MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4f469a543b083c08d289261d3e9c0e7c8eaebb92633b4e8153d9448bc4c7a635. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4f469a543b083c08d289261d3e9c0e7c8eaebb92633b4e8153d9448bc4c7a635
SHA3-384 hash: e56abcc299035738b5d3833d135a9d9dcd5ccc56fbe7aa26978f7cf584af9733e380e019a4b76eb30458dd69fce5c71a
SHA1 hash: 036e87bd0d4a071f632bb46018c5a7dff72e4bd8
MD5 hash: a41673ad458e81708629f34e6cf52dcf
humanhash: saturn-pizza-north-stream
File name:enquiry20j20endooooo746e66682DIF.arj
Download: download sample
Signature MassLogger
File size:868'893 bytes
First seen:2020-06-08 06:00:33 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:tT6ciSlPuiIs6Q38Byrnrotj30AzKkTob1QaMJ5C7MeXvmz:d6clO23nbru0MKFeaMyMZ
TLSH 1F052387765128538C73C87847DFEC8E0631EC91D58533A63BD1A0B13FF2AA71662AE5
Reporter abuse_ch
Tags:arj MassLogger


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: mail.strongmailvault.com
Sending IP: 111.90.144.228
From: Purchase <info@tolrav.net>
Subject: Price Quotation
Attachment: enquiry20j20endooooo746e66682DIF.arj (contains "enquiry20j20endooooo746e66682DIF.exe")

MassLogger SMTP exfil server:
mail.pirc-energy.co.uk:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-08 06:02:07 UTC
AV detection:
18 of 47 (38.30%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 4f469a543b083c08d289261d3e9c0e7c8eaebb92633b4e8153d9448bc4c7a635

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments