MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 73a8cacd0330bf03a7483a32d6a83c99cdc9f762a7ce3bb803690766a40ff0bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 73a8cacd0330bf03a7483a32d6a83c99cdc9f762a7ce3bb803690766a40ff0bc
SHA3-384 hash: f8cbabfeeaa7329204fada21d379da58ffbae4f58455c0982bf72419f9d03160cb81b1e471173a3d524c0055f1974c8a
SHA1 hash: 2f518688542f43b3a5b380d94b19bd520ee7d1c3
MD5 hash: 6459ef20cb64a39bd46f06dcc4fcdd31
humanhash: georgia-eighteen-lithium-vermont
File name:Signed Order.zip
Download: download sample
Signature MassLogger
File size:811'906 bytes
First seen:2020-06-16 12:57:31 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:lKIM1wd1/6vTMJUJnDKnP4I7GJ0dDJ9CvXgpIVjv2tpwaiM3Y:4IgrdDKPVSCPOgpIVj+tH3Y
TLSH 20053399238431C962FD1AE43C3911D28E64E5D866EB651C3E89DED2F9F5C09F084B8F
Reporter abuse_ch
Tags:MassLogger zip


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: crimsonintl.com
Sending IP: 37.49.224.211
From: Izaika Patel <sales@crimsonintl.com>
Reply-To: Izaika Patel <sales@crimsonintl.com>
Subject: SIGNED ORDER
Attachment: Signed Order.zip (contains "Signed Order.exe")

MassLogger SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-16 12:59:05 UTC
AV detection:
30 of 48 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 73a8cacd0330bf03a7483a32d6a83c99cdc9f762a7ce3bb803690766a40ff0bc

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments