MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d098e12e21205c68dfe995b5e4ca60ab2fef5769f7eff8fcf63664fd154f534. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4d098e12e21205c68dfe995b5e4ca60ab2fef5769f7eff8fcf63664fd154f534
SHA3-384 hash: a26ba8518bd4b7a143228d9c5aa4af9df4b7f5aab02d84e483d75c83b4bb5849baa9df20bc32033568a408aa6ee91b5c
SHA1 hash: 3f3a98d3fee26bb7b1f48c8802d4f6f49c0dab0b
MD5 hash: a8028f94a9bb825aa340cce3fe0d0b0d
humanhash: venus-avocado-hot-september
File name:Xf10142020PurchaseOrder766657.zip
Download: download sample
Signature MassLogger
File size:720'712 bytes
First seen:2020-10-14 15:53:40 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:csE+nk3v9Nf9qevsFuZ8Id5Ln3g/ZUjwBMic2q4u3NH4bMOFEtJK7JXA46zk:cMk/vfmkZ8q3g/ZUjwPc2q4OH4bMk7J/
TLSH 4FE433280B58CDAB1EEE28299560A6E70C7E718F42FCEDE0DBAF41D53B208DC11559B4
Reporter abuse_ch
Tags:MassLogger zip


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: mail.praelegal.de
Sending IP: 31.7.33.42
From: Salih Önder | PraeLegal <salihonder@praelegal.de>
Subject: RE: PO# XFf10142020 Delivery before 12th December 2020
Attachment: Xf10142020PurchaseOrder766657.zip (contains "Xf10142020PurchaseOrder766657.exe")

MassLogger SMTP exfil server:
smtp.yandex.ru:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Ymacco
Status:
Malicious
First seen:
2020-10-14 07:01:01 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 4d098e12e21205c68dfe995b5e4ca60ab2fef5769f7eff8fcf63664fd154f534

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments