MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0b1e16ec3b9df30065ab12858d60db441afa2ad9f96e9a32e1f6c94eb675c71c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0b1e16ec3b9df30065ab12858d60db441afa2ad9f96e9a32e1f6c94eb675c71c
SHA3-384 hash: f715703788c681435554e93341ea3f6d8a1fdfc15ca572ea48f9a6ed8691283fef0165bc50fe476d68ff9d59f50f3143
SHA1 hash: 7f72d275b52e5775960ba5169b2fa956542cd53b
MD5 hash: 26d15bf678633c5fd4c87c3a7f022474
humanhash: robert-comet-connecticut-mexico
File name:RFQ 031-24062020.zip
Download: download sample
Signature MassLogger
File size:692'770 bytes
First seen:2020-06-24 07:44:29 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:QOQh2SZ4uURJTn/hSqQaNwvEuJ4m1bWcCfjIUGg7KO8yE7fXuM1:d8cJ7oJvTnbWcCEU7t8T+O
TLSH 67E42311974DEED113EFF228667BC84260E347B4AAD4DABE75C80A1189445FC8CE9DE2
Reporter abuse_ch
Tags:MassLogger zip


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: umacintl.com
Sending IP: 37.49.224.135
From: Chandana <techex@umacintl.com>
Subject: Confirmation order: RFQ #031-24062020
Attachment: RFQ 031-24062020.zip (contains "RFQ #031-24062020.exe")

MassLogger SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-24 07:46:06 UTC
AV detection:
21 of 31 (67.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 0b1e16ec3b9df30065ab12858d60db441afa2ad9f96e9a32e1f6c94eb675c71c

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments