MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d0a266b4b689590e572020b8117157cdfa05d9b6d9cbcdb0aa5389ab3d55cfa6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d0a266b4b689590e572020b8117157cdfa05d9b6d9cbcdb0aa5389ab3d55cfa6
SHA3-384 hash: 67e6d51c532cf1d6633cac8c1e50dd729c9dfb48ac36cc36e3cf7f088ce5f9d0367903c95fec3897d3c9a2d04103de95
SHA1 hash: 92da2b84a69eee0e015d1031f0af998014db7827
MD5 hash: c8a43aca750f1bd180abfd1a2e21c440
humanhash: six-beryllium-zulu-ten
File name:BIS SWIFT_20072020_9427492749242_PDF.img
Download: download sample
Signature MassLogger
File size:942'080 bytes
First seen:2020-07-21 14:06:55 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:8Nqgr996/t+7HtJQnzKTA392KSSSdWEa6R:kBU10tJQdN2KSSSg+
TLSH 0315016AE72A4F3ECC9D16BA52C0F0851FB2A003A263EB2DE49D64895F23F5547D1347
Reporter abuse_ch
Tags:img MassLogger


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: tex-style.eu
Sending IP: 45.138.172.247
From: COMEX-BISA <info@tex-style.eu>
Subject: Mensaje SWIFT Transf. Exterior (30105) - MT 103 - 200T000000121678 - SAVAL S.R.L.
Attachment: BIS SWIFT_20072020_9427492749242_PDF.img (contains "BIS SWIFT_20072020_9427492749242_PDF.exe")

MassLogger SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Agensla
Status:
Malicious
First seen:
2020-07-21 14:08:06 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

img d0a266b4b689590e572020b8117157cdfa05d9b6d9cbcdb0aa5389ab3d55cfa6

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments