MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 27bd33f85c3b000cadf1d14bf5a97abd2eab7398709df23aa442bc5f7f9ba5e7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 27bd33f85c3b000cadf1d14bf5a97abd2eab7398709df23aa442bc5f7f9ba5e7
SHA3-384 hash: 3316051a860dd754214fee086fff9c27ec329b55eafde83a4903db5eebcaf74344fa34225d9e9d90470debfe55472656
SHA1 hash: 7f0327f8bdf8523d396c52d048904f6bbda78f17
MD5 hash: 2c56277ff096dab14b93861e5b3da2c1
humanhash: edward-high-football-oklahoma
File name:Project Document A02057 NMB TYP PIP SPC 40000_REV_D Material Spec_scanned from a xerox printer002.pd
Download: download sample
Signature MassLogger
File size:1'310'720 bytes
First seen:2020-10-16 13:44:29 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:55ZYEMD2huFYOHxyMl3kw7tyNf8TqX5SfCaIK5IBA3gXxPnOofgMykfACLG:ZYxoiiw7t2OY8Ca/5zenOoohkV
TLSH F25512B2A1248CE5F47154F0995FE8702061A85E94A1A31E3C9FFA3ED7F33C25563A1B
Reporter abuse_ch
Tags:MassLogger pd


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: server.kaihanglong.com
Sending IP: 92.53.124.70
From: sales <sales@kaihanglong.com>
Subject: RFQ 33091782773847 (DAHLIA, TERATAI & KANGSAR) - SUPPLY
Attachment: Project Document A02057 NMB TYP PIP SPC 40000_REV_D Material Spec_scanned from a xerox printer002.pd (contains "PROJECT_.EXE")

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-10-16 08:18:04 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

iso 27bd33f85c3b000cadf1d14bf5a97abd2eab7398709df23aa442bc5f7f9ba5e7

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments