MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 28c730bd1c67c68555acc37b3eea559a341a18c6b22381ad5dc7ac8a4748efab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 28c730bd1c67c68555acc37b3eea559a341a18c6b22381ad5dc7ac8a4748efab
SHA3-384 hash: 5947cb9e410864f267424cecf4a6a68135a26e2b29c86850dc3a44ce061c2883eb1db82d840a3fd0fa4204d6dd802fbd
SHA1 hash: 8eb3556a22d1399be118952815a5f5665e658a1e
MD5 hash: ad50c12c7353dbf6ca6d09d9056e919b
humanhash: harry-harry-fourteen-winter
File name:HSBC SWIFT 15072020_39458727759233665_PDF.iso
Download: download sample
Signature MassLogger
File size:1'071'104 bytes
First seen:2020-07-16 07:19:33 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 24576:0T++/jax34xtXHx7nJR1soHlEgZaKlhrtZX8iwO:K/jaKXXxj71syC2Toiw
TLSH A535D0CC3910719EC95E8C764964EC30A6212C66F7FBD20673CB6D9F7A3D587DA012A2
Reporter abuse_ch
Tags:HSBC iso MassLogger


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: llsa731-a17.servidoresdns.net
Sending IP: 82.223.190.25
From: HSBC Advising service <kepa@landetaburdinlanak.com>
Reply-To: c.eomirou@rmk.com
Subject: Payment Advice - Ref: HSBC99002992/28052020
Attachment: HSBC SWIFT 15072020_39458727759233665_PDF.iso (contains "HSBC SWIFT 15072020_39458727759233665_PDF.exe")

MassLogger SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2020-07-16 07:21:06 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

iso 28c730bd1c67c68555acc37b3eea559a341a18c6b22381ad5dc7ac8a4748efab

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments