MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 25153f00d841c6a41619c7c630dde71dcf443205ce1436f1a7aa4ac682de2e5f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 25153f00d841c6a41619c7c630dde71dcf443205ce1436f1a7aa4ac682de2e5f
SHA3-384 hash: 6f5b85df309e4b7ec6a49cd29ed59999e2cb0e6a4c703f9c922caec9bdc09a4f2e08a7d178c76394dde08ec59b0af94b
SHA1 hash: 161a90d173f5d07d3c698356d2ecb6a1906a2595
MD5 hash: 5494034355aba3dce71a87bb3acffc6a
humanhash: white-bluebird-october-paris
File name:SCAN_20200805_1524203946573.r00
Download: download sample
Signature MassLogger
File size:851'784 bytes
First seen:2020-08-05 11:40:41 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 24576:SXPt0OMnEPD1mKrd81/Mp/jbVZBNTuN11cOu:NE5x8l6lZBRydu
TLSH F80523F94B176238ABFB6208B7F1531AA5CC105BB8B48E54449CA3613B14F9EFB4453A
Reporter abuse_ch
Tags:geo MassLogger r00 TUR


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: teb.com.tr
Sending IP: 156.96.58.85
From: hasan.huseyin.isik@teb.com.tr
Reply-To: 'hasan.huseyin.isik@teb.com.tr' <logzgo99@yahoo.com>
Subject: Faks e mail talimat hakkında
Attachment: SCAN_20200805_1524203946573.r00 (contains "SCAN_20200805_1524203946573.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-05 11:42:10 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

r00 25153f00d841c6a41619c7c630dde71dcf443205ce1436f1a7aa4ac682de2e5f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments