MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1f4d1b50fddb44e5bd891b724268023d4f53c181d36a691d1d3e50bd3d4ed5ac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 1f4d1b50fddb44e5bd891b724268023d4f53c181d36a691d1d3e50bd3d4ed5ac
SHA3-384 hash: b564dcec8a04239d7c13b3c26e43771bbea2d7d3f23e772d44ed1f545361f52ffa0a2a3fdddd3580ed73e760d88ec93b
SHA1 hash: ebfaa70afb5a6d09e5af636d282e09cdc4e7d6db
MD5 hash: ac09901b00317ba41ace6e75e2105228
humanhash: north-fix-monkey-shade
File name:Vessel Details.zip
Download: download sample
Signature MassLogger
File size:1'048'733 bytes
First seen:2020-12-01 14:19:51 UTC
Last seen:2020-12-10 08:09:50 UTC
File type: zip
MIME type:application/zip
ssdeep 24576:zploo/fdNe6zlP6OHMK9dUEkw5HY/U2ptEDIlvgsuFIA7S4D:Pd/DzlP6OsmkMHY/xtEDIlgsqCi
TLSH 5A253316D44710B2BBF6469D38E32E0B7AB9C4C3B5FB54A9B6274A0E07421A4F5B724C
Reporter GovCERT_CH

Intelligence


File Origin
# of uploads :
28
# of downloads :
172
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-12-01 14:20:07 UTC
AV detection:
12 of 28 (42.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 1f4d1b50fddb44e5bd891b724268023d4f53c181d36a691d1d3e50bd3d4ed5ac

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments