MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cc66a0c7680a36d621599ce291eccb413e08344baf623ea8c80b214ed0f16f0d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cc66a0c7680a36d621599ce291eccb413e08344baf623ea8c80b214ed0f16f0d
SHA3-384 hash: ec7890d5b0c7a3dc93933aeff816f91a910858355c6ce88c4fdd5c716fb334f3db1c382063535b8ae435ac2c6d7b098b
SHA1 hash: db1fd70d9fe1d0785a806f0ab774ef6e5253bc61
MD5 hash: 6e3b6d920ca7edca98d5b84c49f23c10
humanhash: freddie-washington-batman-violet
File name:img00001.z
Download: download sample
Signature MassLogger
File size:762'155 bytes
First seen:2020-06-29 06:36:13 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:1iCGvt1uSnFC5M86MW1CnDqH8Tq5aJBXTDUADKQwN1zOq+O1ZeAR2CDHpOGN3d:1w1xFek58qcTqojU1Qkzj++cA3DrVd
TLSH 2AF433A35B064C37D2EB4E11B90A9E3F594538DC8264CBBD18886CD2617712E8F98FCC
Reporter abuse_ch
Tags:MassLogger z


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: delivery.mailspamprotection.com
Sending IP: 146.66.121.9
From: James Smith<info@oasisgrace.com>
Reply-To: James Smith<newlogs147@gmail.com>
Subject: Very Urgent
Attachment: img00001.z (contains "img00001.exe")

MassLogger SMTP exfil server:
mail.mytravelexplorer.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-06-29 06:38:05 UTC
AV detection:
15 of 31 (48.39%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

z cc66a0c7680a36d621599ce291eccb413e08344baf623ea8c80b214ed0f16f0d

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments