MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3d54e41c4973aec92d7198e866c45e9d50bf81d52afe85e378f8266e87e75f94. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3d54e41c4973aec92d7198e866c45e9d50bf81d52afe85e378f8266e87e75f94
SHA3-384 hash: c1dd3d0643d6c48b47575de776fd4027ab302d6dd1af3ebf7c23a37979afaaf551db8ca5276a7a123ea97cc69715d3c7
SHA1 hash: 5f5fc6694d34e9fcac942adb756516e9e9d7d553
MD5 hash: fb971260a1374b48bc1db5b60a80f627
humanhash: social-fourteen-arkansas-india
File name:Datasheet.gz
Download: download sample
Signature MassLogger
File size:879'746 bytes
First seen:2020-07-03 06:13:53 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 24576:teCWiP8a72GmXpveS6p3FQznngwAXR/rAIzpTe/xBE:tlPR72Hte/+CAWJeLE
TLSH 481533503AB5601A8CD881A6F0E3F00FDD89593D5EF972507522B6EDBA2B013D1DB7B1
Reporter abuse_ch
Tags:gz MassLogger


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: msa-smtp16.hinet.net
Sending IP: 168.95.6.66
From: <cytina.chiu@msa.hinet.net>
Subject: 产品咨询(RG25LGSJ) - WITHCHEM 韩国化学贸易公司
Attachment: Datasheet.gz (contains "Datasheet.exe")

MassLogger SMTP exfil server:
mail.mkontakt.az:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-03 06:15:08 UTC
AV detection:
29 of 48 (60.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

gz 3d54e41c4973aec92d7198e866c45e9d50bf81d52afe85e378f8266e87e75f94

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments