MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c99795d551dcec9f256338f7253d413be4f2ceb2b20c5bc3515041683cd22a6a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c99795d551dcec9f256338f7253d413be4f2ceb2b20c5bc3515041683cd22a6a
SHA3-384 hash: 311a3099563c94bdda87f9e1c6788efc7fab670a6a1cae34b9fe312a40a77135aad92f3232d267d7f7c615acb349f5ab
SHA1 hash: f91bb56a161e841a147a9f20ec778d37dc9f87df
MD5 hash: 5d9351c921398cfdab9497c418937b69
humanhash: timing-venus-four-massachusetts
File name:Migliore consulenza globale sui pagamenti PI CFL002 19A.gz
Download: download sample
Signature MassLogger
File size:864'906 bytes
First seen:2020-08-08 08:12:16 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:EplIfiuctWwwxHSixs32wMexLzSQ3UtyXhE/:wlOctFwNS9sSz3kQM
TLSH A50533AF129F009D09E90E5A6AD8F058EF69573A9D3B1E10BBC740267173D1EDCAC50E
Reporter abuse_ch
Tags:gz MassLogger


Avatar
abuse_ch
Malspam distributing unidentified malware:

From: Cristina Sasso <Jinju@aramex.com>
Subject: Migliore consulenza globale sui pagamenti // PI # CFL002 / 19A
Attachment: Migliore consulenza globale sui pagamenti PI CFL002 19A.gz (contains "Migliore consulenza globale sui pagamenti PI # CFL002 19A.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-08 08:14:09 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip c99795d551dcec9f256338f7253d413be4f2ceb2b20c5bc3515041683cd22a6a

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments