MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 169e12b7649dbcd068ae831147a4a8d06d8467c85b8b0490a2bc54ad143347e5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 169e12b7649dbcd068ae831147a4a8d06d8467c85b8b0490a2bc54ad143347e5
SHA3-384 hash: 787c88c3685fec6cb0074c5f72b4c9066abac32563f9579c34cc816e2ec9cffd064bae7b22f49bb199bb9ab57e52b3ba
SHA1 hash: 09607298a8d50b54f70496b813f76ba30d001f64
MD5 hash: 70720374447c5185364273ca2efd480b
humanhash: red-south-alanine-illinois
File name:purchase order.zip
Download: download sample
Signature MassLogger
File size:643'051 bytes
First seen:2020-07-13 06:26:46 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:mHZSauSCNf0zNMzAN4hEOVNKqARTLFCN87t4Y4Dvoq4Pre:HS+qezvEUyTLVuYkwq4ze
TLSH 0ED423FB21AF92F0A316BF7C27D0C914F502824828945DDEEB257BDBAC4B607488954F
Reporter abuse_ch
Tags:MassLogger zip


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: janasi.com
Sending IP: 185.144.28.112
From: Townsend<ajit@janasi.com>
Subject: purchase orderr
Attachment: purchase order.zip (contains "purchase order.exe")

MassLogger SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-13 06:28:08 UTC
AV detection:
36 of 47 (76.60%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 169e12b7649dbcd068ae831147a4a8d06d8467c85b8b0490a2bc54ad143347e5

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments