MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 2f5ddc948bb23c9c0798e16b92bc8434922800a11b503643fd7f490a9f16da06. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
MassLogger
Vendor detections: 16
| SHA256 hash: | 2f5ddc948bb23c9c0798e16b92bc8434922800a11b503643fd7f490a9f16da06 |
|---|---|
| SHA3-384 hash: | d1ba5aef78a9b92604893c77be3cba4e91d1e7f473465567637064ec0c786feaed01218b7e1f91b0da7c33b626663c97 |
| SHA1 hash: | b912ef9d1b8dee585bb4806aac8efef49589dc86 |
| MD5 hash: | f6b81a1448045922f4342e60069318c2 |
| humanhash: | oklahoma-minnesota-charlie-mountain |
| File name: | GERİLİM KABLO Trafo Tic ve San AŞ RFQ_xlsx.exe |
| Download: | download sample |
| Signature | MassLogger |
| File size: | 1'186'304 bytes |
| First seen: | 2025-05-12 14:04:11 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'747 x AgentTesla, 19'642 x Formbook, 12'245 x SnakeKeylogger) |
| ssdeep | 24576:AHVtONla9ZdwuEcl1cKDc0b329c8KbK16Kjm89so:AHVcoK1Yc43+EK9mIs |
| TLSH | T14D45F14DF74A8EADD5EC17FE4222351452B8D0FBD2CBE3764CD9A6F0A9126ED0942183 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10522/11/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | exe MassLogger |
Intelligence
File Origin
DEVendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
f0ea203238500f03663733e31fea8cebb0d7c72af6d6f3578e1f67c6c532d028
6f8ee5830f1d488f16a500339d4de56479d89a4c2511328bb201014cabd9ad61
fe2f3029c38f9e6797f91c7f560ed013262e9feebbd0cb3850222ab7d46c8c32
147df6d9002c2a3d567f521595f16251f12b7e8d2adecab583a349aa95818736
0a36f604c1dfb7297c21f2b74600caa5df81ae43c9c1824e4a8de425b0dfaede
6fe914c71774d81a9ab4bc2b23a80aaa0f164c4d2d34f441ff95b546a3205afe
3c71dc69770af48af03effe50dbbbd246b8168d7e0fa5211b622759fcb6c0e3e
e91741f5f641f834836a6ce849bbf6563aa14fa4b686b6db3255a5e43c81d8f6
348379e04d8c9defb167f9b86bdabbab2ac4f95ea7ee6b1ea2bed36eafc62c95
54e2bde839e16579f55ca4ebd209bce0dab579ecd90e0c7d7efb85ea31cb357f
29fdb6bb8fa31427adbdadbbfe4aadf63ddea46f356a1382e8d68a1d3dcff8cf
e2528ff769b71dede661504e3af25efaaaa8bbc5983f0ecb5b70dca7451b2a8f
5f6e993861f9f97e0a51d060965c669fe94a00efcf2a03152ea5a53f67cb8756
316e340b6adade7f5a9a3ad9c620d7c9bcf900d08cfcec28e8d3b6dc2b6e5a1e
1c82d7afb5165833d07383fbdfc7daf78a19d527cd84bc24b3dbbc2035582472
ad94f1a913b31ec1412a784e2f5eda3b9e2d4f09f01b1162ec6a7a39516c47d2
131e7a58c7eef929455150072f714c30c3136b950297f6d8dffa6189499d8a73
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | crime_snake_keylogger |
|---|---|
| Author: | Rony (r0ny_123) |
| Description: | Detects Snake keylogger payload |
| Rule name: | INDICATOR_SUSPICIOUS_Binary_References_Browsers |
|---|---|
| Author: | ditekSHen |
| Description: | Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers. |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_DotNetProcHook |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables with potential process hoocking |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_TelegramChatBot |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables using Telegram Chat Bot |
| Rule name: | MAL_Envrial_Jan18_1 |
|---|---|
| Author: | Florian Roth (Nextron Systems) |
| Description: | Detects Encrial credential stealer malware |
| Reference: | https://twitter.com/malwrhunterteam/status/953313514629853184 |
| Rule name: | MAL_Envrial_Jan18_1_RID2D8C |
|---|---|
| Author: | Florian Roth |
| Description: | Detects Encrial credential stealer malware |
| Reference: | https://twitter.com/malwrhunterteam/status/953313514629853184 |
| Rule name: | masslogger_gcch |
|---|---|
| Author: | govcert_ch |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | RANSOMWARE |
|---|---|
| Author: | ToroGuitar |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Sus_Obf_Enc_Spoof_Hide_PE |
|---|---|
| Author: | XiAnzheng |
| Description: | Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP) |
| Rule name: | telegram_bot_api |
|---|---|
| Author: | rectifyq |
| Description: | Detects file containing Telegram Bot API |
| Rule name: | Windows_Trojan_SnakeKeylogger_af3faa65 |
|---|---|
| Author: | Elastic Security |
| Rule name: | win_masslogger_w0 |
|---|---|
| Author: | govcert_ch |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (GUARD_CF) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.