MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9fd392cb0625064392be62c5ac1fd196236bccc2ee8be8fbc0334ac1f2edbe87. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 9fd392cb0625064392be62c5ac1fd196236bccc2ee8be8fbc0334ac1f2edbe87
SHA3-384 hash: 517f23159ad8f097d7d23b5fdf1530c3ed5b0cc4b8cea887796e3729ccad835ba276bc701a56cc4f181fdba324d1d5d1
SHA1 hash: 7760c9c692621634379161a664c4b0106ac0612d
MD5 hash: 72ea78123b169071e343c6f12df452f0
humanhash: kitten-magazine-december-hot
File name:yeni sifariş.zip
Download: download sample
Signature MassLogger
File size:818'789 bytes
First seen:2020-05-27 07:49:17 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:gtAHcZxcpQ0Olm3q95wtOM5xGeJLCpPHVi:gFypQ0Oc81M5FtCpPHY
TLSH 0E05231CD040BBA7BFD1067A107E0F7A52BE46B1D63818FA327131752B9E1B25A52C6F
Reporter abuse_ch
Tags:MassLogger zip


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: host2.himbimarket.com
Sending IP: 72.52.244.66
From: Alikhan Alizada <epugnant@groupe-rdt.com>
Subject: Re: Re: AW: yeni sifariş kotirovka
Attachment: yeni sifariş.zip (contains "yeni sifariş.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-27 08:37:14 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
7 of 48 (14.58%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 9fd392cb0625064392be62c5ac1fd196236bccc2ee8be8fbc0334ac1f2edbe87

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments