MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a30b832b57390359990b3c114f97974d079c77c9a94d77c809d250cc56dfa70c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: a30b832b57390359990b3c114f97974d079c77c9a94d77c809d250cc56dfa70c
SHA3-384 hash: c23252627229a6ff4a698547010beb42542906da40d61b890d6d1203d9a904d5cd93dbcb77bd3451b966264694b3b862
SHA1 hash: 87c2842ced0634b43c94841c849257ffa27d9a60
MD5 hash: 2186da778fcbe1c2eec0445d0db5745c
humanhash: don-rugby-low-ink
File name:PO052620.rar
Download: download sample
Signature MassLogger
File size:857'813 bytes
First seen:2020-05-26 11:17:23 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:0DsPQW+6SI71phSFR4nQzuKPWGmwGe6THFw8qnl/J:RQnuMknHKenm6jy9nlR
TLSH 3E0533F0C15D834D2B9BC8D960C8B45A533F0814FED2EB9A573B924EA519A6C19F68CC
Reporter abuse_ch
Tags:MassLogger rar


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: econocaribe.com
Sending IP: 103.147.184.73
From: info@econocaribe.com
Subject: P.O For Our New Order!
Attachment: PO052620.rar (contains "PO#052620.exe")

MassLogger SMTP exfil server:
us2.smtp.mailhostbox.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-26 11:37:06 UTC
File Type:
Binary (Archive)
Extracted files:
8
AV detection:
23 of 48 (47.92%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar a30b832b57390359990b3c114f97974d079c77c9a94d77c809d250cc56dfa70c

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments