MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 14c618dec5ec31c655ae3c518d2af66c6b5e44162b68c20e725f1ab76bf281cd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 14c618dec5ec31c655ae3c518d2af66c6b5e44162b68c20e725f1ab76bf281cd
SHA3-384 hash: fcde62667455c8ad7540fd8d7f6c58c71bb5c14ee1c3e564d1f6d70690290fce6667fd29629186148ae7110c45ee2f7d
SHA1 hash: 3b90b047e90d59e40ce855a07fcfb3e9cfbaac40
MD5 hash: 47af348402ab6750f67c9c14fda0b6ac
humanhash: skylark-papa-uranus-golf
File name:PAGO.js
Download: download sample
Signature MassLogger
File size:2'516'409 bytes
First seen:2026-06-23 12:08:37 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:application/octet-stream
ssdeep 384:dQt2S1T8ovO31Hmpe9m7VTdc1fVm+YP6ROf8JVivLqbGB6YUc/kE25QhtlxRx7Ih:Ww
TLSH T177C5128636A4B0CECACA73D14E48F7939B07324D7BE361E93A0327F55D860782945DB6
Magika javascript
Reporter James_inthe_box
Tags:exe js MassLogger

Intelligence


File Origin
# of uploads :
1
# of downloads :
166
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
aes anti-vm base64 crypto fingerprint obfuscated overlay powershell repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-06-23T08:02:00Z UTC
Last seen:
2026-06-25T10:38:00Z UTC
Hits:
~1000
Detections:
Trojan.JS.SAgent.sb HEUR:Trojan.Script.Generic
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-06-23 12:08:20 UTC
File Type:
Binary
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
masslogger
Score:
  10/10
Tags:
family:masslogger collection discovery execution spyware stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Command and Scripting Interpreter: JavaScript
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Command and Scripting Interpreter: PowerShell
Looks up external IP address via web service
Badlisted process makes network request
Family: MassLogger
Process spawned unexpected child process
Malware Config
C2 Extraction:
https://api.telegram.org/bot8863119254:AAH253pnN63l3kHxRxN-9CdTBo712ifHgpM/sendMessage?chat_id=8153569978
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments