MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ff4ed39c61c2f035b7891a1e3b0302a8a2a68ecd63ff07422f35bc92fc4fd868. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ff4ed39c61c2f035b7891a1e3b0302a8a2a68ecd63ff07422f35bc92fc4fd868
SHA3-384 hash: 11f50c187636172107a8a65762105c7ccf25f2ba9fa024ed4289078fd3e4bfd241bcfaef015965acbe9f470d043ce8c4
SHA1 hash: 33c70bf37fc33e6d7f0fe03e03720c24b0c12461
MD5 hash: 7705fea607ffc7fe954c7030c4b80ab4
humanhash: neptune-oscar-north-earth
File name:PO. 74823.gz
Download: download sample
Signature MassLogger
File size:654'021 bytes
First seen:2020-08-18 06:30:02 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:Ld3SK5wfxKCW7L1rY2b/61yrU2j6ESjROnNqLJuUX0aX8:oaSxk7L15nlSwuJCaM
TLSH 90D423DD5C11A3E3BEAC972BBB9555EDE86C0940B0618EC4391CA3BAD1F2E0FF146161
Reporter abuse_ch
Tags:gz MassLogger


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: server.domain.com
Sending IP: 89.38.225.219
From: Sophie Loynds <mwarowny@wolhbi.com>
Subject: PO. 74823
Attachment: PO. 74823.gz (contains "PO. 74823.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-18 06:31:11 UTC
AV detection:
25 of 48 (52.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

gz ff4ed39c61c2f035b7891a1e3b0302a8a2a68ecd63ff07422f35bc92fc4fd868

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments