MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 03fa8086a22680d5f35280f2cd75e5878a717f18c86f18bec54be8f735e925e6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 03fa8086a22680d5f35280f2cd75e5878a717f18c86f18bec54be8f735e925e6
SHA3-384 hash: 66ea44be682f4e9ba0f74ec33a0f8a7b191ebd0b78c5c11121776eae01bdda746a8492ca93c720052fd506de8c2f4d14
SHA1 hash: 6de80f02115d08a024009ada1ee4f3e9ffd26464
MD5 hash: 6d9372e476cfef4274c73341061f21d4
humanhash: cup-arkansas-nitrogen-missouri
File name:Invoice and packing list PDF.rar
Download: download sample
Signature MassLogger
File size:695'066 bytes
First seen:2020-10-15 10:36:57 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:FmhKRn7B2nSNaDRfo6WiTDyamv9Gf/kpdmdIFQg3wKHzZN+qKC8U4d/H:FaCn7QnSNGV+iyamYnwPF/wAzZUwk
TLSH 55E42300596D4DBF9B93DB47634FF25EA07468E45B2DB2A03E91B684347B0B4C5BD80B
Reporter abuse_ch
Tags:DHL MassLogger rar


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: srv1.demspor.com
Sending IP: 31.169.94.221
From: DHL International <mkule@rekordtekstil.com.tr>
Reply-To: DHL International <portoviro.asso@gmail.com>
Subject: Re: Your Shipment invoice & packing-list
Attachment: Invoice and packing list PDF.rar (contains "2baba (7).exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.LokibotCrypt
Status:
Malicious
First seen:
2020-10-14 18:40:20 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar 03fa8086a22680d5f35280f2cd75e5878a717f18c86f18bec54be8f735e925e6

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments