MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8c689dedf337057280913d9a8dfc9c10c297e2dc9669a1e19e2c8cbf99cd5ed9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 8c689dedf337057280913d9a8dfc9c10c297e2dc9669a1e19e2c8cbf99cd5ed9
SHA3-384 hash: 6bb30b10989118bfb432b35148d9837e05ea9aea20c670288dabde7a9ef9448ea6b5406038e3b2fe3f4e05efc47691e5
SHA1 hash: 1b6fdee9577d7fb5c5adc0bf4b4032281d824d48
MD5 hash: 99728a572c625ddf3d1227b7f857ea03
humanhash: coffee-football-steak-gee
File name:PO31909704_1.zip
Download: download sample
Signature MassLogger
File size:765'007 bytes
First seen:2020-08-05 08:42:50 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:ElU2yGSozJV14QEEnZ8NJ4b0x3oi3DtcLoSdJX751AFhhJlqPBsC1EU3/e:EllHrJpElGy3pztcLLd2lqaCSL
TLSH 4AF423236982997A7EDA07120CAC5392E93E465B15B7E7CC6808198970C5CB3FD14EFF
Reporter abuse_ch
Tags:MassLogger zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: tlac.co.ke
Sending IP: 103.99.1.147
From: Satish <satishmodi@tlac.co.ke>
Subject: Order confirmation
Attachment: PO31909704_1.zip (contains "PO31909704_1.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.FormBook
Status:
Malicious
First seen:
2020-08-05 08:44:07 UTC
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 8c689dedf337057280913d9a8dfc9c10c297e2dc9669a1e19e2c8cbf99cd5ed9

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments