MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 27bd33f85c3b000cadf1d14bf5a97abd2eab7398709df23aa442bc5f7f9ba5e7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
MassLogger
Vendor detections: 4
| SHA256 hash: | 27bd33f85c3b000cadf1d14bf5a97abd2eab7398709df23aa442bc5f7f9ba5e7 |
|---|---|
| SHA3-384 hash: | 3316051a860dd754214fee086fff9c27ec329b55eafde83a4903db5eebcaf74344fa34225d9e9d90470debfe55472656 |
| SHA1 hash: | 7f0327f8bdf8523d396c52d048904f6bbda78f17 |
| MD5 hash: | 2c56277ff096dab14b93861e5b3da2c1 |
| humanhash: | edward-high-football-oklahoma |
| File name: | Project Document A02057 NMB TYP PIP SPC 40000_REV_D Material Spec_scanned from a xerox printer002.pd |
| Download: | download sample |
| Signature | MassLogger |
| File size: | 1'310'720 bytes |
| First seen: | 2020-10-16 13:44:29 UTC |
| Last seen: | Never |
| File type: | iso |
| MIME type: | application/x-iso9660-image |
| ssdeep | 12288:55ZYEMD2huFYOHxyMl3kw7tyNf8TqX5SfCaIK5IBA3gXxPnOofgMykfACLG:ZYxoiiw7t2OY8Ca/5zenOoohkV |
| TLSH | F25512B2A1248CE5F47154F0995FE8702061A85E94A1A31E3C9FFA3ED7F33C25563A1B |
| Reporter | |
| Tags: | MassLogger pd |
abuse_ch
Malspam distributing MassLogger:HELO: server.kaihanglong.com
Sending IP: 92.53.124.70
From: sales <sales@kaihanglong.com>
Subject: RFQ 33091782773847 (DAHLIA, TERATAI & KANGSAR) - SUPPLY
Attachment: Project Document A02057 NMB TYP PIP SPC 40000_REV_D Material Spec_scanned from a xerox printer002.pd (contains "PROJECT_.EXE")
Intelligence
File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-10-16 08:18:04 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Trojan
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
MassLogger
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.