc2e073e59

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments