MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4dd968fcdadbde8f3400a3c78ad8613a5c1f10f4fed3052427f819b8e176aa47. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4dd968fcdadbde8f3400a3c78ad8613a5c1f10f4fed3052427f819b8e176aa47
SHA3-384 hash: e6129eb18f56a23c01e71b444f5ab9e206656c7ac2e61a60e1942a1e7760cb174e76cf24bb7f5e66f52fa01fd98c657d
SHA1 hash: 29f6261ac26986cb0c02ea44437beffd263350f3
MD5 hash: 20fd9243a731612bdbe148ac122ab716
humanhash: friend-happy-papa-alpha
File name:SCB09876.rar
Download: download sample
Signature MassLogger
File size:1'115'740 bytes
First seen:2020-11-06 07:35:25 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:SyDhtsbK8NPWsqS1CR1hPuaijVfPnmeoQ+6b:S+tsbKg5iB+Xnmeog
TLSH 5635331026E8A39ED5164D0FD777AC7468C3E11AA20FF712F58F10990B371939BBA1A7
Reporter abuse_ch
Tags:MassLogger rar Yahoo


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: sonic304-23.consmr.mail.gq1.yahoo.com
Sending IP: 98.137.68.204
From: Ali joy <joyali124@yahoo.com.sg>
Subject: FW: Payment Transfer
Attachment: SCB09876.rar (contains "pmdt2egRhRSrXC1.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2020-11-06 07:37:09 UTC
AV detection:
4 of 48 (8.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar 4dd968fcdadbde8f3400a3c78ad8613a5c1f10f4fed3052427f819b8e176aa47

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments