MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 98b94a69e5bbb73e9ed6c65f1aa949b50ecb4e3b779316fe09f6b80a7f4614e9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 98b94a69e5bbb73e9ed6c65f1aa949b50ecb4e3b779316fe09f6b80a7f4614e9
SHA3-384 hash: ba38ea763a0688f282de1f59861aa561aa594f4ae4c3e2f8c97df478a2e1e5b1cb5fa07a9651f56d8e9f45762b22c7f9
SHA1 hash: 89f7ab042971b36e5711402badbc1b2cbf762d5d
MD5 hash: 70d09bbaa8cfc229ff808ea797f15dda
humanhash: stream-north-romeo-michigan
File name:ALL LIST 304853058.IMG
Download: download sample
Signature MassLogger
File size:1'966'080 bytes
First seen:2020-06-03 08:04:40 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:GaUDdj6VEt6lBvyPDZr+9v9OGFphSx+S0BE0XolSYyGuOHHtcDSW4OTR:Qh6N/vSFr+N9OGxSxDEZolXyeHHtS
TLSH 4C956B3279D28815C928027644699AC4BAF67B443653C72EF1AF535B9F03B2FBB121CD
Reporter abuse_ch
Tags:img MassLogger


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: mail.globaldispomedika.com
Sending IP: 203.77.234.26
From: 大和塚 <gudang@globaldispomedika.com>
Subject: RE: Loading/ Shipping Advice - Draft Docs,
Attachment: ALL LIST 304853058.IMG (contains "PO# 304853058 - NEW ORDER.exe")

MassLogger C2:
http://rowlinson-knitwears.com/themes/classic/assets/pn/upload.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-06-02 23:31:12 UTC
AV detection:
13 of 31 (41.94%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

img 98b94a69e5bbb73e9ed6c65f1aa949b50ecb4e3b779316fe09f6b80a7f4614e9

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments